peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,883 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-10684 In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attac… In your normal cycle 9.8 critical 4.9% 2017-06-29
CVE-2020-13109 Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in m… In your normal cycle 9.8 critical 4.9% 2020-05-16
CVE-2019-10789 All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanit… In your normal cycle 9.8 critical 4.9% 2020-02-06
CVE-2013-1751 TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl bac… In your normal cycle 9.8 critical 4.9% 2019-11-07
CVE-2026-2017 A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx… In your normal cycle 9.8 critical 4.9% 2026-02-06
CVE-2024-11639 An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access In your normal cycle 10.0 critical 4.9% 2024-12-10
CVE-2019-3463 Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to p… In your normal cycle 9.8 critical 4.9% 2019-02-06
CVE-2016-6646 The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.… In your normal cycle 9.8 critical 4.9% 2016-10-05
CVE-2018-11410 An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a… In your normal cycle 9.8 critical 4.9% 2018-05-24
CVE-2018-15497 The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this… In your normal cycle 9.8 critical 4.9% 2018-10-23
CVE-2020-27160 Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior… In your normal cycle 9.8 critical 4.9% 2020-10-27
CVE-2019-5600 In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELE… In your normal cycle 9.8 critical 4.9% 2019-07-03
CVE-2017-4918 VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful expl… In your normal cycle 9.8 critical 4.9% 2017-06-08
CVE-2019-7252 Linear eMerge E3-Series devices have Default Credentials. In your normal cycle 9.8 critical 4.9% 2019-07-02
CVE-2023-40057 The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an… In your normal cycle 9.0 critical 4.9% 2024-02-15
CVE-2019-1651 A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condit… In your normal cycle 9.9 critical 4.9% 2019-01-24
CVE-2020-3743 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3745 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3746 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3749 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3750 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3751 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2020-3754 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier h… In your normal cycle 9.8 critical 4.9% 2020-02-13
CVE-2022-36536 An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escala… In your normal cycle 9.8 critical 4.9% 2022-09-16
CVE-2014-9846 Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. In your normal cycle 9.8 critical 4.9% 2017-03-20
CVE-2020-24383 An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check for proper '\0' termination of t… In your normal cycle 9.1 critical 4.9% 2020-12-11
CVE-2021-21016 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful… In your normal cycle 9.1 critical 4.9% 2021-02-11
CVE-2017-16610 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not… In your normal cycle 9.8 critical 4.8% 2018-01-23
CVE-2016-7134 ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of serv… In your normal cycle 9.8 critical 4.8% 2016-09-12
CVE-2016-4250 Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.8% 2016-07-13
← previous page 198 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt