peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,955 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1130 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befor… In your normal cycle 9.8 critical 3.7% 2016-05-11
CVE-2021-21465 The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker c… In your normal cycle 9.9 critical 3.7% 2021-01-12
CVE-2021-45998 D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vu… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46226 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46228 D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerabilit… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46455 D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerabi… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46456 D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerabi… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2021-46457 D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnera… In your normal cycle 9.8 critical 3.7% 2022-02-04
CVE-2020-23426 zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for f… In your normal cycle 9.8 critical 3.7% 2021-04-08
CVE-2025-13773 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5… In your normal cycle 9.8 critical 3.7% 2025-12-24
CVE-2026-26791 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server functi… In your normal cycle 9.8 critical 3.7% 2026-03-12
CVE-2026-26793 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attacke… In your normal cycle 9.8 critical 3.7% 2026-03-12
CVE-2026-26795 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Thi… In your normal cycle 9.8 critical 3.7% 2026-03-12
CVE-2017-1000047 rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution In your normal cycle 9.8 critical 3.7% 2017-07-17
CVE-2021-33962 China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device compone… In your normal cycle 9.8 critical 3.7% 2022-01-14
CVE-2019-18224 idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. In your normal cycle 9.8 critical 3.7% 2019-10-21
CVE-2019-8206 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… In your normal cycle 9.8 critical 3.7% 2019-10-17
CVE-2021-40525 Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writi… In your normal cycle 9.1 critical 3.7% 2022-01-04
CVE-2017-5398 Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort t… In your normal cycle 9.8 critical 3.7% 2018-06-11
CVE-2021-21804 A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cra… In your normal cycle 9.8 critical 3.7% 2021-07-16
CVE-2021-39379 A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… In your normal cycle 9.8 critical 3.7% 2021-09-01
CVE-2021-25914 Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remot… In your normal cycle 9.8 critical 3.7% 2021-03-01
CVE-2016-20010 EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable… In your normal cycle 10.0 critical 3.7% 2021-05-05
CVE-2019-13962 lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not pro… In your normal cycle 9.8 critical 3.7% 2019-07-18
CVE-2016-10328 FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.… In your normal cycle 9.8 critical 3.7% 2017-04-14
CVE-2020-13931 If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker con… In your normal cycle 9.8 critical 3.7% 2020-12-18
CVE-2020-15489 An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI script… In your normal cycle 9.8 critical 3.7% 2020-07-01
CVE-2018-11241 An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as… In your normal cycle 9.8 critical 3.7% 2018-09-21
CVE-2018-15723 The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated rem… In your normal cycle 9.8 critical 3.7% 2018-12-20
CVE-2018-14353 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. In your normal cycle 9.8 critical 3.7% 2018-07-17
← previous page 244 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt