peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,957 CVEs 1,734 on KEV 17,295 EPSS ≥ 10% 25,091 with exploits synced 2026-10-06

36,763 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1044 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 10.0 critical 6.9% 2016-05-11
CVE-2025-15501 A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the… In your normal cycle 9.8 critical 6.9% 2026-01-09
CVE-2016-1761 libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of se… In your normal cycle 9.8 critical 6.9% 2016-03-24
CVE-2018-13818 Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is no… In your normal cycle 9.8 critical 6.9% 2018-07-10
CVE-2020-24650 A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7142 A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) versio… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7143 A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7144 A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) versi… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7146 A devgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7149 A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) ver… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7150 A faultstatchoosefaulttype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7154 A ifviewselectpage expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7159 A customtemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) ver… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7167 A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) vers… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7171 A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s)… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-7172 A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s… In your normal cycle 9.8 critical 6.9% 2020-10-19
CVE-2020-36705 The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image func… In your normal cycle 9.8 critical 6.9% 2023-06-07
CVE-2024-3566 A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fun… In your normal cycle 9.8 critical 6.9% 2024-04-10
CVE-2021-29921 In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allo… In your normal cycle 9.8 critical 6.9% 2021-05-06
CVE-2017-14596 In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password. In your normal cycle 9.8 critical 6.9% 2017-09-20
CVE-2017-3086 Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary c… In your normal cycle 9.8 critical 6.9% 2017-06-20
CVE-2015-8386 PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a deni… In your normal cycle 9.8 critical 6.9% 2015-12-02
CVE-2018-12113 Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response. In your normal cycle 9.8 critical 6.9% 2018-07-05
CVE-2016-9051 An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A… In your normal cycle 9.8 critical 6.9% 2017-02-21
CVE-2025-25948 Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1… In your normal cycle 9.1 critical 6.9% 2025-03-03
CVE-2025-45985 Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0… In your normal cycle 9.8 critical 6.9% 2025-06-13
CVE-2018-10592 Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4… In your normal cycle 9.8 critical 6.9% 2018-07-31
CVE-2019-3925 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3… In your normal cycle 9.8 critical 6.9% 2019-04-30
CVE-2019-3926 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.… In your normal cycle 9.8 critical 6.9% 2019-04-30
CVE-2016-1327 Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary co… In your normal cycle 9.8 critical 6.9% 2016-03-09
← previous page 160 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt