peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,948 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-6692 Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protec… In your normal cycle 10.0 critical 3.8% 2018-08-21
CVE-2017-16228 Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash chara… In your normal cycle 9.8 critical 3.8% 2017-10-29
CVE-2016-5116 gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers t… In your normal cycle 9.1 critical 3.8% 2016-08-07
CVE-2017-5202 The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). In your normal cycle 9.8 critical 3.8% 2017-01-28
CVE-2017-5203 The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). In your normal cycle 9.8 critical 3.8% 2017-01-28
CVE-2018-7847 A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which… In your normal cycle 9.8 critical 3.8% 2019-05-22
CVE-2021-31962 Kerberos AppContainer Security Feature Bypass Vulnerability In your normal cycle 9.4 critical 3.8% 2021-06-08
CVE-2019-7745 JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Settin… In your normal cycle 9.8 critical 3.8% 2019-05-07
CVE-2017-8856 In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the '… In your normal cycle 9.8 critical 3.8% 2017-05-09
CVE-2018-3774 Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authenticatio… In your normal cycle 10.0 critical 3.8% 2018-08-12
CVE-2014-5170 The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess… In your normal cycle 9.8 critical 3.8% 2018-03-29
CVE-2018-17918 Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page. In your normal cycle 9.8 critical 3.8% 2018-11-02
CVE-2023-2734 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verifi… In your normal cycle 9.8 critical 3.8% 2023-05-25
CVE-2020-15123 In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikel… In your normal cycle 9.3 critical 3.8% 2020-07-20
CVE-2017-15376 The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port… In your normal cycle 9.8 critical 3.8% 2017-10-16
CVE-2021-2047 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are… In your normal cycle 9.8 critical 3.8% 2021-01-20
CVE-2021-2075 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.… In your normal cycle 9.8 critical 3.8% 2021-01-20
CVE-2022-27804 An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One Security Ki… In your normal cycle 9.8 critical 3.8% 2022-10-25
CVE-2020-35545 Time-based SQL injection exists in Spotweb 1.4.9 via the query string. In your normal cycle 9.8 critical 3.8% 2020-12-17
CVE-2016-7852 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 3.8% 2016-10-21
CVE-2016-7854 Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 3.8% 2016-10-21
CVE-2016-2018 HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors. In your normal cycle 9.1 critical 3.8% 2016-06-08
CVE-2022-20709 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Exe… In your normal cycle 10.0 critical 3.8% 2022-02-10
CVE-2017-1000437 Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution. In your normal cycle 9.8 critical 3.8% 2018-01-02
CVE-2017-8226 Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reve… In your normal cycle 9.8 critical 3.8% 2019-07-03
CVE-2019-10787 im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be c… In your normal cycle 9.8 critical 3.8% 2020-02-04
CVE-2020-6072 An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels i… In your normal cycle 9.8 critical 3.8% 2020-03-24
CVE-2017-5545 The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cau… In your normal cycle 9.1 critical 3.8% 2017-01-21
CVE-2019-11217 The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a cra… In your normal cycle 9.8 critical 3.8% 2019-04-24
CVE-2020-14859 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… In your normal cycle 9.8 critical 3.8% 2020-10-21
← previous page 238 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt