peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,267 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

36,711 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-37642 TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCh… Patch early 9.1 critical 11.4% 2024-06-14
CVE-2022-35559 A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and pi… Patch early 9.8 critical 11.4% 2022-08-12
CVE-2021-26432 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability Patch early 9.8 critical 11.3% 2021-08-12
CVE-2023-46220 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 11.3% 2023-12-19
CVE-2023-46225 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 11.3% 2023-12-19
CVE-2023-46257 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 11.3% 2023-12-19
CVE-2023-46259 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 11.3% 2023-12-19
CVE-2023-46261 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 11.3% 2023-12-19
CVE-2019-13462 Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. Patch early 9.1 critical 11.3% 2019-08-12
CVE-2025-13184 Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9… Patch early 9.8 critical 11.3% 2025-12-10
CVE-2017-0372 Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. Patch early 9.8 critical 11.3% 2018-04-13
CVE-2022-35698 Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of th… Patch early 10.0 critical 11.3% 2022-10-14
CVE-2026-33478 WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain togeth… Patch early 10.0 critical 11.2% 2026-03-23
CVE-2022-20780 Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM)… Patch early 9.9 critical 11.2% 2022-05-04
CVE-2022-25759 The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. Patch early 9.9 critical 11.2% 2022-07-22
CVE-2024-33699 The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator pas… Patch early 9.9 critical 11.2% 2024-10-30
CVE-2018-12813 Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. Patch early 9.8 critical 11.2% 2018-10-17
CVE-2018-12814 Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. Patch early 9.8 critical 11.2% 2018-10-17
CVE-2004-0005 Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding… Patch early 9.8 critical 11.2% 2004-03-03
CVE-2017-8817 The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application c… Patch early 9.8 critical 11.2% 2017-11-29
CVE-2023-23489 The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' para… Patch early 9.8 critical 11.2% 2023-01-20
CVE-2001-0248 Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT comman… Patch early 9.8 critical 11.2% 2001-06-18
CVE-2020-8298 fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeS… Patch early 9.8 critical 11.2% 2021-03-04
CVE-2025-52376 An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, al… Patch early 9.8 critical 11.2% 2025-07-15
CVE-2026-22778 vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimo… Patch early 9.8 critical 11.2% 2026-02-02
CVE-2018-5353 The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privilege… Patch early 9.8 critical 11.1% 2020-09-30
CVE-2019-17638 In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 4… Patch early 9.4 critical 11.1% 2020-07-09
CVE-2016-10107 Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. Patch early 9.8 critical 11.1% 2017-01-03
CVE-2021-41560 OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. Patch early 9.8 critical 11.1% 2021-12-15
CVE-2019-17195 Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potentia… Patch early 9.8 critical 11.1% 2019-10-15
← previous page 130 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt