peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,461 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,936 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-3797 Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and… In your normal cycle 9.8 critical 3.9% 2020-03-25
CVE-2018-15168 A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynam… In your normal cycle 9.8 critical 3.9% 2018-08-08
CVE-2021-33816 The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, an… In your normal cycle 9.8 critical 3.9% 2021-11-10
CVE-2020-9039 Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and… In your normal cycle 9.8 critical 3.9% 2020-02-22
CVE-2021-32983 A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The… In your normal cycle 9.8 critical 3.9% 2021-08-30
CVE-2020-6141 An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL in… In your normal cycle 9.8 critical 3.9% 2020-09-01
CVE-2019-10878 In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/sh… In your normal cycle 9.8 critical 3.9% 2019-04-05
CVE-2020-12007 A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a des… In your normal cycle 9.8 critical 3.9% 2020-07-16
CVE-2019-9898 Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. In your normal cycle 9.8 critical 3.9% 2019-03-21
CVE-2020-2040 A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with r… In your normal cycle 9.8 critical 3.9% 2020-09-09
CVE-2016-7983 The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). In your normal cycle 9.8 critical 3.9% 2017-01-28
CVE-2016-7489 Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this ma… In your normal cycle 9.8 critical 3.9% 2016-11-10
CVE-2018-20432 D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to ga… In your normal cycle 9.8 critical 3.9% 2020-09-14
CVE-2014-9841 The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "… In your normal cycle 9.8 critical 3.9% 2017-03-20
CVE-2014-9843 The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. In your normal cycle 9.8 critical 3.9% 2017-03-20
CVE-2017-1000009 Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution. In your normal cycle 9.8 critical 3.9% 2017-07-17
CVE-2019-8948 PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. In your normal cycle 9.8 critical 3.9% 2019-02-20
CVE-2022-29130 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability In your normal cycle 9.8 critical 3.9% 2022-05-10
CVE-2016-5062 The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to… In your normal cycle 9.8 critical 3.9% 2016-09-29
CVE-2011-2717 The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacha… In your normal cycle 9.8 critical 3.9% 2019-11-27
CVE-2017-8415 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pass… In your normal cycle 9.8 critical 3.9% 2019-07-02
CVE-2015-7029 Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or… In your normal cycle 9.8 critical 3.9% 2016-07-03
CVE-2015-7425 The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectr… In your normal cycle 10.0 critical 3.9% 2016-02-21
CVE-2021-27646 Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute… In your normal cycle 9.8 critical 3.9% 2021-03-12
CVE-2019-8268 UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadString functi… In your normal cycle 9.8 critical 3.9% 2019-03-08
CVE-2019-8272 UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution. This attack appears… In your normal cycle 9.8 critical 3.9% 2019-03-08
CVE-2023-6320 A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A seri… In your normal cycle 9.1 critical 3.9% 2024-04-09
CVE-2018-1000042 Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS C… In your normal cycle 9.8 critical 3.9% 2018-02-09
CVE-2018-1000043 Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS C… In your normal cycle 9.8 critical 3.9% 2018-02-09
CVE-2018-5488 NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.… In your normal cycle 9.8 critical 3.9% 2018-06-13
← previous page 232 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt