peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,954 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-13410 Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash… In your normal cycle 9.8 critical 3.8% 2018-07-06
CVE-2018-0104 A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary c… In your normal cycle 9.6 critical 3.8% 2018-01-04
CVE-2018-20334 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell met… In your normal cycle 9.8 critical 3.8% 2020-03-20
CVE-2016-6525 Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cras… In your normal cycle 9.8 critical 3.8% 2016-09-22
CVE-2021-29417 gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal. In your normal cycle 9.8 critical 3.8% 2021-03-29
CVE-2017-7864 FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobj… In your normal cycle 9.8 critical 3.8% 2017-04-14
CVE-2014-3927 mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code. In your normal cycle 9.8 critical 3.8% 2017-04-03
CVE-2019-3984 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… In your normal cycle 9.8 critical 3.8% 2019-12-31
CVE-2017-5152 An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user… In your normal cycle 9.1 critical 3.8% 2017-02-13
CVE-2020-26728 A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution vi… In your normal cycle 9.8 critical 3.8% 2022-02-11
CVE-2014-3624 Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests… In your normal cycle 9.8 critical 3.8% 2017-10-30
CVE-2015-7938 Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors. In your normal cycle 9.8 critical 3.8% 2016-01-09
CVE-2020-35605 The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing spe… In your normal cycle 9.8 critical 3.8% 2020-12-21
CVE-2017-4907 VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-ove… In your normal cycle 9.8 critical 3.8% 2017-06-08
CVE-2015-8972 Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent at… In your normal cycle 9.8 critical 3.8% 2017-01-23
CVE-2019-19230 An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker… In your normal cycle 9.8 critical 3.8% 2019-12-09
CVE-2018-1567 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a… In your normal cycle 9.8 critical 3.8% 2018-09-07
CVE-2014-3741 The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary comma… In your normal cycle 9.8 critical 3.8% 2017-10-23
CVE-2017-17833 OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a… In your normal cycle 9.8 critical 3.8% 2018-04-23
CVE-2022-29851 documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion… In your normal cycle 9.8 critical 3.8% 2022-10-25
CVE-2018-6292 Remote Code Execution in Saperion Web Client version 7.5.2 83166. In your normal cycle 9.8 critical 3.8% 2018-02-13
CVE-2021-42646 XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0… In your normal cycle 9.1 critical 3.8% 2022-05-11
CVE-2024-3234 The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is… In your normal cycle 9.8 critical 3.8% 2024-06-06
CVE-2026-13001 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_… In your normal cycle 9.8 critical 3.8% 2026-07-14
CVE-2026-3844 The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'… In your normal cycle 9.8 critical 3.8% 2026-04-23
CVE-2019-10479 An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were identified that allow a remot… In your normal cycle 9.8 critical 3.8% 2019-04-05
CVE-2017-5397 The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for th… In your normal cycle 9.8 critical 3.8% 2018-06-11
CVE-2023-42116 Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… In your normal cycle 9.8 critical 3.8% 2024-05-03
CVE-2018-5156 A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream d… In your normal cycle 9.8 critical 3.8% 2018-10-18
CVE-2020-35717 zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true). In your normal cycle 9.0 critical 3.8% 2021-01-01
← previous page 240 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt