peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,735 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-7993 Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitr… In your normal cycle 9.8 critical 8.3% 2019-08-26
CVE-2014-0073 The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App… In your normal cycle 9.8 critical 8.3% 2017-10-30
CVE-2019-8271 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code exe… In your normal cycle 9.8 critical 8.3% 2019-03-08
CVE-2019-8273 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result… In your normal cycle 9.8 critical 8.3% 2019-03-08
CVE-2019-8274 UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result… In your normal cycle 9.8 critical 8.3% 2019-03-08
CVE-2022-31678 VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user t… In your normal cycle 9.1 critical 8.3% 2022-10-28
CVE-2017-8768 Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS com… In your normal cycle 9.8 critical 8.3% 2017-05-04
CVE-2019-11540 In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.… In your normal cycle 9.8 critical 8.3% 2019-04-26
CVE-2019-15310 An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could r… In your normal cycle 9.8 critical 8.3% 2020-07-01
CVE-2018-10682 An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authen… In your normal cycle 9.8 critical 8.3% 2018-05-09
CVE-2019-8073 ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Succ… In your normal cycle 9.8 critical 8.3% 2019-09-27
CVE-2020-17510 Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. In your normal cycle 9.8 critical 8.2% 2020-11-05
CVE-2024-39367 An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A special… In your normal cycle 9.1 critical 8.2% 2025-01-14
CVE-2021-3148 An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command… In your normal cycle 9.8 critical 8.2% 2021-02-27
CVE-2021-37160 A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before N… In your normal cycle 9.8 critical 8.2% 2021-08-02
CVE-2016-6795 In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for… In your normal cycle 9.8 critical 8.2% 2017-09-20
CVE-2015-0780 SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remot… In your normal cycle 9.8 critical 8.2% 2017-08-09
CVE-2021-3199 Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence i… In your normal cycle 9.8 critical 8.2% 2021-01-26
CVE-2018-20180 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process… In your normal cycle 9.8 critical 8.2% 2019-03-15
CVE-2018-20181 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process(… In your normal cycle 9.8 critical 8.2% 2019-03-15
CVE-2018-20182 rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results… In your normal cycle 9.8 critical 8.2% 2019-03-15
CVE-2019-1226 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne… In your normal cycle 9.8 critical 8.2% 2019-08-14
CVE-2023-31986 A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN functi… In your normal cycle 9.8 critical 8.2% 2023-05-15
CVE-2017-3207 The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externaliza… In your normal cycle 9.8 critical 8.2% 2018-06-11
CVE-2017-3202 The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes v… In your normal cycle 9.8 critical 8.2% 2018-06-11
CVE-2015-4601 PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected da… In your normal cycle 9.8 critical 8.2% 2016-05-16
CVE-2024-39759 Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially cr… In your normal cycle 10.0 critical 8.2% 2025-01-14
CVE-2024-39761 Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially cr… In your normal cycle 10.0 critical 8.2% 2025-01-14
CVE-2021-27274 This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… In your normal cycle 9.8 critical 8.2% 2021-03-29
CVE-2019-6808 A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which… In your normal cycle 9.8 critical 8.2% 2019-05-22
← previous page 146 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt