peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,074 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-19365 The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted… Patch early 9.1 critical 22.3% 2019-03-21
CVE-2025-54261 ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Travers… Patch early 10.0 critical 22.2% 2025-09-09
CVE-2017-5804 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. Patch early 9.8 critical 22.2% 2018-02-15
CVE-2017-5805 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. Patch early 9.8 critical 22.2% 2018-02-15
CVE-2017-5806 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found. Patch early 9.8 critical 22.2% 2018-02-15
CVE-2025-25014 A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. Patch early 9.1 critical 22.2% 2025-05-06
CVE-2022-31259 The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configure… Patch early 9.8 critical 22.2% 2022-05-21
CVE-2021-24094 Windows TCP/IP Remote Code Execution Vulnerability Patch early 9.8 critical 22.1% 2021-02-25
CVE-2022-36572 Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin… Patch early 9.8 critical 22% 2022-08-29
CVE-2023-2479 OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. Patch early 9.8 critical 22% 2023-05-02
CVE-2025-2005 The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the… Patch early 9.8 critical 22% 2025-04-02
CVE-2015-7919 SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via u… Patch early 10.0 critical 22% 2015-12-21
CVE-2025-55346 User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS… Patch early 9.8 critical 22% 2025-08-14
CVE-2021-22931 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host n… Patch early 9.8 critical 22% 2021-08-16
CVE-2022-23389 PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. Patch early 9.8 critical 22% 2022-02-14
CVE-2023-52440 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->Sessio… Patch early 9.8 critical 21.9% 2024-02-21
CVE-2017-5807 A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found. Patch early 9.8 critical 21.9% 2018-02-15
CVE-2024-1283 Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted H… Patch early 9.8 critical 21.9% 2024-02-07
CVE-2021-46704 In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts a… Patch early 9.8 critical 21.9% 2022-03-06
CVE-2022-1390 The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated a… Patch early 9.8 critical 21.9% 2022-04-25
CVE-2018-17879 An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several i… Patch early 9.8 critical 21.9% 2023-10-26
CVE-2023-0104 The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an… Patch early 9.3 critical 21.8% 2023-02-22
CVE-2017-14135 enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrar… Patch early 9.8 critical 21.8% 2017-09-04
CVE-2023-3824 In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insuff… Patch early 9.4 critical 21.8% 2023-08-11
CVE-2022-40471 Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload function… Patch early 9.8 critical 21.8% 2022-10-31
CVE-2022-37128 In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. Patch early 9.8 critical 21.7% 2022-08-31
CVE-2022-31827 MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. Patch early 9.1 critical 21.7% 2022-06-09
CVE-2022-37134 D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base6… Patch early 9.8 critical 21.7% 2022-08-22
CVE-2026-23550 Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: fro… Patch early 9.8 critical 21.7% 2026-01-14
CVE-2019-1373 A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Rem… Patch early 9.8 critical 21.7% 2019-11-12
← previous page 105 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt