peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,707 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,958 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-5740 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP re… In your normal cycle 9.8 critical 3.7% 2017-10-18
CVE-2020-8964 TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,… In your normal cycle 9.8 critical 3.7% 2020-02-13
CVE-2021-35522 A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP… In your normal cycle 9.8 critical 3.7% 2021-07-22
CVE-2021-40408 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… In your normal cycle 9.8 critical 3.7% 2022-01-28
CVE-2021-40409 An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], base… In your normal cycle 9.8 critical 3.7% 2022-01-28
CVE-2016-1245 It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discov… In your normal cycle 9.8 critical 3.7% 2017-02-22
CVE-2024-10763 The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_aj… In your normal cycle 9.8 critical 3.7% 2025-02-13
CVE-2023-49371 RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit. In your normal cycle 9.8 critical 3.7% 2023-12-01
CVE-2025-0674 Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functiona… In your normal cycle 9.8 critical 3.7% 2025-02-07
CVE-2017-7476 Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c. In your normal cycle 9.8 critical 3.7% 2017-05-02
CVE-2018-18240 Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's… In your normal cycle 9.8 critical 3.7% 2018-10-11
CVE-2016-4999 SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuild… In your normal cycle 9.8 critical 3.7% 2016-08-05
CVE-2016-5008 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers… In your normal cycle 9.8 critical 3.7% 2016-07-13
CVE-2019-20467 An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (w… In your normal cycle 9.8 critical 3.7% 2021-07-22
CVE-2016-10759 The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileMana… In your normal cycle 9.8 critical 3.7% 2019-05-24
CVE-2016-6559 Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write… In your normal cycle 9.8 critical 3.7% 2018-07-13
CVE-2026-85103 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Q… In your normal cycle 9.8 critical 3.7% 2026-09-09
CVE-2026-73296 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… In your normal cycle 9.4 critical 3.7% 2026-08-12
CVE-2018-15441 A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQ… In your normal cycle 9.4 critical 3.7% 2018-11-28
CVE-2014-9186 A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2… In your normal cycle 9.8 critical 3.7% 2019-04-08
CVE-2016-3086 The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeMa… In your normal cycle 9.8 critical 3.7% 2017-09-05
CVE-2011-1935 pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remot… In your normal cycle 9.8 critical 3.6% 2017-10-20
CVE-2013-4409 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. In your normal cycle 9.8 critical 3.6% 2019-11-04
CVE-2014-1860 Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities In your normal cycle 9.8 critical 3.6% 2020-01-08
CVE-2014-8650 python-requests-Kerberos through 0.5 does not handle mutual authentication In your normal cycle 9.8 critical 3.6% 2019-12-15
CVE-2016-9400 The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical mem… In your normal cycle 9.8 critical 3.6% 2017-02-22
CVE-2016-6143 SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. In your normal cycle 9.8 critical 3.6% 2017-04-13
CVE-2016-10141 An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860… In your normal cycle 9.8 critical 3.6% 2017-01-13
CVE-2019-16733 processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system… In your normal cycle 9.8 critical 3.6% 2019-12-13
CVE-2019-16737 The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arb… In your normal cycle 9.8 critical 3.6% 2019-12-13
← previous page 247 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt