peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,567 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,739 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-11308 Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an expl… In your normal cycle 9.8 critical 8% 2018-05-19
CVE-2022-35741 Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity… In your normal cycle 9.8 critical 8% 2022-07-18
CVE-2018-4923 Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to arbitrary file deletion. In your normal cycle 9.1 critical 8% 2018-05-19
CVE-2019-12900 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. In your normal cycle 9.8 critical 8% 2019-06-19
CVE-2025-34515 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows a… In your normal cycle 9.8 critical 8% 2025-10-16
CVE-2016-5019 CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow… In your normal cycle 9.8 critical 8% 2016-10-03
CVE-2018-5341 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when upload… In your normal cycle 9.8 critical 8% 2018-04-18
CVE-2022-0788 The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL… In your normal cycle 9.8 critical 7.9% 2022-06-08
CVE-2020-28020 Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging th… In your normal cycle 9.8 critical 7.9% 2021-05-06
CVE-2017-1000158 CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-base… In your normal cycle 9.8 critical 7.9% 2017-11-17
CVE-2020-22211 SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. In your normal cycle 9.8 critical 7.9% 2021-06-16
CVE-2026-52806 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server… In your normal cycle 9.9 critical 7.9% 2026-06-24
CVE-2018-20177 rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() an… In your normal cycle 9.8 critical 7.9% 2019-03-15
CVE-2017-10672 Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a re… In your normal cycle 9.8 critical 7.9% 2017-06-29
CVE-2025-49825 Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 a… In your normal cycle 9.8 critical 7.9% 2025-06-17
CVE-2019-13640 In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metachar… In your normal cycle 9.8 critical 7.9% 2019-07-17
CVE-2021-33501 Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL. In your normal cycle 9.6 critical 7.9% 2021-07-19
CVE-2021-24212 The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to up… In your normal cycle 9.8 critical 7.9% 2021-04-05
CVE-2021-27710 Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allow… In your normal cycle 9.8 critical 7.9% 2021-04-14
CVE-2019-25487 SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by… In your normal cycle 9.8 critical 7.9% 2026-03-11
CVE-2023-45499 VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. In your normal cycle 9.8 critical 7.9% 2023-10-27
CVE-2021-25139 A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an app… In your normal cycle 9.8 critical 7.9% 2021-02-09
CVE-2019-19148 Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue i… In your normal cycle 9.8 critical 7.9% 2020-03-20
CVE-2020-15394 The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Re… In your normal cycle 9.8 critical 7.9% 2020-09-25
CVE-2016-4009 Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified… In your normal cycle 9.8 critical 7.9% 2016-04-13
CVE-2021-20617 Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an… In your normal cycle 9.8 critical 7.9% 2021-01-14
CVE-2016-4209 Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro… In your normal cycle 9.8 critical 7.9% 2016-07-13
CVE-2016-6994 Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acro… In your normal cycle 9.8 critical 7.9% 2016-10-13
CVE-2021-21124 Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sa… In your normal cycle 9.6 critical 7.9% 2021-02-09
CVE-2012-6437 The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whethe… In your normal cycle 9.8 critical 7.8% 2013-01-24
← previous page 149 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt