peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,962 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-17364 The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute… In your normal cycle 9.8 critical 3.6% 2019-12-13
CVE-2019-19333 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits"… In your normal cycle 9.8 critical 3.6% 2019-12-06
CVE-2022-47003 A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. In your normal cycle 9.8 critical 3.6% 2023-02-01
CVE-2021-27573 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no… In your normal cycle 9.8 critical 3.6% 2021-05-07
CVE-2020-8570 Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying mul… In your normal cycle 9.1 critical 3.6% 2021-01-21
CVE-2020-6770 Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on t… In your normal cycle 10.0 critical 3.6% 2020-02-07
CVE-2020-13916 A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated c… In your normal cycle 9.8 critical 3.6% 2020-07-28
CVE-2019-10784 phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area,… In your normal cycle 9.6 critical 3.6% 2020-02-04
CVE-2023-26134 Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails… In your normal cycle 9.8 critical 3.6% 2023-06-28
CVE-2023-0947 Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3. In your normal cycle 9.8 critical 3.6% 2023-02-22
CVE-2018-20817 SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a… In your normal cycle 9.8 critical 3.6% 2019-04-19
CVE-2018-19783 Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. In your normal cycle 9.8 critical 3.6% 2019-03-21
CVE-2021-21019 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful… In your normal cycle 9.1 critical 3.6% 2021-02-11
CVE-2016-9480 libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file… In your normal cycle 9.1 critical 3.6% 2016-11-29
CVE-2020-8178 Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks. In your normal cycle 9.8 critical 3.6% 2020-07-15
CVE-2019-10950 Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telne… In your normal cycle 9.8 critical 3.6% 2019-04-30
CVE-2019-14431 In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256… In your normal cycle 9.8 critical 3.6% 2019-07-29
CVE-2023-33338 Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. In your normal cycle 9.8 critical 3.6% 2023-05-23
CVE-2021-43272 An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to… In your normal cycle 9.8 critical 3.6% 2021-11-14
CVE-2018-19725 Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a security bypas… In your normal cycle 9.8 critical 3.6% 2019-03-05
CVE-2017-2345 On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and rest… In your normal cycle 9.8 critical 3.6% 2017-07-17
CVE-2016-7947 Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response. In your normal cycle 9.8 critical 3.6% 2016-12-13
CVE-2016-7948 X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data. In your normal cycle 9.8 critical 3.6% 2016-12-13
CVE-2017-12166 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting i… In your normal cycle 9.8 critical 3.6% 2017-10-04
CVE-2019-0261 Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for… In your normal cycle 9.8 critical 3.6% 2019-02-15
CVE-2017-1002020 Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQ… In your normal cycle 9.8 critical 3.6% 2017-09-14
CVE-2017-1002021 Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it ins… In your normal cycle 9.8 critical 3.6% 2017-09-14
CVE-2017-1002022 Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL… In your normal cycle 9.8 critical 3.6% 2017-09-14
CVE-2020-25928 The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component i… In your normal cycle 9.8 critical 3.6% 2021-08-18
CVE-2023-39001 A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows… In your normal cycle 9.8 critical 3.6% 2023-08-09
← previous page 248 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt