peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,557 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,944 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-27269 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the c… In your normal cycle 9.8 critical 3.8% 2022-04-10
CVE-2016-3606 Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and… In your normal cycle 9.6 critical 3.8% 2016-07-21
CVE-2016-9138 PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial… In your normal cycle 9.8 critical 3.8% 2017-01-04
CVE-2020-28971 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unaut… In your normal cycle 9.8 critical 3.8% 2020-12-01
CVE-2017-6821 Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors… In your normal cycle 9.8 critical 3.8% 2017-05-23
CVE-2021-3918 json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') In your normal cycle 9.8 critical 3.8% 2021-11-13
CVE-2021-27462 A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies se… In your normal cycle 10.0 critical 3.8% 2022-03-23
CVE-2021-27470 A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies se… In your normal cycle 10.0 critical 3.8% 2022-03-23
CVE-2019-8009 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 3.8% 2019-08-20
CVE-2019-8098 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 3.8% 2019-08-20
CVE-2019-8100 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 3.8% 2019-08-20
CVE-2022-1531 SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerabili… In your normal cycle 9.8 critical 3.8% 2022-04-29
CVE-2022-3477 The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does… In your normal cycle 9.8 critical 3.8% 2022-11-14
CVE-2017-16523 MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalen… In your normal cycle 9.8 critical 3.8% 2017-11-03
CVE-2022-32839 The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catali… In your normal cycle 9.8 critical 3.8% 2022-08-24
CVE-2023-26326 The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated att… In your normal cycle 9.8 critical 3.8% 2023-02-23
CVE-2017-13139 In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk. In your normal cycle 9.8 critical 3.8% 2017-08-23
CVE-2019-7165 A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. In your normal cycle 9.8 critical 3.8% 2019-07-03
CVE-2019-13192 Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute… In your normal cycle 9.8 critical 3.8% 2020-03-13
CVE-2016-9942 Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application cr… In your normal cycle 9.8 critical 3.8% 2016-12-31
CVE-2018-1000881 Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedA… In your normal cycle 9.8 critical 3.8% 2018-12-20
CVE-2018-8871 In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, w… In your normal cycle 9.8 critical 3.8% 2018-05-25
CVE-2025-55423 A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-… In your normal cycle 9.8 critical 3.8% 2026-01-20
CVE-2024-34257 TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands… In your normal cycle 9.8 critical 3.8% 2024-05-08
CVE-2022-23123 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to… In your normal cycle 9.8 critical 3.8% 2023-03-28
CVE-2016-4819 The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f through 3.16b, and DX Library for… In your normal cycle 9.8 critical 3.8% 2016-06-19
CVE-2019-10104 In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the defaul… In your normal cycle 9.8 critical 3.8% 2019-07-03
CVE-2022-37452 Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set. In your normal cycle 9.8 critical 3.8% 2022-08-07
CVE-2022-22845 QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' ins… In your normal cycle 9.8 critical 3.8% 2022-01-10
CVE-2025-71210 A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected… In your normal cycle 9.8 critical 3.8% 2026-05-21
← previous page 237 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt