peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,011 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,888 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-44906 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). In your normal cycle 9.8 critical 4.6% 2022-03-17
CVE-2019-13956 Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_… In your normal cycle 9.8 critical 4.6% 2019-07-18
CVE-2020-17363 USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHun… In your normal cycle 9.9 critical 4.6% 2020-12-31
CVE-2014-4982 LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server. In your normal cycle 9.8 critical 4.6% 2020-01-10
CVE-2024-41468 Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand In your normal cycle 9.8 critical 4.6% 2024-07-25
CVE-2020-35191 The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker… In your normal cycle 9.8 critical 4.6% 2020-12-17
CVE-2010-4203 WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (me… In your normal cycle 9.8 critical 4.6% 2010-11-06
CVE-2020-25207 JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. In your normal cycle 9.8 critical 4.6% 2020-11-16
CVE-2019-3975 Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL… In your normal cycle 9.8 critical 4.6% 2019-09-10
CVE-2018-3757 Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter. In your normal cycle 9.8 critical 4.6% 2018-06-01
CVE-2016-7115 Buffer overflow in the handle_packet function in mactelnet.c in the client in MAC-Telnet 0.4.3 and earlier allows remote TELNET servers to execute arb… In your normal cycle 9.8 critical 4.6% 2016-08-30
CVE-2018-17914 InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability… In your normal cycle 9.8 critical 4.6% 2018-11-02
CVE-2019-1938 A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated… In your normal cycle 9.8 critical 4.6% 2019-08-21
CVE-2021-41080 Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search. In your normal cycle 9.8 critical 4.6% 2021-11-11
CVE-2019-7019 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4.6% 2019-05-24
CVE-2019-7027 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4.6% 2019-05-24
CVE-2019-7060 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4.6% 2019-05-24
CVE-2015-8286 Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 90… In your normal cycle 9.8 critical 4.6% 2016-02-18
CVE-2022-23852 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. In your normal cycle 9.8 critical 4.6% 2022-01-24
CVE-2016-4573 Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-… In your normal cycle 9.8 critical 4.6% 2016-09-09
CVE-2020-14001 The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such a… In your normal cycle 9.8 critical 4.6% 2020-07-17
CVE-2015-3991 strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code. In your normal cycle 9.8 critical 4.6% 2017-09-07
CVE-2018-1000005 libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pul… In your normal cycle 9.1 critical 4.6% 2018-01-24
CVE-2026-1306 The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJA… In your normal cycle 9.8 critical 4.6% 2026-02-14
CVE-2017-3010 Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerabil… In your normal cycle 9.8 critical 4.6% 2017-03-31
CVE-2021-38613 The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and ac… In your normal cycle 9.8 critical 4.5% 2021-08-24
CVE-2014-9474 Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors re… In your normal cycle 9.8 critical 4.5% 2017-10-10
CVE-2019-0008 A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC)… In your normal cycle 9.8 critical 4.5% 2019-04-10
CVE-2008-7313 The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE… In your normal cycle 9.8 critical 4.5% 2017-03-31
CVE-2016-1416 Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administrat… In your normal cycle 9.8 critical 4.5% 2016-07-02
← previous page 207 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt