peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,590 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,743 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-17066 An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functio… In your normal cycle 9.8 critical 7.3% 2018-09-15
CVE-2016-9053 An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3. A special… In your normal cycle 9.8 critical 7.2% 2017-02-21
CVE-2025-24865 The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retr… In your normal cycle 10.0 critical 7.2% 2025-02-13
CVE-2019-11994 A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600… In your normal cycle 9.8 critical 7.2% 2020-01-03
CVE-2020-24639 There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwa… In your normal cycle 9.8 critical 7.2% 2021-01-15
CVE-2021-41646 Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasse… In your normal cycle 9.8 critical 7.2% 2021-10-29
CVE-2024-20450 Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series… In your normal cycle 9.8 critical 7.2% 2024-08-07
CVE-2023-37924 Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now w… In your normal cycle 9.8 critical 7.2% 2023-11-22
CVE-2020-11982 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) d… In your normal cycle 9.8 critical 7.2% 2020-07-17
CVE-2022-31976 Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request. In your normal cycle 9.8 critical 7.2% 2022-06-02
CVE-2022-31977 Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team. In your normal cycle 9.8 critical 7.2% 2022-06-02
CVE-2022-31978 Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry. In your normal cycle 9.8 critical 7.2% 2022-06-02
CVE-2014-125117 A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploit… In your normal cycle 9.8 critical 7.2% 2025-07-25
CVE-2022-24049 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11… In your normal cycle 9.8 critical 7.2% 2022-02-18
CVE-2024-28189 Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacke… In your normal cycle 10.0 critical 7.2% 2024-04-18
CVE-2017-16740 A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. T… In your normal cycle 10.0 critical 7.2% 2018-01-09
CVE-2017-12633 The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De… In your normal cycle 9.8 critical 7.2% 2017-11-15
CVE-2017-12634 The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-… In your normal cycle 9.8 critical 7.2% 2017-11-15
CVE-2022-34598 The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands. In your normal cycle 9.8 critical 7.2% 2022-07-06
CVE-2016-6949 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 7.2% 2016-10-13
CVE-2017-8923 The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length… In your normal cycle 9.8 critical 7.2% 2017-05-12
CVE-2024-51092 LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsC… In your normal cycle 9.1 critical 7.2% 2026-05-08
CVE-2019-1010060 NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were… In your normal cycle 9.8 critical 7.2% 2019-07-16
CVE-2018-5097 A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content d… In your normal cycle 9.8 critical 7.2% 2018-06-11
CVE-2018-5104 A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploi… In your normal cycle 9.8 critical 7.2% 2018-06-11
CVE-2022-4873 On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of… In your normal cycle 9.8 critical 7.2% 2023-01-11
CVE-2026-23523 Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install… In your normal cycle 9.6 critical 7.2% 2026-01-16
CVE-2026-33453 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's cam… In your normal cycle 10.0 critical 7.2% 2026-04-27
CVE-2004-0434 k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing l… In your normal cycle 9.8 critical 7.2% 2004-07-07
CVE-2024-6385 An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting f… In your normal cycle 9.6 critical 7.2% 2024-07-11
← previous page 155 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt