peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,488 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-05

36,732 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-3466 A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attack… In your normal cycle 9.8 critical 8.7% 2021-03-25
CVE-2018-12756 Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnera… In your normal cycle 9.8 critical 8.7% 2018-07-20
CVE-2018-12802 Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Security Bypass vulner… In your normal cycle 9.8 critical 8.7% 2018-07-20
CVE-2020-7593 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO!… In your normal cycle 9.8 critical 8.7% 2020-07-14
CVE-2017-11274 Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code executi… In your normal cycle 9.8 critical 8.7% 2017-08-11
CVE-2017-3075 Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. S… In your normal cycle 9.8 critical 8.7% 2017-06-20
CVE-2017-3084 Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Success… In your normal cycle 9.8 critical 8.7% 2017-06-20
CVE-2017-3853 A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attack… In your normal cycle 9.8 critical 8.7% 2017-03-22
CVE-2016-6938 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Ac… In your normal cycle 9.8 critical 8.7% 2016-09-17
CVE-2017-8981 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found. In your normal cycle 9.8 critical 8.7% 2018-02-15
CVE-2021-26291 Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting i… In your normal cycle 9.1 critical 8.7% 2021-04-23
CVE-2022-20140 In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of pri… In your normal cycle 9.8 critical 8.7% 2022-06-15
CVE-2015-6435 An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5… In your normal cycle 9.8 critical 8.7% 2016-01-22
CVE-2018-5338 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanis… In your normal cycle 9.8 critical 8.7% 2018-04-18
CVE-2025-2620 A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler… In your normal cycle 9.8 critical 8.7% 2025-03-22
CVE-2023-39747 TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/Wla… In your normal cycle 9.8 critical 8.7% 2023-08-21
CVE-2023-39751 TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm. In your normal cycle 9.8 critical 8.7% 2023-08-21
CVE-2024-30163 Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_c… In your normal cycle 9.8 critical 8.7% 2024-06-07
CVE-2019-14896 A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could… In your normal cycle 9.8 critical 8.7% 2019-11-27
CVE-2022-35649 The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in… In your normal cycle 9.8 critical 8.7% 2022-07-25
CVE-2023-46977 TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth. In your normal cycle 9.8 critical 8.7% 2023-10-31
CVE-2017-5814 A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found. In your normal cycle 9.8 critical 8.7% 2018-02-15
CVE-2020-25483 An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the se… In your normal cycle 9.8 critical 8.7% 2020-10-23
CVE-2020-25367 A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exec… In your normal cycle 9.8 critical 8.6% 2021-11-04
CVE-2020-25368 A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exec… In your normal cycle 9.8 critical 8.6% 2021-11-04
CVE-2019-20330 FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. In your normal cycle 9.8 critical 8.6% 2020-01-03
CVE-2022-0658 The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to un… In your normal cycle 9.8 critical 8.6% 2022-03-14
CVE-2022-0787 The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statement… In your normal cycle 9.8 critical 8.6% 2022-03-28
CVE-2018-4944 Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary c… In your normal cycle 9.8 critical 8.6% 2018-05-19
CVE-2016-1000112 Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin In your normal cycle 9.1 critical 8.6% 2016-10-06
← previous page 142 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt