peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,968 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-33443 Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary admini… In your normal cycle 9.8 critical 3.5% 2023-06-08
CVE-2022-42493 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reques… In your normal cycle 9.8 critical 3.5% 2023-01-26
CVE-2021-45414 A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver… In your normal cycle 9.8 critical 3.5% 2022-02-28
CVE-2022-0730 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. In your normal cycle 9.8 critical 3.5% 2022-03-03
CVE-2018-7811 An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could a… In your normal cycle 9.8 critical 3.5% 2018-11-30
CVE-2020-6989 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows r… In your normal cycle 9.8 critical 3.5% 2020-03-24
CVE-2017-1710 A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-F… In your normal cycle 9.8 critical 3.5% 2017-11-13
CVE-2022-28397 An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. N… In your normal cycle 9.8 critical 3.5% 2022-04-12
CVE-2018-18912 An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request ha… In your normal cycle 9.8 critical 3.5% 2019-05-13
CVE-2018-5768 A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COO… In your normal cycle 9.8 critical 3.5% 2018-03-20
CVE-2018-19355 modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute a… In your normal cycle 9.8 critical 3.5% 2018-11-19
CVE-2019-12042 Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda prod… In your normal cycle 9.8 critical 3.5% 2019-05-23
CVE-2017-9772 Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marke… In your normal cycle 9.8 critical 3.5% 2017-06-23
CVE-2023-3533 Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attack… In your normal cycle 9.8 critical 3.5% 2023-11-28
CVE-2017-16088 The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire… In your normal cycle 10.0 critical 3.5% 2018-06-07
CVE-2018-14818 WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior have a stack-based buffer overflow vulnerabi… In your normal cycle 9.8 critical 3.5% 2018-10-08
CVE-2020-25066 A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or… In your normal cycle 10.0 critical 3.5% 2020-12-22
CVE-2021-27468 The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vul… In your normal cycle 10.0 critical 3.5% 2022-03-23
CVE-2016-4564 The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to loc… In your normal cycle 9.8 critical 3.5% 2016-06-04
CVE-2016-7939 The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions. In your normal cycle 9.8 critical 3.5% 2017-01-28
CVE-2019-5490 Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that coul… In your normal cycle 9.8 critical 3.5% 2019-03-21
CVE-2020-5599 TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model… In your normal cycle 9.8 critical 3.5% 2020-07-07
CVE-2015-5334 Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible… In your normal cycle 9.8 critical 3.5% 2020-01-23
CVE-2021-3657 A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMA… In your normal cycle 9.8 critical 3.5% 2022-02-18
CVE-2017-7856 LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in v… In your normal cycle 9.8 critical 3.5% 2017-04-14
CVE-2018-15715 Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable… In your normal cycle 9.8 critical 3.5% 2018-11-30
CVE-2018-18753 Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. In your normal cycle 9.8 critical 3.5% 2018-10-29
CVE-2021-32708 Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under cert… In your normal cycle 9.8 critical 3.5% 2021-06-24
CVE-2019-18364 In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. In your normal cycle 9.8 critical 3.5% 2019-10-31
CVE-2017-7728 On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incor… In your normal cycle 9.8 critical 3.5% 2017-07-11
← previous page 256 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt