peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,813 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,970 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-7953 Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string. In your normal cycle 9.8 critical 3.5% 2016-12-13
CVE-2018-9207 Arbitrary file upload in jQuery Upload File <= 4.0.2 In your normal cycle 9.8 critical 3.5% 2018-11-19
CVE-2019-1804 A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an… In your normal cycle 9.8 critical 3.5% 2019-05-03
CVE-2015-8298 Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands vi… In your normal cycle 9.8 critical 3.5% 2018-09-24
CVE-2018-19646 The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because co… In your normal cycle 9.8 critical 3.5% 2018-11-28
CVE-2023-46266 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. In your normal cycle 9.1 critical 3.5% 2023-12-19
CVE-2023-34754 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=ed… In your normal cycle 9.8 critical 3.4% 2023-06-14
CVE-2016-0903 Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote… In your normal cycle 9.1 critical 3.4% 2016-09-21
CVE-2018-5155 A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash… In your normal cycle 9.8 critical 3.4% 2018-06-11
CVE-2024-23653 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containe… In your normal cycle 9.8 critical 3.4% 2024-01-31
CVE-2019-16239 process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes. In your normal cycle 9.8 critical 3.4% 2019-09-17
CVE-2017-16615 An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When proc… In your normal cycle 9.8 critical 3.4% 2017-11-08
CVE-2018-3856 An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The… In your normal cycle 9.9 critical 3.4% 2018-08-23
CVE-2020-29016 A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to… In your normal cycle 9.8 critical 3.4% 2021-01-14
CVE-2021-20232 A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential… In your normal cycle 9.8 critical 3.4% 2021-03-12
CVE-2018-16530 A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process cre… In your normal cycle 9.8 critical 3.4% 2019-04-09
CVE-2018-16957 The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracl… In your normal cycle 9.8 critical 3.4% 2018-09-18
CVE-2017-10965 An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer. In your normal cycle 9.8 critical 3.4% 2017-07-07
CVE-2019-10069 In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. In your normal cycle 9.8 critical 3.4% 2019-05-31
CVE-2019-13658 CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and com… In your normal cycle 9.8 critical 3.4% 2019-10-02
CVE-2019-7537 An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python command… In your normal cycle 9.8 critical 3.4% 2019-03-21
CVE-2019-0938 An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser,… In your normal cycle 9.0 critical 3.4% 2019-05-16
CVE-2020-3330 A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker t… In your normal cycle 9.8 critical 3.4% 2020-07-16
CVE-2017-5946 The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an… In your normal cycle 9.8 critical 3.4% 2017-02-27
CVE-2018-15386 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have d… In your normal cycle 9.8 critical 3.4% 2018-10-05
CVE-2020-12763 TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This… In your normal cycle 9.8 critical 3.4% 2020-05-13
CVE-2023-1424 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules… In your normal cycle 10.0 critical 3.4% 2023-05-24
CVE-2021-43439 RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely In your normal cycle 9.8 critical 3.4% 2021-12-20
CVE-2022-21744 In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Pac… In your normal cycle 9.8 critical 3.4% 2022-07-06
CVE-2023-36281 An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ o… In your normal cycle 9.8 critical 3.4% 2023-08-22
← previous page 259 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt