peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,121 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,709 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-54466 Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap… Patch early 9.8 critical 17.3% 2025-08-15
CVE-2024-39932 Gogs through 0.13.0 allows argument injection during the previewing of changes. Patch early 9.9 critical 17.3% 2024-07-04
CVE-2016-2315 revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or… Patch early 9.8 critical 17.3% 2016-04-08
CVE-2018-4917 Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable heap overflow… Patch early 9.8 critical 17.3% 2018-05-19
CVE-2022-40624 pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerabil… Patch early 9.8 critical 17.3% 2022-12-20
CVE-2023-2071 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t… Patch early 9.8 critical 17.3% 2023-09-12
CVE-2016-6814 When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java ser… Patch early 9.8 critical 17.2% 2018-01-18
CVE-2020-7361 The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating… Patch early 9.6 critical 17.2% 2020-08-06
CVE-2019-7840 ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Suc… Patch early 9.8 critical 17.2% 2019-06-12
CVE-2018-10466 Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. Patch early 9.8 critical 17.2% 2018-05-29
CVE-2018-14916 LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. Patch early 9.1 critical 17.2% 2019-06-28
CVE-2018-8879 Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows… Patch early 9.8 critical 17.2% 2019-11-21
CVE-2025-24434 Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability tha… Patch early 9.1 critical 17.2% 2025-02-11
CVE-2021-27147 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP. Patch early 9.8 critical 17.1% 2021-02-10
CVE-2021-27160 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP. Patch early 9.8 critical 17.1% 2021-02-10
CVE-2021-27161 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP. Patch early 9.8 critical 17.1% 2021-02-10
CVE-2018-14706 System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to ex… Patch early 9.8 critical 17.1% 2018-12-03
CVE-2022-28452 Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. Patch early 9.8 critical 17.1% 2022-04-29
CVE-2013-10048 An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, resp… Patch early 9.8 critical 17.1% 2025-08-01
CVE-2018-0301 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management inte… Patch early 9.8 critical 17% 2018-06-20
CVE-2023-44018 Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node fu… Patch early 9.8 critical 17% 2023-09-27
CVE-2019-1306 A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azu… Patch early 9.8 critical 17% 2019-09-11
CVE-2021-43297 A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubb… Patch early 9.8 critical 17% 2022-01-10
CVE-2022-24218 An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. Patch early 9.1 critical 17% 2022-02-01
CVE-2022-29322 D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip. Patch early 9.8 critical 16.9% 2022-05-10
CVE-2021-28959 Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to re… Patch early 9.8 critical 16.9% 2021-04-30
CVE-2025-41115 SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by in… Patch early 10.0 critical 16.9% 2025-11-21
CVE-2023-30149 SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop… Patch early 9.8 critical 16.9% 2023-06-02
CVE-2019-1182 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne… Patch early 9.8 critical 16.9% 2019-08-14
CVE-2021-33266 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… Patch early 9.8 critical 16.9% 2021-12-01
← previous page 115 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt