peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,599 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,836 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-14477 In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially craft… In your normal cycle 9.8 critical 6% 2018-05-09
CVE-2017-14478 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially craft… In your normal cycle 9.8 critical 6% 2018-05-09
CVE-2017-14479 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially cra… In your normal cycle 9.8 critical 6% 2018-05-09
CVE-2017-14480 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially cra… In your normal cycle 9.8 critical 6% 2018-05-09
CVE-2019-14699 An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filenam… In your normal cycle 9.8 critical 6% 2019-08-06
CVE-2020-14343 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes unt… In your normal cycle 9.8 critical 6% 2021-02-09
CVE-2024-12029 A remote code execution vulnerability exists in invoke-ai/invokeai versions 5.3.1 through 5.4.2 via the /api/v2/models/install API. The vulnerability… In your normal cycle 9.8 critical 6% 2025-03-20
CVE-2015-4650 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code wi… In your normal cycle 9.8 critical 6% 2017-10-16
CVE-2017-9034 Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root… In your normal cycle 9.8 critical 6% 2017-05-26
CVE-2024-52759 D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. In your normal cycle 9.8 critical 6% 2024-11-19
CVE-2023-35854 Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for… In your normal cycle 9.8 critical 6% 2023-06-20
CVE-2016-4210 Integer overflow in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader… In your normal cycle 9.8 critical 6% 2016-07-13
CVE-2019-19450 paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar… In your normal cycle 9.8 critical 6% 2023-09-20
CVE-2020-10055 A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications a… In your normal cycle 9.8 critical 6% 2020-08-14
CVE-2015-7806 Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote… In your normal cycle 9.8 critical 6% 2017-10-17
CVE-2018-17897 LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. In your normal cycle 9.8 critical 6% 2018-10-17
CVE-2025-6058 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function ho… In your normal cycle 9.8 critical 6% 2025-07-12
CVE-2017-14723 Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the pos… In your normal cycle 9.8 critical 6% 2017-09-23
CVE-2020-1032 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… In your normal cycle 9.0 critical 5.9% 2020-07-14
CVE-2020-1041 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… In your normal cycle 9.0 critical 5.9% 2020-07-14
CVE-2020-1043 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user o… In your normal cycle 9.0 critical 5.9% 2020-07-14
CVE-2024-29201 JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism… In your normal cycle 9.9 critical 5.9% 2024-03-29
CVE-2024-29202 JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vu… In your normal cycle 9.9 critical 5.9% 2024-03-29
CVE-2016-2245 HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. In your normal cycle 9.8 critical 5.9% 2016-03-19
CVE-2016-3587 Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availabil… In your normal cycle 9.6 critical 5.9% 2016-07-21
CVE-2016-3610 Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availabil… In your normal cycle 9.6 critical 5.9% 2016-07-21
CVE-2016-4072 The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fil… In your normal cycle 9.8 critical 5.9% 2016-05-20
CVE-2021-39675 In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privile… In your normal cycle 9.8 critical 5.9% 2022-02-11
CVE-2020-11995 A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use He… In your normal cycle 9.8 critical 5.9% 2021-01-11
CVE-2019-6742 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authenticatio… In your normal cycle 9.8 critical 5.9% 2019-06-03
← previous page 175 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt