peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

402,999 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,886 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-36983 This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to e… In your normal cycle 9.8 critical 4.7% 2023-03-29
CVE-2018-6485 An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could… In your normal cycle 9.8 critical 4.7% 2018-02-01
CVE-2015-10137 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upl… In your normal cycle 9.8 critical 4.7% 2025-07-22
CVE-2020-20269 A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22. In your normal cycle 9.8 critical 4.7% 2021-01-26
CVE-2023-39560 ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php. In your normal cycle 9.8 critical 4.7% 2023-08-28
CVE-2023-24943 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability In your normal cycle 9.8 critical 4.7% 2023-05-09
CVE-2016-2338 An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function hea… In your normal cycle 9.8 critical 4.7% 2022-09-29
CVE-2020-27654 Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands… In your normal cycle 9.8 critical 4.7% 2020-10-29
CVE-2016-6137 An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security No… In your normal cycle 9.8 critical 4.7% 2016-09-27
CVE-2018-12039 joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/"… In your normal cycle 9.8 critical 4.7% 2018-06-07
CVE-2022-28719 Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the syst… In your normal cycle 9.8 critical 4.7% 2022-04-28
CVE-2022-32221 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT… In your normal cycle 9.8 critical 4.7% 2022-12-05
CVE-2024-34982 An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploadi… In your normal cycle 9.8 critical 4.7% 2024-05-17
CVE-2016-6199 ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object. In your normal cycle 9.8 critical 4.7% 2017-02-07
CVE-2014-2293 Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execu… In your normal cycle 9.8 critical 4.7% 2018-03-26
CVE-2015-8362 The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which make… In your normal cycle 9.8 critical 4.7% 2016-01-22
CVE-2021-3160 Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to in… In your normal cycle 9.8 critical 4.7% 2021-01-28
CVE-2020-10374 A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST requ… In your normal cycle 9.8 critical 4.7% 2020-03-30
CVE-2017-12791 Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with i… In your normal cycle 9.8 critical 4.7% 2017-08-23
CVE-2023-6318 A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throug… In your normal cycle 9.1 critical 4.7% 2024-04-09
CVE-2021-29943 When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usin… In your normal cycle 9.1 critical 4.7% 2021-04-13
CVE-2015-4412 BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service… In your normal cycle 9.8 critical 4.7% 2018-02-05
CVE-2021-46362 A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers t… In your normal cycle 9.8 critical 4.7% 2022-02-11
CVE-2015-4464 Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server. In your normal cycle 9.8 critical 4.7% 2017-08-18
CVE-2017-1000190 SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. In your normal cycle 9.1 critical 4.7% 2017-11-17
CVE-2025-22467 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution… In your normal cycle 9.9 critical 4.7% 2025-02-11
CVE-2017-7899 An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A… In your normal cycle 9.8 critical 4.7% 2017-06-30
CVE-2015-8390 PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized m… In your normal cycle 9.8 critical 4.7% 2015-12-02
CVE-2018-17963 qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibl… In your normal cycle 9.8 critical 4.7% 2018-10-09
CVE-2014-4972 Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary co… In your normal cycle 9.8 critical 4.7% 2018-01-08
← previous page 204 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt