peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,084 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,705 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-2006 HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… Patch early 9.8 critical 20.4% 2016-04-21
CVE-2016-2007 HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, ak… Patch early 9.8 critical 20.4% 2016-04-21
CVE-2018-18475 Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. Patch early 9.8 critical 20.4% 2018-10-23
CVE-2024-39226 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.… Patch early 9.8 critical 20.4% 2024-08-06
CVE-2016-9361 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.… Patch early 9.8 critical 20.4% 2017-02-13
CVE-2019-9203 Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. Patch early 9.8 critical 20.4% 2019-03-28
CVE-2026-22679 Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devo… Patch early 9.8 critical 20.4% 2026-04-07
CVE-2024-24576 Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly esc… Patch early 10.0 critical 20.3% 2024-04-09
CVE-2025-32583 Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects… Patch early 9.9 critical 20.3% 2025-04-17
CVE-2022-22951 VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command in… Patch early 9.1 critical 20.3% 2022-03-23
CVE-2021-27146 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. Patch early 9.8 critical 20.3% 2021-02-10
CVE-2021-27153 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded trueadmin / admintrue credentials for an IS… Patch early 9.8 critical 20.3% 2021-02-10
CVE-2021-27154 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. Patch early 9.8 critical 20.3% 2021-02-10
CVE-2021-27155 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credential… Patch early 9.8 critical 20.3% 2021-02-10
CVE-2019-12526 An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remo… Patch early 9.8 critical 20.3% 2019-11-26
CVE-2022-0591 The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable… Patch early 9.1 critical 20.2% 2022-03-21
CVE-2017-3167 In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication ph… Patch early 9.8 critical 20.2% 2017-06-20
CVE-2023-31689 In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and… Patch early 9.8 critical 20.2% 2023-05-22
CVE-2024-22651 There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04. Patch early 9.8 critical 20.2% 2024-01-24
CVE-2022-45711 IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools funct… Patch early 9.8 critical 20.2% 2022-12-23
CVE-2024-29021 Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Serve… Patch early 9.0 critical 20.2% 2024-04-18
CVE-2024-39309 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and… Patch early 9.8 critical 20.2% 2024-07-01
CVE-2021-22802 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on u… Patch early 9.8 critical 20.2% 2022-02-11
CVE-2024-21334 Open Management Infrastructure (OMI) Remote Code Execution Vulnerability Patch early 9.8 critical 20.2% 2024-03-12
CVE-2022-26082 A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A speciall… Patch early 9.1 critical 20.1% 2022-05-25
CVE-2022-1556 The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for St… Patch early 9.8 critical 20.1% 2022-05-30
CVE-2018-1000802 Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Inj… Patch early 9.8 critical 20.1% 2018-09-18
CVE-2021-3064 A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-bas… Patch early 9.8 critical 20.1% 2021-11-10
CVE-2022-38828 TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi Patch early 9.8 critical 20.1% 2022-09-16
CVE-2016-4510 The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitr… Patch early 9.1 critical 20.1% 2016-06-09
← previous page 108 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt