peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,286 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

36,914 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-9936 The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or… In your normal cycle 9.8 critical 4.3% 2017-01-04
CVE-2017-7105 An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… In your normal cycle 9.8 critical 4.3% 2017-10-23
CVE-2017-7108 An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… In your normal cycle 9.8 critical 4.3% 2017-10-23
CVE-2017-7110 An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… In your normal cycle 9.8 critical 4.3% 2017-10-23
CVE-2017-7112 An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue invo… In your normal cycle 9.8 critical 4.3% 2017-10-23
CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by c… In your normal cycle 9.8 critical 4.3% 2026-07-30
CVE-2016-2297 Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like… In your normal cycle 9.4 critical 4.3% 2016-05-14
CVE-2017-6044 An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions p… In your normal cycle 9.8 critical 4.3% 2017-06-30
CVE-2018-8955 The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remot… In your normal cycle 9.8 critical 4.3% 2018-10-24
CVE-2020-15357 Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a s… In your normal cycle 9.8 critical 4.3% 2020-12-11
CVE-2019-8199 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 4.3% 2019-10-17
CVE-2021-34813 Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup… In your normal cycle 9.8 critical 4.3% 2021-06-16
CVE-2022-23812 This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or… In your normal cycle 9.8 critical 4.3% 2022-03-16
CVE-2018-18751 An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_… In your normal cycle 9.8 critical 4.3% 2018-10-29
CVE-2017-10685 In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attac… In your normal cycle 9.8 critical 4.3% 2017-06-29
CVE-2021-42232 TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the progra… In your normal cycle 9.8 critical 4.3% 2022-08-23
CVE-2020-28035 WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. In your normal cycle 9.8 critical 4.3% 2020-11-02
CVE-2020-5341 Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data… In your normal cycle 9.8 critical 4.3% 2021-07-28
CVE-2019-7039 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4.3% 2019-05-24
CVE-2020-17383 A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's fi… In your normal cycle 9.8 critical 4.3% 2022-01-24
CVE-2019-8280 UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result code execution. This atta… In your normal cycle 9.8 critical 4.2% 2019-03-08
CVE-2017-5581 Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE me… In your normal cycle 9.8 critical 4.2% 2017-02-28
CVE-2018-11587 There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php… In your normal cycle 9.8 critical 4.2% 2018-06-25
CVE-2019-1213 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An atta… In your normal cycle 9.8 critical 4.2% 2019-08-14
CVE-2014-9320 SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges… In your normal cycle 9.8 critical 4.2% 2021-08-09
CVE-2016-0942 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.2% 2016-01-14
CVE-2016-0944 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.2% 2016-01-14
CVE-2016-0945 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.2% 2016-01-14
CVE-2016-0946 Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 4.2% 2016-01-14
CVE-2017-12796 The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users… In your normal cycle 9.8 critical 4.2% 2017-10-23
← previous page 218 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt