peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,108 CVEs 1,734 on KEV 17,293 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,897 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-25168 Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary… In your normal cycle 9.8 critical 4.5% 2022-08-04
CVE-2019-6978 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is una… In your normal cycle 9.8 critical 4.5% 2019-01-28
CVE-2019-14451 RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configu… In your normal cycle 9.8 critical 4.5% 2019-10-25
CVE-2025-32966 DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link… In your normal cycle 9.8 critical 4.5% 2025-04-23
CVE-2018-7667 Adminer through 4.3.1 has SSRF via the server parameter. In your normal cycle 9.8 critical 4.4% 2018-03-05
CVE-2022-0194 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit… In your normal cycle 9.8 critical 4.4% 2023-03-28
CVE-2019-17041 An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages.… In your normal cycle 9.8 critical 4.4% 2019-10-07
CVE-2016-2783 Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle V… In your normal cycle 9.8 critical 4.4% 2017-01-23
CVE-2012-10021 A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode()… In your normal cycle 9.8 critical 4.4% 2025-07-31
CVE-2020-25014 A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows re… In your normal cycle 9.8 critical 4.4% 2020-11-27
CVE-2017-17033 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20… In your normal cycle 9.8 critical 4.4% 2017-12-21
CVE-2019-8258 UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable… In your normal cycle 9.8 critical 4.4% 2019-03-05
CVE-2022-46071 There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access. In your normal cycle 9.8 critical 4.4% 2022-12-14
CVE-2026-3584 The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function… In your normal cycle 9.8 critical 4.4% 2026-03-20
CVE-2026-3300 The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12.… In your normal cycle 9.8 critical 4.4% 2026-03-31
CVE-2021-26583 A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code exec… In your normal cycle 9.8 critical 4.4% 2021-05-10
CVE-2016-5667 Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request to… In your normal cycle 9.8 critical 4.4% 2016-08-03
CVE-2016-5668 Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via… In your normal cycle 9.8 critical 4.4% 2016-08-03
CVE-2024-27890 Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in… In your normal cycle 9.6 critical 4.4% 2026-06-04
CVE-2026-34415 Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to… In your normal cycle 9.8 critical 4.4% 2026-04-22
CVE-2018-20815 In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk. In your normal cycle 9.8 critical 4.4% 2019-05-31
CVE-2019-8161 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 4.4% 2019-10-17
CVE-2019-8167 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 4.4% 2019-10-17
CVE-2019-8169 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 4.4% 2019-10-17
CVE-2019-8200 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 4.4% 2019-10-17
CVE-2014-4657 The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via… In your normal cycle 9.8 critical 4.4% 2020-02-20
CVE-2022-4328 The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attacker… In your normal cycle 9.8 critical 4.4% 2023-03-06
CVE-2022-33965 Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress. In your normal cycle 9.3 critical 4.4% 2022-07-25
CVE-2016-4366 HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via… In your normal cycle 9.8 critical 4.4% 2016-06-08
CVE-2017-14351 A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vuln… In your normal cycle 9.8 critical 4.4% 2017-09-30
← previous page 211 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt