peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,936 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4328 MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which makes it easier for remote atta… In your normal cycle 9.8 critical 4% 2016-06-10
CVE-2016-2024 HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vec… In your normal cycle 9.8 critical 4% 2016-06-08
CVE-2021-33267 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4% 2021-12-01
CVE-2021-33269 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4% 2021-12-01
CVE-2021-33270 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4% 2021-12-01
CVE-2021-33271 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4% 2021-12-01
CVE-2021-33274 D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the fu… In your normal cycle 9.8 critical 4% 2021-12-01
CVE-2016-3527 Unspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 12.1 and 12.2 allows remote attackers to affec… In your normal cycle 9.1 critical 4% 2016-07-21
CVE-2016-3546 Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers t… In your normal cycle 9.1 critical 4% 2016-07-21
CVE-2016-10128 Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x bef… In your normal cycle 9.8 critical 4% 2017-03-24
CVE-2017-1000372 A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setui… In your normal cycle 9.8 critical 4% 2017-06-19
CVE-2020-9630 Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerabi… In your normal cycle 9.8 critical 4% 2020-06-26
CVE-2019-11061 A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT device… In your normal cycle 10.0 critical 4% 2019-08-29
CVE-2017-2519 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… In your normal cycle 9.8 critical 4% 2017-05-22
CVE-2021-20125 An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect… In your normal cycle 9.8 critical 3.9% 2021-10-13
CVE-2018-7800 A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device… In your normal cycle 9.8 critical 3.9% 2018-12-24
CVE-2015-8804 x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-3… In your normal cycle 9.8 critical 3.9% 2016-02-23
CVE-2022-3481 The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a RE… In your normal cycle 9.8 critical 3.9% 2022-11-07
CVE-2022-26186 TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. In your normal cycle 9.8 critical 3.9% 2022-03-22
CVE-2021-24220 Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPre… In your normal cycle 9.1 critical 3.9% 2021-04-12
CVE-2018-5188 Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume… In your normal cycle 9.8 critical 3.9% 2018-10-18
CVE-2020-28940 On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unaut… In your normal cycle 9.8 critical 3.9% 2020-12-01
CVE-2020-28970 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unaut… In your normal cycle 9.8 critical 3.9% 2020-12-01
CVE-2020-27853 Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string… In your normal cycle 9.8 critical 3.9% 2020-10-27
CVE-2020-3784 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2020-3785 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2020-3786 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2020-3787 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2020-3788 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2020-3789 Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful e… In your normal cycle 9.8 critical 3.9% 2020-03-25
← previous page 231 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt