peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,908 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,882 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-5885 Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers t… In your normal cycle 9.8 critical 5% 2017-02-28
CVE-2018-0238 A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, r… In your normal cycle 9.9 critical 5% 2018-04-19
CVE-2020-25763 Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution… In your normal cycle 9.8 critical 5% 2020-09-30
CVE-2019-12182 Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative… In your normal cycle 9.8 critical 5% 2020-03-13
CVE-2020-1963 Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fil… In your normal cycle 9.1 critical 5% 2020-06-03
CVE-2020-1959 A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading t… In your normal cycle 9.8 critical 5% 2020-05-04
CVE-2018-11061 RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to a server-side template inject… In your normal cycle 9.1 critical 5% 2018-08-24
CVE-2016-6903 lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. In your normal cycle 9.9 critical 5% 2017-04-24
CVE-2020-24914 A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileDat… In your normal cycle 9.8 critical 5% 2021-03-04
CVE-2018-18493 A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit… In your normal cycle 9.8 critical 5% 2019-02-28
CVE-2016-9558 (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted… In your normal cycle 9.8 critical 5% 2017-02-28
CVE-2019-1010174 CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack… In your normal cycle 9.8 critical 5% 2019-07-25
CVE-2013-1401 Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPr… In your normal cycle 9.8 critical 5% 2020-02-13
CVE-2015-5729 The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, whic… In your normal cycle 9.8 critical 5% 2017-03-23
CVE-2025-68706 A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetti… In your normal cycle 9.8 critical 5% 2025-12-29
CVE-2018-19081 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS me… In your normal cycle 9.8 critical 5% 2018-11-07
CVE-2019-10879 In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead to a buffer overflow and possi… In your normal cycle 9.8 critical 5% 2019-04-05
CVE-2020-15477 The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspb… In your normal cycle 9.8 critical 5% 2020-07-23
CVE-2016-4607 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… In your normal cycle 9.8 critical 5% 2016-07-22
CVE-2016-4610 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchO… In your normal cycle 9.8 critical 5% 2016-07-22
CVE-2014-2073 Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "C… In your normal cycle 9.8 critical 5% 2018-04-10
CVE-2020-8441 JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued… In your normal cycle 9.8 critical 5% 2020-02-19
CVE-2015-7939 Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename. In your normal cycle 9.6 critical 5% 2016-01-09
CVE-2015-2867 A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system. In your normal cycle 9.8 critical 5% 2017-01-06
CVE-2019-19842 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=sp… In your normal cycle 9.8 critical 5% 2020-01-22
CVE-2019-16335 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a… In your normal cycle 9.8 critical 5% 2019-09-15
CVE-2018-14350 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wit… In your normal cycle 9.8 critical 5% 2018-07-17
CVE-2022-25235 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a ce… In your normal cycle 9.8 critical 5% 2022-02-16
CVE-2018-14357 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquot… In your normal cycle 9.8 critical 5% 2018-07-17
CVE-2019-6823 A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker… In your normal cycle 9.8 critical 5% 2019-07-15
← previous page 195 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt