peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,963 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-23626 A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerabilit… In your normal cycle 9.0 critical 3.5% 2024-01-26
CVE-2024-23627 A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulne… In your normal cycle 9.0 critical 3.5% 2024-01-26
CVE-2017-6050 A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which m… In your normal cycle 9.8 critical 3.5% 2017-06-21
CVE-2021-27944 Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthentica… In your normal cycle 9.8 critical 3.5% 2021-08-26
CVE-2020-0594 Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthentic… In your normal cycle 9.8 critical 3.5% 2020-06-15
CVE-2016-7109 Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a diff… In your normal cycle 9.8 critical 3.5% 2016-09-07
CVE-2019-11005 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remot… In your normal cycle 9.8 critical 3.5% 2019-04-08
CVE-2021-40719 Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation whe… In your normal cycle 9.8 critical 3.5% 2021-10-21
CVE-2019-12148 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerabil… In your normal cycle 9.8 critical 3.5% 2019-10-22
CVE-2018-10617 Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buff… In your normal cycle 9.8 critical 3.5% 2018-06-18
CVE-2018-10621 Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buf… In your normal cycle 9.8 critical 3.5% 2018-06-18
CVE-2018-10623 Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be… In your normal cycle 9.8 critical 3.5% 2018-06-18
CVE-2015-7541 The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attac… In your normal cycle 10.0 critical 3.5% 2016-01-08
CVE-2018-15747 The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system… In your normal cycle 9.8 critical 3.5% 2019-06-21
CVE-2017-16764 An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML par… In your normal cycle 9.8 critical 3.5% 2017-11-10
CVE-2020-24384 A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could… In your normal cycle 9.8 critical 3.5% 2020-11-10
CVE-2024-9290 The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and… In your normal cycle 9.8 critical 3.5% 2024-12-13
CVE-2019-7164 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. In your normal cycle 9.8 critical 3.5% 2019-02-20
CVE-2020-11673 An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone… In your normal cycle 9.8 critical 3.5% 2020-04-13
CVE-2021-42911 A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfun… In your normal cycle 9.8 critical 3.5% 2022-03-29
CVE-2021-43484 A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension o… In your normal cycle 9.8 critical 3.5% 2022-03-31
CVE-2018-6667 Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exec… In your normal cycle 10.0 critical 3.5% 2018-06-26
CVE-2022-46366 Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17… In your normal cycle 9.8 critical 3.5% 2022-12-02
CVE-2017-6551 Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Con… In your normal cycle 9.8 critical 3.5% 2017-05-02
CVE-2017-9634 Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to overwrite arbitrary memory loc… In your normal cycle 9.8 critical 3.5% 2018-04-17
CVE-2017-9636 Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary c… In your normal cycle 9.8 critical 3.5% 2018-04-17
CVE-2017-9638 Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary c… In your normal cycle 9.8 critical 3.5% 2018-04-17
CVE-2016-8348 An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Lie… In your normal cycle 9.8 critical 3.5% 2017-02-13
CVE-2026-19598 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,… In your normal cycle 9.8 critical 3.5% 2026-08-15
CVE-2022-23900 A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized… In your normal cycle 9.8 critical 3.5% 2022-04-07
← previous page 254 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt