peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,041 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,891 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-10251 A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and… In your normal cycle 9.8 critical 4.5% 2018-05-04
CVE-2016-6912 Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecifie… In your normal cycle 9.8 critical 4.5% 2017-01-26
CVE-2022-1986 OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. In your normal cycle 9.8 critical 4.5% 2022-06-09
CVE-2019-14313 A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability woul… In your normal cycle 9.8 critical 4.5% 2019-07-30
CVE-2017-17484 The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for… In your normal cycle 9.8 critical 4.5% 2017-12-10
CVE-2026-77806 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code… In your normal cycle 9.8 critical 4.5% 2026-08-21
CVE-2021-27362 The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might… In your normal cycle 9.8 critical 4.5% 2021-02-17
CVE-2014-9984 nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup… In your normal cycle 9.8 critical 4.5% 2017-06-12
CVE-2020-29127 An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web br… In your normal cycle 9.8 critical 4.5% 2020-11-30
CVE-2017-16618 An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YAML" string or file (aka load_y… In your normal cycle 9.8 critical 4.5% 2017-11-08
CVE-2017-16763 An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being load… In your normal cycle 9.8 critical 4.5% 2017-11-10
CVE-2020-3198 Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Co… In your normal cycle 9.8 critical 4.5% 2020-06-03
CVE-2018-12976 In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a dir… In your normal cycle 9.8 critical 4.5% 2018-07-05
CVE-2019-15751 An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with a… In your normal cycle 9.8 critical 4.5% 2019-10-07
CVE-2024-39781 Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte… In your normal cycle 9.1 critical 4.5% 2025-01-14
CVE-2024-39783 Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte… In your normal cycle 9.1 critical 4.5% 2025-01-14
CVE-2014-2302 The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by in… In your normal cycle 9.8 critical 4.5% 2018-07-19
CVE-2024-11613 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all version… In your normal cycle 9.8 critical 4.5% 2025-01-08
CVE-2017-5954 An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to ac… In your normal cycle 9.8 critical 4.5% 2017-02-10
CVE-2019-14698 An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buff… In your normal cycle 9.8 critical 4.5% 2019-08-06
CVE-2019-14708 An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote c… In your normal cycle 9.8 critical 4.5% 2019-08-06
CVE-2018-18861 Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command. In your normal cycle 9.8 critical 4.5% 2018-11-20
CVE-2017-13719 The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera… In your normal cycle 9.8 critical 4.5% 2019-07-03
CVE-2016-7942 The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, whi… In your normal cycle 9.8 critical 4.5% 2016-12-13
CVE-2016-7943 The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigge… In your normal cycle 9.8 critical 4.5% 2016-12-13
CVE-2017-3834 A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauth… In your normal cycle 9.8 critical 4.5% 2017-04-06
CVE-2019-6824 A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to ex… In your normal cycle 9.8 critical 4.5% 2019-07-15
CVE-2022-35866 This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authenticati… In your normal cycle 9.8 critical 4.5% 2022-08-03
CVE-2016-2000 HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafte… In your normal cycle 9.8 critical 4.5% 2016-04-05
CVE-2016-2003 HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to… In your normal cycle 9.8 critical 4.5% 2016-04-20
← previous page 210 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt