peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,674 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,840 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-61511 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the t… In your normal cycle 9.8 critical 5.6% 2026-07-27
CVE-2018-8845 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcce… In your normal cycle 9.8 critical 5.6% 2018-05-15
CVE-2022-24702 An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution vi… In your normal cycle 9.8 critical 5.6% 2022-06-02
CVE-2015-8367 The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory… In your normal cycle 9.8 critical 5.6% 2020-01-14
CVE-2021-24741 The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, c… In your normal cycle 9.8 critical 5.6% 2021-09-20
CVE-2016-4265 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.6% 2016-08-26
CVE-2016-4266 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.6% 2016-08-26
CVE-2016-4268 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.6% 2016-08-26
CVE-2016-4269 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.6% 2016-08-26
CVE-2016-4270 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 5.6% 2016-08-26
CVE-2026-20186 A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… In your normal cycle 9.9 critical 5.6% 2026-04-15
CVE-2019-7020 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 5.6% 2019-05-24
CVE-2019-7085 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 5.6% 2019-05-24
CVE-2021-27856 FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privil… In your normal cycle 9.8 critical 5.6% 2021-12-15
CVE-2016-6291 The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers… In your normal cycle 9.8 critical 5.6% 2016-07-25
CVE-2016-6813 Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is ab… In your normal cycle 9.8 critical 5.6% 2018-02-06
CVE-2020-14100 In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator… In your normal cycle 9.8 critical 5.6% 2020-09-11
CVE-2018-17141 HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit ena… In your normal cycle 9.8 critical 5.6% 2018-09-21
CVE-2018-0308 A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… In your normal cycle 9.8 critical 5.6% 2018-06-20
CVE-2018-0312 A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker… In your normal cycle 9.8 critical 5.6% 2018-06-20
CVE-2017-16926 Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (… In your normal cycle 9.8 critical 5.6% 2017-11-22
CVE-2024-5535 Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory cont… In your normal cycle 9.1 critical 5.6% 2024-06-27
CVE-2016-1363 Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through… In your normal cycle 9.8 critical 5.6% 2016-04-21
CVE-2021-33885 An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to… In your normal cycle 10.0 critical 5.6% 2021-08-25
CVE-2017-5897 The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags i… In your normal cycle 9.8 critical 5.6% 2017-03-23
CVE-2024-3673 The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inc… In your normal cycle 9.1 critical 5.6% 2024-08-30
CVE-2022-29774 iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. In your normal cycle 9.8 critical 5.6% 2022-06-21
CVE-2025-14346 WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pai… In your normal cycle 9.8 critical 5.6% 2026-01-05
CVE-2020-10917 This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not requi… In your normal cycle 9.8 critical 5.6% 2020-07-22
CVE-2014-5044 Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application cra… In your normal cycle 9.8 critical 5.6% 2018-03-07
← previous page 182 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt