peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,984 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,885 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-0150 A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IO… In your normal cycle 9.8 critical 4.8% 2018-03-28
CVE-2020-9906 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watch… In your normal cycle 9.1 critical 4.8% 2020-10-22
CVE-2020-10595 pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library.… In your normal cycle 9.8 critical 4.8% 2020-03-31
CVE-2024-7988 A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code… In your normal cycle 9.8 critical 4.8% 2024-08-26
CVE-2019-16114 In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain ac… In your normal cycle 9.8 critical 4.8% 2019-09-09
CVE-2019-16445 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16446 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16448 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16455 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16459 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16460 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16462 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2019-16464 Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and ear… In your normal cycle 9.8 critical 4.8% 2019-12-19
CVE-2017-7481 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup… In your normal cycle 9.8 critical 4.8% 2018-07-19
CVE-2023-37483 SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-… In your normal cycle 9.8 critical 4.8% 2023-08-08
CVE-2016-8736 Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. In your normal cycle 9.8 critical 4.8% 2017-10-12
CVE-2017-15692 In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acces… In your normal cycle 9.8 critical 4.8% 2018-02-27
CVE-2016-5687 The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact v… In your normal cycle 9.8 critical 4.8% 2016-12-13
CVE-2018-14806 Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. In your normal cycle 9.8 critical 4.8% 2018-10-23
CVE-2020-1889 A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of pr… In your normal cycle 10.0 critical 4.8% 2020-09-03
CVE-2019-9569 Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possi… In your normal cycle 9.8 critical 4.8% 2019-08-26
CVE-2020-3801 Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… In your normal cycle 9.8 critical 4.8% 2020-03-25
CVE-2021-37424 ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. In your normal cycle 9.8 critical 4.8% 2021-09-21
CVE-2016-3657 Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0… In your normal cycle 9.8 critical 4.8% 2016-04-12
CVE-2013-3316 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". In your normal cycle 9.8 critical 4.8% 2020-01-29
CVE-2013-3317 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. In your normal cycle 9.8 critical 4.8% 2020-01-29
CVE-2018-1000613 Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally… In your normal cycle 9.8 critical 4.8% 2018-07-09
CVE-2016-9535 tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mod… In your normal cycle 9.8 critical 4.8% 2016-11-22
CVE-2017-14375 EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VA… In your normal cycle 9.8 critical 4.8% 2017-11-01
CVE-2022-29063 The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier,… In your normal cycle 9.8 critical 4.8% 2022-09-02
← previous page 201 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt