peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,573 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,743 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-23898 MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. In your normal cycle 9.8 critical 7.7% 2022-03-03
CVE-2025-50475 An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary… In your normal cycle 9.8 critical 7.7% 2025-07-31
CVE-2015-7512 Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial… In your normal cycle 9.0 critical 7.7% 2016-01-08
CVE-2018-20377 Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full contr… In your normal cycle 9.8 critical 7.7% 2018-12-23
CVE-2019-20451 The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and reque… In your normal cycle 9.8 critical 7.7% 2020-02-10
CVE-2020-16245 Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/d… In your normal cycle 9.8 critical 7.7% 2020-08-25
CVE-2017-8809 api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. In your normal cycle 9.8 critical 7.7% 2017-11-15
CVE-2016-0916 EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary… In your normal cycle 9.8 critical 7.7% 2016-06-10
CVE-2018-18471 /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can… In your normal cycle 9.8 critical 7.7% 2019-06-19
CVE-2015-8876 Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows re… In your normal cycle 9.8 critical 7.7% 2016-05-22
CVE-2016-9052 An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially craft… In your normal cycle 9.8 critical 7.7% 2017-01-26
CVE-2016-9054 An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially craft… In your normal cycle 9.8 critical 7.7% 2017-01-26
CVE-2023-34132 Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affe… In your normal cycle 9.8 critical 7.7% 2023-07-13
CVE-2015-5073 Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service… In your normal cycle 9.1 critical 7.7% 2016-12-13
CVE-2018-20985 The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. In your normal cycle 9.8 critical 7.7% 2019-08-22
CVE-2022-0949 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape… In your normal cycle 9.8 critical 7.7% 2022-04-11
CVE-2017-8404 An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings rec… In your normal cycle 9.8 critical 7.7% 2019-07-02
CVE-2025-59246 Azure Entra ID Elevation of Privilege Vulnerability In your normal cycle 9.8 critical 7.7% 2025-10-09
CVE-2018-15484 An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP i… In your normal cycle 9.8 critical 7.7% 2018-09-07
CVE-2024-11772 Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve… In your normal cycle 9.1 critical 7.7% 2024-12-10
CVE-2019-1384 A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerabil… In your normal cycle 9.9 critical 7.6% 2019-11-12
CVE-2020-35575 A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pane… In your normal cycle 9.8 critical 7.6% 2020-12-26
CVE-2021-24527 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of… In your normal cycle 9.8 critical 7.6% 2021-08-16
CVE-2017-3060 Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful ex… In your normal cycle 9.8 critical 7.6% 2017-04-12
CVE-2018-7121 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. In your normal cycle 9.8 critical 7.6% 2019-06-05
CVE-2019-15311 An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker… In your normal cycle 9.8 critical 7.6% 2020-07-01
CVE-2019-11234 FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. In your normal cycle 9.8 critical 7.6% 2019-04-22
CVE-2018-7532 Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras,… In your normal cycle 9.8 critical 7.6% 2018-03-22
CVE-2019-11356 The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted… In your normal cycle 9.8 critical 7.6% 2019-06-03
CVE-2019-15505 drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be re… In your normal cycle 9.8 critical 7.6% 2019-08-23
← previous page 151 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt