peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

36,711 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-26897 Windows DNS Server Remote Code Execution Vulnerability Patch early 9.8 critical 11.6% 2021-03-11
CVE-2023-26068 Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). Patch early 9.8 critical 11.6% 2023-04-10
CVE-2018-4958 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4959 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4961 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4977 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4983 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4988 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2018-4989 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnera… Patch early 9.8 critical 11.6% 2018-07-09
CVE-2022-3184 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to ac… Patch early 9.8 critical 11.6% 2022-12-21
CVE-2024-52765 H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. Patch early 9.8 critical 11.6% 2024-11-20
CVE-2018-1000120 A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or w… Patch early 9.8 critical 11.6% 2018-03-14
CVE-2022-0817 The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to… Patch early 9.8 critical 11.6% 2022-05-09
CVE-2017-12377 ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of… Patch early 9.8 critical 11.6% 2018-01-26
CVE-2025-45488 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter… Patch early 9.8 critical 11.6% 2025-05-06
CVE-2021-38408 A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user… Patch early 9.8 critical 11.6% 2021-09-09
CVE-2022-25450 Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. Patch early 9.8 critical 11.6% 2022-03-18
CVE-2020-15639 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is… Patch early 9.8 critical 11.5% 2020-08-25
CVE-2018-20338 Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. Patch early 9.8 critical 11.5% 2018-12-21
CVE-2018-4872 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier v… Patch early 10.0 critical 11.5% 2018-02-27
CVE-2020-12001 FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:… Patch early 9.8 critical 11.5% 2020-06-15
CVE-2021-25831 A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of th… Patch early 9.8 critical 11.5% 2021-03-01
CVE-2019-9653 NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to ha… Patch early 9.8 critical 11.5% 2019-05-31
CVE-2025-28146 Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/… Patch early 9.8 critical 11.5% 2025-04-04
CVE-2016-1051 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… Patch early 9.8 critical 11.5% 2016-05-11
CVE-2025-45487 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. Patch early 9.8 critical 11.5% 2025-05-06
CVE-2019-0719 A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticat… Patch early 9.1 critical 11.4% 2019-11-12
CVE-2024-7261 The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earl… Patch early 9.8 critical 11.4% 2024-09-03
CVE-2019-14813 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, ena… Patch early 9.8 critical 11.4% 2019-09-06
CVE-2022-25347 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrar… Patch early 9.8 critical 11.4% 2022-03-29
← previous page 129 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt