peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,941 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,885 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-42645 CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter… In your normal cycle 10.0 critical 4.8% 2022-05-10
CVE-2024-6460 The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible fo… In your normal cycle 9.8 critical 4.8% 2024-08-16
CVE-2017-5677 PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint,… In your normal cycle 9.8 critical 4.8% 2017-02-06
CVE-2017-8979 Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code executio… In your normal cycle 9.8 critical 4.8% 2018-02-15
CVE-2012-0931 Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a de… In your normal cycle 9.8 critical 4.8% 2012-01-28
CVE-2015-7988 The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service… In your normal cycle 9.8 critical 4.8% 2016-06-26
CVE-2018-20122 The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary tha… In your normal cycle 9.8 critical 4.8% 2019-02-21
CVE-2022-4221 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated att… In your normal cycle 9.8 critical 4.8% 2022-12-01
CVE-2022-25315 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. In your normal cycle 9.8 critical 4.8% 2022-02-18
CVE-2022-23218 The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on th… In your normal cycle 9.8 critical 4.8% 2022-01-14
CVE-2021-28925 SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/. In your normal cycle 9.8 critical 4.8% 2021-04-08
CVE-2021-3762 A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image wh… In your normal cycle 9.8 critical 4.8% 2022-03-03
CVE-2015-8394 PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflo… In your normal cycle 9.8 critical 4.8% 2015-12-02
CVE-2020-1964 It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to p… In your normal cycle 9.8 critical 4.8% 2020-04-16
CVE-2024-39763 Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specia… In your normal cycle 9.1 critical 4.8% 2025-01-14
CVE-2024-1597 pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode t… In your normal cycle 10.0 critical 4.8% 2024-02-19
CVE-2024-10571 The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the '… In your normal cycle 9.8 critical 4.8% 2024-11-14
CVE-2018-14805 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within… In your normal cycle 9.8 critical 4.8% 2018-08-29
CVE-2016-1395 The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devi… In your normal cycle 9.8 critical 4.8% 2016-06-19
CVE-2022-4050 The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL inj… In your normal cycle 9.8 critical 4.8% 2022-12-19
CVE-2020-21937 An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute… In your normal cycle 9.8 critical 4.8% 2021-07-21
CVE-2015-8969 git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the str… In your normal cycle 9.8 critical 4.8% 2016-11-03
CVE-2014-5414 Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authenticatio… In your normal cycle 9.1 critical 4.8% 2016-10-05
CVE-2020-1961 Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, en… In your normal cycle 9.8 critical 4.8% 2020-05-04
CVE-2015-8776 The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (applicati… In your normal cycle 9.1 critical 4.8% 2016-04-19
CVE-2018-14599 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious se… In your normal cycle 9.8 critical 4.8% 2018-08-24
CVE-2014-8337 Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to exe… In your normal cycle 9.8 critical 4.8% 2020-01-03
CVE-2020-3470 Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execu… In your normal cycle 9.8 critical 4.8% 2020-11-18
CVE-2022-4059 The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX… In your normal cycle 9.8 critical 4.8% 2023-01-02
CVE-2018-0488 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute ar… In your normal cycle 9.8 critical 4.8% 2018-02-13
← previous page 200 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt