peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,585 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,835 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-24329 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRule… In your normal cycle 9.8 critical 6.2% 2024-01-30
CVE-2015-8299 Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted K… In your normal cycle 9.8 critical 6.2% 2017-08-29
CVE-2021-4473 Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated… In your normal cycle 9.8 critical 6.2% 2026-04-07
CVE-2026-10886 Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… In your normal cycle 9.6 critical 6.2% 2026-06-04
CVE-2020-27744 An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privile… In your normal cycle 9.8 critical 6.2% 2020-10-29
CVE-2020-29495 DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacke… In your normal cycle 10.0 critical 6.2% 2021-01-14
CVE-2016-0933 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 6.2% 2016-01-14
CVE-2018-7218 The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.2… In your normal cycle 9.8 critical 6.2% 2018-05-17
CVE-2019-7105 Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution. In your normal cycle 9.8 critical 6.2% 2019-05-23
CVE-2019-7106 Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution. In your normal cycle 9.8 critical 6.2% 2019-05-23
CVE-2016-1289 The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary… In your normal cycle 9.8 critical 6.2% 2016-07-02
CVE-2016-2337 Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can caus… In your normal cycle 9.8 critical 6.2% 2017-01-06
CVE-2017-3088 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitati… In your normal cycle 10.0 critical 6.2% 2017-06-20
CVE-2017-3089 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF imaging model. Successful exploitatio… In your normal cycle 9.8 critical 6.2% 2017-06-20
CVE-2017-3093 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the bitmap representation module. Successful… In your normal cycle 9.8 critical 6.2% 2017-06-20
CVE-2017-3094 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF processing engine. Successful exploit… In your normal cycle 9.8 critical 6.2% 2017-06-20
CVE-2017-3095 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF parsing engine. Successful exploitati… In your normal cycle 9.8 critical 6.2% 2017-06-20
CVE-2017-3096 Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the character code mapping module. Successful… In your normal cycle 9.8 critical 6.2% 2017-06-20
CVE-2016-7001 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 6.2% 2016-10-13
CVE-2016-7002 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 6.2% 2016-10-13
CVE-2016-7003 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 6.2% 2016-10-13
CVE-2016-7004 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 6.2% 2016-10-13
CVE-2018-14354 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquot… In your normal cycle 9.8 critical 6.2% 2018-07-17
CVE-2023-39796 SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_REC… In your normal cycle 9.8 critical 6.1% 2023-11-10
CVE-2019-14537 YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. In your normal cycle 9.8 critical 6.1% 2019-08-07
CVE-2026-38360 Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_… In your normal cycle 9.8 critical 6.1% 2026-05-08
CVE-2026-15748 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_uplo… In your normal cycle 9.8 critical 6.1% 2026-08-18
CVE-2019-18780 An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute… In your normal cycle 9.8 critical 6.1% 2019-11-05
CVE-2020-1946 In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. W… In your normal cycle 9.8 critical 6.1% 2021-03-25
CVE-2018-3779 active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An att… In your normal cycle 9.8 critical 6.1% 2018-08-10
← previous page 172 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt