peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,851 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-07

36,871 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-39765 Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… In your normal cycle 9.1 critical 5.2% 2025-01-14
CVE-2014-3005 XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows… In your normal cycle 9.8 critical 5.2% 2018-02-01
CVE-2016-0959 Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, A… In your normal cycle 9.8 critical 5.2% 2017-06-27
CVE-2017-7555 Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could sen… In your normal cycle 9.8 critical 5.2% 2017-08-17
CVE-2020-7203 A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow re… In your normal cycle 9.8 critical 5.2% 2020-12-18
CVE-2022-25330 Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or a… In your normal cycle 9.8 critical 5.2% 2022-02-24
CVE-2017-11563 D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions suc… In your normal cycle 9.8 critical 5.2% 2018-08-24
CVE-2018-4148 An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. A buffer overflow allows… In your normal cycle 9.8 critical 5.2% 2018-04-03
CVE-2018-11711 A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors in… In your normal cycle 9.8 critical 5.2% 2018-06-04
CVE-2016-9013 Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running… In your normal cycle 9.8 critical 5.2% 2016-12-09
CVE-2020-15900 A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file acces… In your normal cycle 9.8 critical 5.2% 2020-07-28
CVE-2021-28152 Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port… In your normal cycle 9.8 critical 5.2% 2021-05-06
CVE-2019-7098 Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… In your normal cycle 9.8 critical 5.2% 2019-05-23
CVE-2019-7099 Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… In your normal cycle 9.8 critical 5.2% 2019-05-23
CVE-2019-7100 Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… In your normal cycle 9.8 critical 5.2% 2019-05-23
CVE-2019-7103 Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code ex… In your normal cycle 9.8 critical 5.2% 2019-05-23
CVE-2020-15782 A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.… In your normal cycle 9.8 critical 5.2% 2021-05-28
CVE-2017-6034 An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in… In your normal cycle 9.8 critical 5.2% 2017-06-30
CVE-2017-3216 WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthen… In your normal cycle 9.8 critical 5.2% 2017-06-20
CVE-2020-11548 The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remo… In your normal cycle 9.8 critical 5.2% 2020-04-05
CVE-2016-4344 Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly… In your normal cycle 9.8 critical 5.2% 2016-05-22
CVE-2016-4345 Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denia… In your normal cycle 9.8 critical 5.2% 2016-05-22
CVE-2019-10202 A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525,… In your normal cycle 9.8 critical 5.2% 2019-10-01
CVE-2016-10115 NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fir… In your normal cycle 9.8 critical 5.2% 2017-01-04
CVE-2021-28134 Clipper before 1.0.5 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC inter… In your normal cycle 9.8 critical 5.2% 2021-03-11
CVE-2019-7834 Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015… In your normal cycle 9.8 critical 5.2% 2019-05-22
CVE-2017-12229 A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attac… In your normal cycle 9.8 critical 5.2% 2017-09-29
CVE-2019-5138 An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A spec… In your normal cycle 9.9 critical 5.2% 2020-02-25
CVE-2017-7898 An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-lo… In your normal cycle 9.8 critical 5.2% 2017-06-30
CVE-2018-1337 In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before… In your normal cycle 9.8 critical 5.2% 2018-07-10
← previous page 189 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt