peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,659 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,954 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-24442 JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. In your normal cycle 9.8 critical 3.8% 2022-02-25
CVE-2025-71211 A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected… In your normal cycle 9.8 critical 3.8% 2026-05-21
CVE-2016-4165 The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input. In your normal cycle 9.8 critical 3.8% 2016-06-16
CVE-2021-20231 A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. In your normal cycle 9.8 critical 3.8% 2021-03-12
CVE-2021-22859 The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL sy… In your normal cycle 9.8 critical 3.8% 2021-03-17
CVE-2020-26867 ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely ex… In your normal cycle 9.8 critical 3.8% 2020-10-12
CVE-2022-43109 D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows… In your normal cycle 9.8 critical 3.7% 2022-11-03
CVE-2020-28281 Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to r… In your normal cycle 9.8 critical 3.7% 2020-12-29
CVE-2018-11091 An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker… In your normal cycle 9.9 critical 3.7% 2018-05-14
CVE-2013-5122 Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access In your normal cycle 9.8 critical 3.7% 2020-01-07
CVE-2018-19115 keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because… In your normal cycle 9.8 critical 3.7% 2018-11-08
CVE-2021-46230 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46231 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46232 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerab… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46233 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability a… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46452 D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46453 D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulne… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2023-48842 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. In your normal cycle 9.8 critical 3.7% 2023-12-01
CVE-2016-1329 Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardco… In your normal cycle 9.8 critical 3.7% 2016-03-03
CVE-2014-9513 Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code. In your normal cycle 9.8 critical 3.7% 2017-08-28
CVE-2018-7499 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcce… In your normal cycle 9.8 critical 3.7% 2018-05-15
CVE-2024-5488 The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerab… In your normal cycle 9.8 critical 3.7% 2024-07-09
CVE-2021-46036 An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. In your normal cycle 9.8 critical 3.7% 2022-02-18
CVE-2024-44411 D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. In your normal cycle 9.8 critical 3.7% 2024-09-09
CVE-2023-0224 The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers… In your normal cycle 9.8 critical 3.7% 2024-01-16
CVE-2026-41452 Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite… In your normal cycle 9.8 critical 3.7% 2026-08-03
CVE-2018-0375 A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected sy… In your normal cycle 9.8 critical 3.7% 2018-07-18
CVE-2022-24796 RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT d… In your normal cycle 10.0 critical 3.7% 2022-03-31
CVE-2023-3049 Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15. In your normal cycle 9.8 critical 3.7% 2023-06-13
CVE-2018-18869 EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecm… In your normal cycle 9.8 critical 3.7% 2018-10-31
← previous page 241 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt