peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,429 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,936 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-19595 reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers… In your normal cycle 9.8 critical 4% 2019-12-05
CVE-2017-16820 The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which cou… In your normal cycle 9.8 critical 4% 2017-11-14
CVE-2019-13571 A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnera… In your normal cycle 9.8 critical 4% 2019-07-29
CVE-2023-3128 Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. T… In your normal cycle 9.4 critical 4% 2023-06-22
CVE-2021-43466 In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. In your normal cycle 9.8 critical 4% 2021-11-09
CVE-2021-45468 Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security… In your normal cycle 9.8 critical 4% 2022-01-14
CVE-2021-44663 A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php. In your normal cycle 9.8 critical 4% 2022-02-24
CVE-2019-7037 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4% 2019-05-24
CVE-2019-7052 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and e… In your normal cycle 9.8 critical 4% 2019-05-24
CVE-2021-21018 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operatio… In your normal cycle 9.1 critical 4% 2021-02-11
CVE-2021-27804 JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption. In your normal cycle 9.8 critical 4% 2021-03-02
CVE-2016-10126 Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x befo… In your normal cycle 9.8 critical 4% 2017-01-10
CVE-2019-3953 Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbitrary code by sending a crafte… In your normal cycle 9.8 critical 4% 2019-06-18
CVE-2016-7446 Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Not… In your normal cycle 9.8 critical 4% 2017-02-06
CVE-2022-44832 D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. In your normal cycle 9.8 critical 4% 2022-12-14
CVE-2026-26792 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target… In your normal cycle 9.8 critical 4% 2026-03-12
CVE-2019-8247 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution… In your normal cycle 9.8 critical 4% 2019-11-14
CVE-2019-8248 Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution… In your normal cycle 9.8 critical 4% 2019-11-14
CVE-2016-6448 A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute ar… In your normal cycle 9.8 critical 4% 2016-11-03
CVE-2020-14498 HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotel… In your normal cycle 9.6 critical 4% 2020-08-26
CVE-2017-3208 The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) fr… In your normal cycle 9.8 critical 4% 2018-06-11
CVE-2015-0192 Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP… In your normal cycle 9.8 critical 4% 2015-07-02
CVE-2015-10135 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function… In your normal cycle 9.8 critical 4% 2025-07-19
CVE-2021-27258 This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticatio… In your normal cycle 9.8 critical 4% 2021-04-14
CVE-2024-53900 Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. In your normal cycle 9.1 critical 4% 2024-12-02
CVE-2019-13473 TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450,… In your normal cycle 9.8 critical 4% 2019-09-11
CVE-2020-9380 IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. In your normal cycle 9.8 critical 4% 2020-03-05
CVE-2017-12562 Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of… In your normal cycle 9.8 critical 4% 2017-08-05
CVE-2016-7806 I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. In your normal cycle 9.8 critical 4% 2017-06-09
CVE-2014-3448 BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload In your normal cycle 9.8 critical 4% 2020-01-09
← previous page 229 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt