peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,708 CVEs 1,734 on KEV 17,294 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,840 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-7689 A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0. In your normal cycle 9.8 critical 5.5% 2017-04-11
CVE-2017-12865 Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitr… In your normal cycle 9.8 critical 5.5% 2017-08-29
CVE-2017-0915 Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execut… In your normal cycle 9.8 critical 5.5% 2018-03-21
CVE-2017-0916 Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting i… In your normal cycle 9.8 critical 5.5% 2018-03-21
CVE-2022-24193 CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. In your normal cycle 9.8 critical 5.5% 2022-03-10
CVE-2022-26136 A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.… In your normal cycle 9.8 critical 5.5% 2022-07-20
CVE-2014-1477 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and… In your normal cycle 9.8 critical 5.5% 2014-02-06
CVE-2014-9761 Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of ser… In your normal cycle 9.8 critical 5.5% 2016-04-19
CVE-2023-3077 The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injec… In your normal cycle 9.8 critical 5.5% 2023-07-10
CVE-2016-8575 The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482. In your normal cycle 9.8 critical 5.5% 2017-01-28
CVE-2017-5342 In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.… In your normal cycle 9.8 critical 5.5% 2017-01-28
CVE-2017-5482 The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575. In your normal cycle 9.8 critical 5.5% 2017-01-28
CVE-2016-3551 Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows r… In your normal cycle 9.8 critical 5.5% 2016-10-25
CVE-2016-4024 Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which… In your normal cycle 9.8 critical 5.5% 2016-05-13
CVE-2020-6967 In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exp… In your normal cycle 9.8 critical 5.5% 2020-03-23
CVE-2026-26216 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks param… In your normal cycle 10.0 critical 5.5% 2026-02-12
CVE-2016-0940 Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Ac… In your normal cycle 9.8 critical 5.5% 2016-01-14
CVE-2020-16204 The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on th… In your normal cycle 9.8 critical 5.5% 2020-09-01
CVE-2010-5325 Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of ser… In your normal cycle 9.8 critical 5.5% 2016-04-15
CVE-2018-1282 This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup tha… In your normal cycle 9.1 critical 5.5% 2018-04-05
CVE-2018-18628 An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize… In your normal cycle 9.8 critical 5.5% 2018-10-23
CVE-2017-11462 Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of securit… In your normal cycle 9.8 critical 5.5% 2017-09-13
CVE-2016-6290 ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which… In your normal cycle 9.8 critical 5.5% 2016-07-25
CVE-2016-3443 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via v… In your normal cycle 9.6 critical 5.5% 2016-04-21
CVE-2016-3444 Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows r… In your normal cycle 9.8 critical 5.5% 2016-07-21
CVE-2016-3468 Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows r… In your normal cycle 9.8 critical 5.5% 2016-07-21
CVE-2016-3613 Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect… In your normal cycle 9.8 critical 5.5% 2016-07-21
CVE-2017-6747 A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local a… In your normal cycle 9.8 critical 5.5% 2017-08-07
CVE-2022-26585 Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. In your normal cycle 9.8 critical 5.5% 2022-04-05
CVE-2020-10224 An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be expl… In your normal cycle 9.8 critical 5.5% 2020-03-08
← previous page 184 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt