peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,602 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,948 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-36363 Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. In your normal cycle 9.8 critical 3.8% 2021-09-28
CVE-2021-36365 Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. In your normal cycle 9.8 critical 3.8% 2021-09-28
CVE-2017-2628 curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not refle… In your normal cycle 9.8 critical 3.8% 2018-03-12
CVE-2019-8022 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 3.8% 2019-08-20
CVE-2019-8023 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… In your normal cycle 9.8 critical 3.8% 2019-08-20
CVE-2021-32605 zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, a… In your normal cycle 9.8 critical 3.8% 2021-05-11
CVE-2017-6969 readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger prog… In your normal cycle 9.1 critical 3.8% 2017-03-17
CVE-2026-26068 emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is acc… In your normal cycle 9.9 critical 3.8% 2026-02-12
CVE-2018-10085 CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\cl… In your normal cycle 9.8 critical 3.8% 2018-04-13
CVE-2018-5442 A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buffer overflow vulnerability has… In your normal cycle 9.8 critical 3.8% 2018-02-05
CVE-2018-5475 A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-based… In your normal cycle 9.8 critical 3.8% 2018-02-19
CVE-2017-10137 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: JNDI). Supported versions that are affected are 10.3.… In your normal cycle 10.0 critical 3.8% 2017-08-08
CVE-2022-45047 Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized ja… In your normal cycle 9.8 critical 3.8% 2022-11-16
CVE-2017-11541 tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c. In your normal cycle 9.8 critical 3.8% 2017-07-23
CVE-2017-11542 tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c. In your normal cycle 9.8 critical 3.8% 2017-07-23
CVE-2016-1901 Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Con… In your normal cycle 9.8 critical 3.8% 2016-01-20
CVE-2018-3783 A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset. In your normal cycle 9.8 critical 3.8% 2018-08-17
CVE-2014-0234 The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows rem… In your normal cycle 9.8 critical 3.8% 2020-02-12
CVE-2020-18020 SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter o… In your normal cycle 9.8 critical 3.8% 2021-04-28
CVE-2017-18211 In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-look… In your normal cycle 9.8 critical 3.8% 2018-03-01
CVE-2017-6950 SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, ak… In your normal cycle 9.8 critical 3.8% 2017-03-23
CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within th… In your normal cycle 9.9 critical 3.8% 2026-02-19
CVE-2018-0608 Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified… In your normal cycle 9.8 critical 3.8% 2018-06-26
CVE-2024-0402 An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which al… In your normal cycle 9.9 critical 3.8% 2024-01-26
CVE-2021-44143 A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mai… In your normal cycle 9.8 critical 3.8% 2021-11-22
CVE-2022-26711 An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPa… In your normal cycle 9.8 critical 3.8% 2022-05-26
CVE-2026-7248 A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The… In your normal cycle 9.8 critical 3.8% 2026-04-28
CVE-2017-0305 F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system config… In your normal cycle 9.8 critical 3.8% 2017-04-06
CVE-2018-4110 An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" component. It allows remote attackers… In your normal cycle 9.8 critical 3.8% 2018-04-03
CVE-2018-10381 TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service esta… In your normal cycle 9.8 critical 3.8% 2018-04-26
← previous page 239 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt