peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,599 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,836 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-8271 The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code. In your normal cycle 9.8 critical 5.9% 2017-04-13
CVE-2017-3184 ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page… In your normal cycle 9.8 critical 5.9% 2017-12-16
CVE-2022-28032 AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php In your normal cycle 9.8 critical 5.9% 2022-04-12
CVE-2018-1000301 curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl… In your normal cycle 9.1 critical 5.9% 2018-05-24
CVE-2019-8070 Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could… In your normal cycle 9.8 critical 5.9% 2019-09-12
CVE-2017-17790 The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by… In your normal cycle 9.8 critical 5.9% 2017-12-20
CVE-2021-28797 A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerabilit… In your normal cycle 9.8 critical 5.9% 2021-04-14
CVE-2017-12883 Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to discl… In your normal cycle 9.1 critical 5.9% 2017-09-19
CVE-2016-1621 libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary cod… In your normal cycle 9.8 critical 5.9% 2016-03-12
CVE-2020-8899 There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, un… In your normal cycle 9.8 critical 5.9% 2020-05-06
CVE-2019-5477 A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Proc… In your normal cycle 9.8 critical 5.9% 2019-08-16
CVE-2020-5723 The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords… In your normal cycle 9.8 critical 5.9% 2020-03-30
CVE-2018-5473 An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmware… In your normal cycle 9.8 critical 5.9% 2018-02-19
CVE-2018-0314 A vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote at… In your normal cycle 9.8 critical 5.9% 2018-06-20
CVE-2022-1950 The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to… In your normal cycle 9.8 critical 5.9% 2022-08-01
CVE-2019-1010268 Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, r… In your normal cycle 9.8 critical 5.9% 2019-07-18
CVE-2017-8023 EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrex… In your normal cycle 9.8 critical 5.9% 2019-04-01
CVE-2024-39762 Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… In your normal cycle 9.1 critical 5.9% 2025-01-14
CVE-2025-60724 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. In your normal cycle 9.8 critical 5.9% 2025-11-11
CVE-2016-1074 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.9% 2016-05-11
CVE-2021-34684 Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and… In your normal cycle 9.8 critical 5.9% 2021-11-08
CVE-2019-5953 Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspeci… In your normal cycle 9.8 critical 5.9% 2019-05-17
CVE-2020-13576 A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to… In your normal cycle 9.8 critical 5.9% 2021-02-10
CVE-2018-4124 An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11… In your normal cycle 9.8 critical 5.9% 2018-04-03
CVE-2020-1025 An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation… In your normal cycle 9.8 critical 5.9% 2020-07-14
CVE-2017-11295 An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploita… In your normal cycle 9.8 critical 5.9% 2017-12-09
CVE-2025-14709 A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/… In your normal cycle 9.8 critical 5.9% 2025-12-15
CVE-2018-7081 A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit… In your normal cycle 9.8 critical 5.9% 2019-09-13
CVE-2022-0715 A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leake… In your normal cycle 9.1 critical 5.8% 2022-03-09
CVE-2019-9945 SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie.… In your normal cycle 9.8 critical 5.8% 2019-03-23
← previous page 176 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt