peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,123 CVEs 1,733 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

36,709 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-31819 An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.p… Patch early 9.8 critical 15.6% 2024-04-10
CVE-2021-3437 Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of ser… Patch early 9.8 critical 15.6% 2022-12-12
CVE-2023-22501 An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user… Patch early 9.1 critical 15.5% 2023-02-01
CVE-2023-38944 An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control an… Patch early 9.8 critical 15.5% 2024-03-06
CVE-2025-4322 The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to… Patch early 9.8 critical 15.5% 2025-05-20
CVE-2024-42812 In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who… Patch early 9.8 critical 15.5% 2024-08-19
CVE-2020-4210 IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… Patch early 9.8 critical 15.5% 2020-02-24
CVE-2020-4213 IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… Patch early 9.8 critical 15.5% 2020-02-24
CVE-2020-4222 IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… Patch early 9.8 critical 15.5% 2020-02-24
CVE-2016-5771 spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage col… Patch early 9.8 critical 15.5% 2016-08-07
CVE-2019-10655 Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unaut… Patch early 9.8 critical 15.5% 2019-03-30
CVE-2018-18556 A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary with elevat… Patch early 9.9 critical 15.4% 2018-12-17
CVE-2025-43564 ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file… Patch early 9.1 critical 15.4% 2025-05-13
CVE-2018-4947 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2018-4948 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2018-4966 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2018-4968 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2018-4978 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2018-4984 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerab… Patch early 9.8 critical 15.4% 2018-07-09
CVE-2019-0586 A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso… Patch early 9.8 critical 15.4% 2019-01-08
CVE-2024-1305 tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overfl… Patch early 9.8 critical 15.4% 2024-07-08
CVE-2024-10542 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an autho… Patch early 9.8 critical 15.4% 2024-11-26
CVE-2024-42905 Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device a… Patch early 9.8 critical 15.4% 2024-08-28
CVE-2016-8511 A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10… Patch early 9.8 critical 15.3% 2018-02-15
CVE-2018-17936 NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the serve… Patch early 9.8 critical 15.3% 2018-11-27
CVE-2025-43563 ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file… Patch early 9.1 critical 15.3% 2025-05-13
CVE-2023-41998 Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows a… Patch early 9.8 critical 15.3% 2023-11-27
CVE-2017-17106 Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/pa… Patch early 9.8 critical 15.3% 2017-12-19
CVE-2019-17361 In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticate… Patch early 9.8 critical 15.2% 2020-01-17
CVE-2015-2560 Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModify… Patch early 9.8 critical 15.2% 2017-08-02
← previous page 119 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt