peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,317 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

36,711 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-40851 Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat. In your normal cycle 9.8 critical 9.7% 2022-09-23
CVE-2016-5772 Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x bef… In your normal cycle 9.8 critical 9.7% 2016-08-07
CVE-2018-4013 An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A special… In your normal cycle 9.8 critical 9.7% 2018-10-19
CVE-2017-5005 Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.31… In your normal cycle 9.8 critical 9.7% 2017-01-02
CVE-2016-3312 ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtain… In your normal cycle 9.1 critical 9.7% 2016-08-09
CVE-2017-13715 The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are init… In your normal cycle 9.8 critical 9.7% 2017-08-29
CVE-2018-18492 A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. T… In your normal cycle 9.8 critical 9.6% 2019-02-28
CVE-2021-33912 libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e… In your normal cycle 9.8 critical 9.6% 2022-01-19
CVE-2021-33913 libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail mess… In your normal cycle 9.8 critical 9.6% 2022-01-19
CVE-2016-5768 Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x befor… In your normal cycle 9.8 critical 9.6% 2016-08-07
CVE-2015-5739 The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct… In your normal cycle 9.8 critical 9.6% 2017-10-18
CVE-2022-4063 The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the… In your normal cycle 9.8 critical 9.6% 2022-12-19
CVE-2018-3937 An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.… In your normal cycle 9.1 critical 9.6% 2018-08-14
CVE-2025-8489 The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalati… In your normal cycle 9.8 critical 9.6% 2025-10-31
CVE-2018-12387 A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by… In your normal cycle 9.1 critical 9.6% 2018-10-18
CVE-2013-7459 Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute… In your normal cycle 9.8 critical 9.6% 2017-02-15
CVE-2020-7199 A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software… In your normal cycle 9.8 critical 9.6% 2020-12-02
CVE-2003-0356 Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary… In your normal cycle 9.8 critical 9.6% 2003-06-09
CVE-2025-39946 In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the… In your normal cycle 9.8 critical 9.6% 2025-10-04
CVE-2019-20504 service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell m… In your normal cycle 9.8 critical 9.6% 2020-03-09
CVE-2024-8785 In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry… In your normal cycle 9.8 critical 9.5% 2024-12-02
CVE-2021-37761 Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. In your normal cycle 9.8 critical 9.5% 2021-09-27
CVE-2021-37928 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. In your normal cycle 9.8 critical 9.5% 2021-10-07
CVE-2021-37929 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. In your normal cycle 9.8 critical 9.5% 2021-10-07
CVE-2021-37930 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. In your normal cycle 9.8 critical 9.5% 2021-10-07
CVE-2021-37931 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. In your normal cycle 9.8 critical 9.5% 2021-10-07
CVE-2022-22280 Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3… In your normal cycle 9.8 critical 9.5% 2022-07-29
CVE-2019-17146 This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not req… In your normal cycle 9.8 critical 9.5% 2020-01-07
CVE-2022-46475 D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. In your normal cycle 9.8 critical 9.5% 2023-01-17
CVE-2018-18313 Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. In your normal cycle 9.1 critical 9.5% 2018-12-07
← previous page 137 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt