peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,660 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,839 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-9582 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabilit… In your normal cycle 9.8 critical 5.7% 2020-06-26
CVE-2020-9583 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabilit… In your normal cycle 9.8 critical 5.7% 2020-06-26
CVE-2016-15042 The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file upload… In your normal cycle 9.8 critical 5.7% 2024-10-16
CVE-2019-8015 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 5.7% 2019-08-20
CVE-2020-23151 rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed di… In your normal cycle 9.8 critical 5.7% 2021-08-09
CVE-2016-4537 The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale… In your normal cycle 9.8 critical 5.7% 2016-05-22
CVE-2016-1040 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.7% 2016-05-11
CVE-2020-15049 An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can su… In your normal cycle 9.9 critical 5.7% 2020-06-30
CVE-2017-14632 Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi-… In your normal cycle 9.8 critical 5.7% 2017-09-21
CVE-2016-6948 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.7% 2016-10-13
CVE-2019-11062 The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploi… In your normal cycle 9.8 critical 5.7% 2019-07-11
CVE-2026-73034 DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the se… In your normal cycle 9.8 critical 5.7% 2026-08-11
CVE-2021-30120 Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of serve… In your normal cycle 9.9 critical 5.7% 2021-07-09
CVE-2026-19586 A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuff… In your normal cycle 9.8 critical 5.7% 2026-08-20
CVE-2010-5305 The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x… In your normal cycle 9.8 critical 5.7% 2019-03-26
CVE-2016-6254 Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a… In your normal cycle 9.1 critical 5.7% 2016-08-19
CVE-2022-26210 Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185… In your normal cycle 9.8 critical 5.7% 2022-03-15
CVE-2024-36412 SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events… In your normal cycle 10.0 critical 5.7% 2024-06-10
CVE-2018-19417 An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variab… In your normal cycle 10.0 critical 5.7% 2018-11-21
CVE-2017-10352 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). The supported version that is af… In your normal cycle 9.9 critical 5.7% 2017-10-19
CVE-2021-40146 A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulne… In your normal cycle 9.8 critical 5.7% 2021-09-11
CVE-2018-19707 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-19708 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-19715 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-16036 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-16037 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-16039 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2018-16040 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier versi… In your normal cycle 9.8 critical 5.7% 2019-01-18
CVE-2015-9262 _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a… In your normal cycle 9.8 critical 5.7% 2018-08-01
CVE-2017-8857 In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command executio… In your normal cycle 9.8 critical 5.7% 2017-05-09
← previous page 180 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt