peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,624 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,838 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-6965 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6967 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6968 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6971 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6979 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6988 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-6993 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2021-42338 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code inj… In your normal cycle 9.8 critical 5.8% 2021-11-19
CVE-2019-13548 CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack… In your normal cycle 9.8 critical 5.8% 2019-09-13
CVE-2019-9871 Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission. In your normal cycle 9.8 critical 5.8% 2019-05-31
CVE-2016-6957 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-1072 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.8% 2016-05-11
CVE-2016-7407 The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file. In your normal cycle 9.8 critical 5.8% 2017-03-03
CVE-2020-6831 A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitabl… In your normal cycle 9.8 critical 5.8% 2020-05-26
CVE-2024-32709 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-R… In your normal cycle 9.3 critical 5.8% 2024-04-24
CVE-2022-32092 D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi. In your normal cycle 9.8 critical 5.8% 2022-06-27
CVE-2020-3742 Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier… In your normal cycle 9.8 critical 5.8% 2020-02-13
CVE-2016-7415 Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote… In your normal cycle 9.8 critical 5.8% 2016-09-17
CVE-2016-6294 The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not prop… In your normal cycle 9.8 critical 5.8% 2016-07-25
CVE-2022-3782 keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An at… In your normal cycle 9.1 critical 5.8% 2023-01-13
CVE-2024-2667 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation… In your normal cycle 9.8 critical 5.8% 2024-05-02
CVE-2026-1709 A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.… In your normal cycle 9.4 critical 5.8% 2026-02-06
CVE-2024-23479 SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vu… In your normal cycle 9.6 critical 5.8% 2024-02-15
CVE-2016-6969 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2009-4013 Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers t… In your normal cycle 9.8 critical 5.8% 2010-02-02
CVE-2016-1089 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Ac… In your normal cycle 9.8 critical 5.8% 2016-10-13
CVE-2016-4520 Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to… In your normal cycle 9.8 critical 5.8% 2016-07-15
CVE-2016-6138 Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Securi… In your normal cycle 9.8 critical 5.8% 2016-08-05
CVE-2024-44349 A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the u… In your normal cycle 9.8 critical 5.8% 2024-10-08
CVE-2017-16548 The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allow… In your normal cycle 9.8 critical 5.8% 2017-11-06
← previous page 178 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt