peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,092 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,706 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-44088 ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. Patch early 9.8 critical 20.1% 2022-11-10
CVE-2022-29592 Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). Patch early 9.8 critical 20.1% 2022-05-05
CVE-2025-44084 D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggerin… Patch early 9.8 critical 20.1% 2025-05-20
CVE-2017-8658 A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engi… Patch early 9.8 critical 20.1% 2017-08-11
CVE-2020-6637 openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. Patch early 9.8 critical 20.1% 2020-08-24
CVE-2023-34747 File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload. Patch early 9.8 critical 20% 2023-06-14
CVE-2019-15606 Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons Patch early 9.8 critical 20% 2020-02-07
CVE-2016-3586 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers… Patch early 9.8 critical 20% 2016-07-21
CVE-2018-14701 System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execu… Patch early 9.8 critical 20% 2018-12-03
CVE-2018-19510 subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header. Patch early 9.8 critical 20% 2019-03-21
CVE-2022-31874 ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. Patch early 9.8 critical 20% 2022-06-17
CVE-2019-8600 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.… Patch early 9.8 critical 20% 2019-12-18
CVE-2017-3169 In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_conn… Patch early 9.8 critical 20% 2017-06-20
CVE-2024-42448 From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code E… Patch early 9.9 critical 19.9% 2024-12-12
CVE-2020-8597 eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. Patch early 9.8 critical 19.9% 2020-02-03
CVE-2024-0087 NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists,… Patch early 9.0 critical 19.9% 2024-05-14
CVE-2024-33344 D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arb… Patch early 9.8 critical 19.9% 2024-04-26
CVE-2022-23357 mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. Patch early 9.1 critical 19.9% 2022-02-03
CVE-2020-13925 Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whil… Patch early 9.8 critical 19.9% 2020-07-14
CVE-2016-8705 Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary prot… Patch early 9.8 critical 19.9% 2017-01-06
CVE-2025-66398 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the int… Patch early 9.6 critical 19.9% 2026-01-01
CVE-2021-27165 An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials. Patch early 9.8 critical 19.8% 2021-02-10
CVE-2021-27168 An issue was discovered on FiberHome HG6245D devices through RP2613. There is a 6GFJdY4aAuUKJjdtSn7d password for the rdsadmin account. Patch early 9.8 critical 19.8% 2021-02-10
CVE-2021-27169 An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. There is a gepon password for the gepon account. Patch early 9.8 critical 19.8% 2021-02-10
CVE-2021-41163 Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.… Patch early 10.0 critical 19.8% 2021-10-20
CVE-2021-27150 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng4201… Patch early 9.8 critical 19.8% 2021-02-10
CVE-2018-7489 FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an inc… Patch early 9.8 critical 19.8% 2018-02-26
CVE-2022-20695 A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to… Patch early 10.0 critical 19.8% 2022-04-15
CVE-2021-38390 A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior… Patch early 9.8 critical 19.8% 2021-08-30
CVE-2023-24775 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. Patch early 9.8 critical 19.8% 2023-03-07
← previous page 109 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt