peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,729 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

36,962 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2026-82688 A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the fi… In your normal cycle 9.1 critical 3.6% 2026-08-31
CVE-2026-82690 A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/… In your normal cycle 9.1 critical 3.6% 2026-08-31
CVE-2026-82691 A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality… In your normal cycle 9.1 critical 3.6% 2026-08-31
CVE-2026-85222 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_cente… In your normal cycle 9.1 critical 3.6% 2026-09-03
CVE-2026-85224 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component… In your normal cycle 9.1 critical 3.6% 2026-09-03
CVE-2026-90702 A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument… In your normal cycle 9.1 critical 3.6% 2026-09-14
CVE-2026-90703 A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such ma… In your normal cycle 9.1 critical 3.6% 2026-09-14
CVE-2021-39377 A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL… In your normal cycle 9.8 critical 3.6% 2021-09-01
CVE-2018-1000827 Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, deni… In your normal cycle 9.8 critical 3.6% 2018-12-20
CVE-2020-13091 pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an… In your normal cycle 9.8 critical 3.6% 2020-05-15
CVE-2020-7614 npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation… In your normal cycle 9.8 critical 3.6% 2020-04-07
CVE-2021-23389 The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. In your normal cycle 9.8 critical 3.6% 2021-07-12
CVE-2016-5297 An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects… In your normal cycle 9.8 critical 3.6% 2018-06-11
CVE-2016-9533 tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDif… In your normal cycle 9.8 critical 3.6% 2016-11-22
CVE-2017-5205 The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). In your normal cycle 9.8 critical 3.6% 2017-01-28
CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection… In your normal cycle 9.8 critical 3.6% 2017-10-19
CVE-2018-16974 An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /fileman… In your normal cycle 9.8 critical 3.6% 2018-09-12
CVE-2017-16226 The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the glo… In your normal cycle 9.8 critical 3.6% 2018-06-07
CVE-2023-4490 The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injectio… In your normal cycle 9.8 critical 3.6% 2023-09-25
CVE-2017-7824 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect val… In your normal cycle 9.8 critical 3.6% 2018-06-11
CVE-2019-19628 In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escal… In your normal cycle 9.8 critical 3.6% 2020-01-05
CVE-2024-10811 Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthent… In your normal cycle 9.8 critical 3.6% 2025-01-14
CVE-2022-26496 In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by… In your normal cycle 9.8 critical 3.6% 2022-03-06
CVE-2024-43498 .NET and Visual Studio Remote Code Execution Vulnerability In your normal cycle 9.8 critical 3.6% 2024-11-12
CVE-2022-40664 Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. In your normal cycle 9.8 critical 3.6% 2022-10-12
CVE-2019-19836 AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcm… In your normal cycle 9.8 critical 3.6% 2020-01-22
CVE-2016-5453 Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiali… In your normal cycle 9.8 critical 3.6% 2016-07-21
CVE-2021-23449 This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. In your normal cycle 9.8 critical 3.6% 2021-10-18
CVE-2020-6932 An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versio… In your normal cycle 10.0 critical 3.6% 2020-08-12
CVE-2020-18717 SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. In your normal cycle 9.8 critical 3.6% 2021-02-05
← previous page 250 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt