peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,295 CVEs 1,734 on KEV 17,292 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

36,710 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-25579 TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. Patch early 9.8 critical 10.4% 2025-03-28
CVE-2013-5618 Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox b… Patch early 9.8 critical 10.4% 2013-12-11
CVE-2018-20555 The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, cons… Patch early 9.8 critical 10.4% 2019-03-21
CVE-2025-1302 Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can… Patch early 9.8 critical 10.4% 2025-02-15
CVE-2022-37056 D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main, Patch early 9.8 critical 10.4% 2022-08-28
CVE-2026-20147 A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating… Patch early 9.9 critical 10.4% 2026-04-15
CVE-2021-38389 Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. Patch early 9.8 critical 10.4% 2021-10-18
CVE-2024-4443 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listing… Patch early 9.8 critical 10.4% 2024-05-22
CVE-2023-20078 Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute a… Patch early 9.8 critical 10.4% 2023-03-03
CVE-2024-6127 BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can… Patch early 9.8 critical 10.3% 2024-06-27
CVE-2023-20079 Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute a… Patch early 9.8 critical 10.3% 2023-03-03
CVE-2016-5018 In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able t… Patch early 9.1 critical 10.3% 2017-08-10
CVE-2018-7364 All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper… Patch early 9.8 critical 10.3% 2018-12-07
CVE-2025-50165 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. Patch early 9.8 critical 10.3% 2025-08-12
CVE-2022-23747 In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during mus… Patch early 9.8 critical 10.2% 2022-08-17
CVE-2015-7182 Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefo… Patch early 9.8 critical 10.2% 2015-11-05
CVE-2016-1995 HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. Patch early 9.8 critical 10.2% 2016-03-18
CVE-2017-8956 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. Patch early 9.8 critical 10.2% 2018-02-15
CVE-2019-17626 ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<spa… Patch early 9.8 critical 10.2% 2019-10-16
CVE-2016-0639 Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and… Patch early 9.8 critical 10.2% 2016-04-21
CVE-2018-13338 System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter du… Patch early 9.8 critical 10.2% 2018-11-27
CVE-2019-7964 Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code executio… Patch early 9.8 critical 10.2% 2019-08-16
CVE-2016-7406 Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) u… Patch early 9.8 critical 10.2% 2017-03-03
CVE-2018-7183 Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an n… Patch early 9.8 critical 10.2% 2018-03-08
CVE-2016-10150 Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to… Patch early 9.8 critical 10.2% 2017-02-06
CVE-2025-55754 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log mess… Patch early 9.6 critical 10.2% 2025-10-27
CVE-2022-0592 The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to… Patch early 9.8 critical 10.2% 2022-05-09
CVE-2024-4295 The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and inclu… Patch early 9.8 critical 10.2% 2024-06-05
CVE-2022-32386 Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan. Patch early 9.8 critical 10.2% 2022-07-06
CVE-2008-0062 KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service… Patch early 9.8 critical 10.1% 2008-03-19
← previous page 134 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt