peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,556 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,833 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-7130 Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution. In your normal cycle 9.8 critical 6.4% 2019-05-23
CVE-2016-2074 Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute a… In your normal cycle 9.8 critical 6.4% 2016-07-03
CVE-2023-53941 EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by in… In your normal cycle 9.8 critical 6.4% 2025-12-18
CVE-2016-1047 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… In your normal cycle 9.8 critical 6.4% 2016-05-11
CVE-2016-1048 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… In your normal cycle 9.8 critical 6.4% 2016-05-11
CVE-2016-1057 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Ac… In your normal cycle 9.8 critical 6.4% 2016-05-11
CVE-2018-17893 LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution. In your normal cycle 9.8 critical 6.4% 2018-10-17
CVE-2016-6890 Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 cert… In your normal cycle 9.8 critical 6.4% 2017-01-05
CVE-2018-0426 A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a… In your normal cycle 9.8 critical 6.4% 2018-10-05
CVE-2009-1048 The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and… In your normal cycle 9.8 critical 6.4% 2009-08-14
CVE-2016-4800 The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected reso… In your normal cycle 9.8 critical 6.4% 2017-04-13
CVE-2023-2780 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. In your normal cycle 9.8 critical 6.4% 2023-05-17
CVE-2021-44140 Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request… In your normal cycle 9.1 critical 6.4% 2021-11-24
CVE-2022-24977 ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe inte… In your normal cycle 9.8 critical 6.4% 2022-02-14
CVE-2018-0500 Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attack… In your normal cycle 9.8 critical 6.4% 2018-07-11
CVE-2018-1295 In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it… In your normal cycle 9.8 critical 6.3% 2018-04-02
CVE-2020-8087 SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as dem… In your normal cycle 9.8 critical 6.3% 2020-01-27
CVE-2013-7171 Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remo… In your normal cycle 9.8 critical 6.3% 2019-11-21
CVE-2016-1503 dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, misma… In your normal cycle 9.8 critical 6.3% 2016-04-18
CVE-2018-20961 In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi dr… In your normal cycle 9.8 critical 6.3% 2019-08-07
CVE-2023-28879 In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in… In your normal cycle 9.8 critical 6.3% 2023-03-31
CVE-2017-3037 Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerabil… In your normal cycle 9.8 critical 6.3% 2017-04-12
CVE-2016-4002 Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote a… In your normal cycle 9.8 critical 6.3% 2016-04-26
CVE-2018-11808 Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to dele… In your normal cycle 9.1 critical 6.3% 2018-06-06
CVE-2018-0001 A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection… In your normal cycle 9.8 critical 6.3% 2018-01-10
CVE-2019-7113 Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and e… In your normal cycle 9.8 critical 6.3% 2019-05-23
CVE-2017-17458 In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .… In your normal cycle 9.8 critical 6.3% 2017-12-07
CVE-2022-28915 D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm. In your normal cycle 9.8 critical 6.3% 2022-05-10
CVE-2017-1000228 nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function In your normal cycle 9.8 critical 6.3% 2017-11-17
CVE-2021-42230 Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter. In your normal cycle 9.8 critical 6.3% 2022-04-15
← previous page 168 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt