peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,075 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-49001 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect succe… Patch early 9.8 critical 21.1% 2025-06-03
CVE-2022-38352 ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerabi… Patch early 9.8 critical 21% 2022-09-15
CVE-2025-2828 A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain… Patch early 10.0 critical 21% 2025-06-23
CVE-2025-4978 A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /B… Patch early 9.8 critical 21% 2025-05-20
CVE-2022-41657 Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil… Patch early 9.8 critical 20.9% 2022-10-31
CVE-2020-25111 An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-S… Patch early 9.8 critical 20.9% 2020-12-11
CVE-2020-10827 A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exec… Patch early 9.8 critical 20.9% 2020-03-26
CVE-2020-10828 A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exec… Patch early 9.8 critical 20.9% 2020-03-26
CVE-2014-7859 Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2… Patch early 9.8 critical 20.9% 2017-08-25
CVE-2020-15893 An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An att… Patch early 9.8 critical 20.9% 2020-07-22
CVE-2021-45967 An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path tr… Patch early 9.8 critical 20.8% 2022-03-18
CVE-2010-1573 Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages… Patch early 9.8 critical 20.8% 2010-06-10
CVE-2022-27228 In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. Patch early 9.8 critical 20.8% 2022-03-22
CVE-2024-21797 A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP reque… Patch early 9.1 critical 20.8% 2025-01-14
CVE-2024-36295 A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request… Patch early 9.1 critical 20.8% 2025-01-14
CVE-2018-19127 A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable fil… Patch early 9.8 critical 20.8% 2018-11-09
CVE-2017-5641 Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. D… Patch early 9.8 critical 20.7% 2017-12-28
CVE-2024-7332 A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_c… Patch early 9.8 critical 20.7% 2024-08-01
CVE-2023-24734 An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image… Patch early 9.8 critical 20.7% 2023-03-06
CVE-2026-1470 n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated… Patch early 9.9 critical 20.7% 2026-01-27
CVE-2023-28725 General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary J… Patch early 9.1 critical 20.6% 2023-03-22
CVE-2022-43775 The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote… Patch early 9.8 critical 20.6% 2022-10-26
CVE-2025-25291 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-s… Patch early 9.8 critical 20.6% 2025-03-12
CVE-2025-43561 ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code… Patch early 9.1 critical 20.6% 2025-05-13
CVE-2022-27336 Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. Patch early 9.8 critical 20.5% 2022-04-27
CVE-2017-6920 Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely duri… Patch early 9.8 critical 20.5% 2018-08-06
CVE-2023-45498 VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. Patch early 9.8 critical 20.5% 2023-10-27
CVE-2022-24934 wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry. Patch early 9.8 critical 20.5% 2022-03-23
CVE-2016-4391 A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0. Patch early 9.8 critical 20.4% 2018-08-06
CVE-2016-2005 HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… Patch early 9.8 critical 20.4% 2016-04-21
← previous page 107 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt