peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,888 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-3166 The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not… In your normal cycle 9.8 critical 4.6% 2019-11-20
CVE-2017-8283 dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hun… In your normal cycle 9.8 critical 4.6% 2017-04-26
CVE-2020-27660 SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the… In your normal cycle 9.6 critical 4.6% 2020-11-30
CVE-2017-7974 A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an un… In your normal cycle 9.8 critical 4.6% 2017-09-26
CVE-2026-74849 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. In your normal cycle 9.8 critical 4.6% 2026-09-22
CVE-2017-2637 A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed… In your normal cycle 9.9 critical 4.6% 2018-07-26
CVE-2021-40177 Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. In your normal cycle 9.8 critical 4.6% 2021-08-29
CVE-2017-5469 Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox… In your normal cycle 9.8 critical 4.6% 2018-06-11
CVE-2019-16885 In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This… In your normal cycle 9.8 critical 4.6% 2019-12-03
CVE-2021-41643 Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. In your normal cycle 9.8 critical 4.6% 2021-10-29
CVE-2019-9161 WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full acc… In your normal cycle 9.8 critical 4.6% 2019-04-18
CVE-2022-20702 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… In your normal cycle 10.0 critical 4.6% 2022-02-10
CVE-2017-13040 The MPTCP parser in tcpdump before 4.9.2 has a buffer over-read in print-mptcp.c, several functions. In your normal cycle 9.8 critical 4.6% 2017-09-14
CVE-2017-13041 The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_nodeinfo_print(). In your normal cycle 9.8 critical 4.6% 2017-09-14
CVE-2019-10970 In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a re… In your normal cycle 9.8 critical 4.6% 2019-07-11
CVE-2025-13390 The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implemen… In your normal cycle 10.0 critical 4.6% 2025-12-03
CVE-2014-3579 XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors invo… In your normal cycle 9.8 critical 4.6% 2017-10-27
CVE-2018-20433 c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. In your normal cycle 9.8 critical 4.6% 2018-12-24
CVE-2018-12356 An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output… In your normal cycle 9.8 critical 4.6% 2018-06-15
CVE-2018-19530 HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when confi… In your normal cycle 9.8 critical 4.6% 2018-11-26
CVE-2018-19531 HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsaf… In your normal cycle 9.8 critical 4.6% 2018-11-26
CVE-2024-43160 Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6. In your normal cycle 10.0 critical 4.6% 2024-08-13
CVE-2026-23515 Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated u… In your normal cycle 9.9 critical 4.6% 2026-02-02
CVE-2019-1010178 Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/… In your normal cycle 9.8 critical 4.6% 2019-07-24
CVE-2014-9847 The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. In your normal cycle 9.8 critical 4.6% 2017-03-20
CVE-2021-32835 Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerabilit… In your normal cycle 9.9 critical 4.6% 2021-09-09
CVE-2019-8246 Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code executio… In your normal cycle 9.8 critical 4.6% 2019-11-14
CVE-2025-22905 RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. In your normal cycle 9.8 critical 4.6% 2025-01-16
CVE-2018-5704 Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers… In your normal cycle 9.6 critical 4.6% 2018-01-16
CVE-2017-10906 Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitra… In your normal cycle 9.8 critical 4.6% 2017-12-08
← previous page 206 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt