peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,075 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-45461 FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitr… Patch early 9.8 critical 21.7% 2021-12-22
CVE-2021-31932 Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functio… Patch early 9.8 critical 21.6% 2022-02-11
CVE-2024-29855 Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator Patch early 9.0 critical 21.6% 2024-06-11
CVE-2022-30450 A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php Patch early 9.8 critical 21.6% 2022-05-11
CVE-2021-27078 Microsoft Exchange Server Remote Code Execution Vulnerability Patch early 9.1 critical 21.6% 2021-03-03
CVE-2018-8540 A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injec… Patch early 9.8 critical 21.6% 2018-12-12
CVE-2017-5674 A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a… Patch early 9.8 critical 21.6% 2017-03-13
CVE-2018-16286 LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limi… Patch early 9.8 critical 21.5% 2018-09-14
CVE-2018-18006 Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL… Patch early 9.8 critical 21.5% 2018-12-14
CVE-2016-0132 Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents… Patch early 9.8 critical 21.5% 2016-03-09
CVE-2019-7267 Linear eMerge 50P/5000P devices allow Cookie Path Traversal. Patch early 9.8 critical 21.5% 2019-07-02
CVE-2019-12409 The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Patch early 9.8 critical 21.4% 2019-11-18
CVE-2022-26635 PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disput… Patch early 9.8 critical 21.4% 2022-04-05
CVE-2019-25224 The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerabilit… Patch early 9.8 critical 21.4% 2025-07-25
CVE-2021-43319 Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. Patch early 9.8 critical 21.4% 2021-11-30
CVE-2022-33171 The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-con… Patch early 9.8 critical 21.4% 2022-07-04
CVE-2021-27144 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u c… Patch early 9.8 critical 21.4% 2021-02-10
CVE-2021-22823 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user r… Patch early 9.1 critical 21.4% 2022-02-11
CVE-2018-2879 Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are af… Patch early 9.0 critical 21.4% 2018-04-19
CVE-2018-8014 The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are inse… Patch early 9.8 critical 21.3% 2018-05-16
CVE-2018-1216 A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell… Patch early 9.8 critical 21.3% 2018-03-08
CVE-2018-8626 A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS… Patch early 9.8 critical 21.2% 2018-12-12
CVE-2016-9498 ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by r… Patch early 9.8 critical 21.2% 2018-07-13
CVE-2023-21692 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Patch early 9.8 critical 21.2% 2023-02-14
CVE-2017-18365 The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arb… Patch early 9.8 critical 21.2% 2019-03-28
CVE-2021-25641 Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before… Patch early 9.8 critical 21.2% 2021-06-01
CVE-2025-37924 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL w… Patch early 9.8 critical 21.2% 2025-05-20
CVE-2022-3921 The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could al… Patch early 9.8 critical 21.2% 2022-12-12
CVE-2022-38308 TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. T… Patch early 9.8 critical 21.2% 2022-09-14
CVE-2020-11901 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. Patch early 9.0 critical 21.1% 2020-06-17
← previous page 106 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt