peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,546 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,735 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-15607 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15608 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15609 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15610 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15613 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15614 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2020-15615 This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i… In your normal cycle 9.8 critical 8.1% 2020-07-28
CVE-2023-31985 A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept fu… In your normal cycle 9.8 critical 8.1% 2023-05-12
CVE-2018-1000666 GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Spec… In your normal cycle 9.8 critical 8.1% 2018-09-06
CVE-2021-37762 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. In your normal cycle 9.8 critical 8.1% 2021-10-07
CVE-2016-1453 Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote… In your normal cycle 9.8 critical 8.1% 2016-10-06
CVE-2020-28037 is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might all… In your normal cycle 9.8 critical 8.1% 2020-11-02
CVE-2022-29361 Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request… In your normal cycle 9.8 critical 8.1% 2022-05-25
CVE-2025-59934 Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems… In your normal cycle 9.4 critical 8.1% 2025-09-26
CVE-2017-11303 An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful e… In your normal cycle 9.8 critical 8.1% 2017-12-09
CVE-2021-32930 The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arb… In your normal cycle 9.8 critical 8.1% 2021-06-11
CVE-2020-4415 IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote… In your normal cycle 9.8 critical 8.1% 2020-04-23
CVE-2018-20664 Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. In your normal cycle 9.8 critical 8.1% 2019-01-03
CVE-2026-58455 Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comma… In your normal cycle 9.8 critical 8% 2026-07-02
CVE-2018-7124 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. In your normal cycle 9.8 critical 8% 2019-06-05
CVE-2019-5367 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. In your normal cycle 9.8 critical 8% 2019-06-05
CVE-2025-32711 Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. In your normal cycle 9.3 critical 8% 2025-06-11
CVE-2018-12822 Adobe Digital Editions versions 4.5.8 and below have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. In your normal cycle 9.8 critical 8% 2018-10-17
CVE-2018-16618 VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttrans… In your normal cycle 9.8 critical 8% 2019-06-19
CVE-2018-1000007 libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcu… In your normal cycle 9.8 critical 8% 2018-01-24
CVE-2025-53766 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. In your normal cycle 9.8 critical 8% 2025-08-12
CVE-2016-6809 Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do… In your normal cycle 9.8 critical 8% 2017-04-06
CVE-2022-1057 The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL stateme… In your normal cycle 9.8 critical 8% 2022-07-11
CVE-2021-41833 Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. In your normal cycle 9.8 critical 8% 2021-11-11
CVE-2023-34152 A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. In your normal cycle 9.8 critical 8% 2023-05-30
← previous page 148 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt