peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,879 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,991 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-13581 An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via… In your normal cycle 9.8 critical 3.4% 2019-11-15
CVE-2019-19374 An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS… In your normal cycle 9.1 critical 3.4% 2019-12-11
CVE-2021-36022 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Wi… In your normal cycle 9.1 critical 3.4% 2021-09-01
CVE-2020-12388 The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fire… In your normal cycle 10.0 critical 3.4% 2020-05-26
CVE-2010-2446 Rbot Reaction plugin allows command execution In your normal cycle 9.8 critical 3.4% 2019-11-06
CVE-2015-7544 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Super… In your normal cycle 9.1 critical 3.4% 2017-09-25
CVE-2018-21162 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86,… In your normal cycle 9.8 critical 3.4% 2020-04-23
CVE-2020-0595 Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated… In your normal cycle 9.8 critical 3.4% 2020-06-15
CVE-2020-9669 Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead… In your normal cycle 9.8 critical 3.4% 2020-07-17
CVE-2018-11542 A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary com… In your normal cycle 9.8 critical 3.4% 2018-07-09
CVE-2017-1002012 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code… In your normal cycle 9.8 critical 3.4% 2017-09-14
CVE-2020-26167 In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator… In your normal cycle 9.8 critical 3.4% 2020-11-04
CVE-2020-20276 An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to… In your normal cycle 9.8 critical 3.4% 2020-12-18
CVE-2017-1000374 A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certai… In your normal cycle 9.8 critical 3.4% 2017-06-19
CVE-2018-1822 IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to… In your normal cycle 9.8 critical 3.4% 2018-10-18
CVE-2021-37422 Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. In your normal cycle 9.8 critical 3.4% 2021-09-10
CVE-2021-41075 The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API. In your normal cycle 9.8 critical 3.4% 2021-10-13
CVE-2019-1003040 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scrip… In your normal cycle 9.8 critical 3.4% 2019-03-28
CVE-2019-1003041 A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri… In your normal cycle 9.8 critical 3.4% 2019-03-28
CVE-2019-18641 Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. In your normal cycle 9.8 critical 3.4% 2020-03-20
CVE-2019-18805 An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tc… In your normal cycle 9.8 critical 3.4% 2019-11-07
CVE-2022-2825 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is no… In your normal cycle 9.8 critical 3.4% 2023-03-29
CVE-2008-7315 UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands. In your normal cycle 9.8 critical 3.4% 2017-10-10
CVE-2020-15916 goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharac… In your normal cycle 9.8 critical 3.4% 2020-07-23
CVE-2019-13613 CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier… In your normal cycle 9.8 critical 3.4% 2019-07-17
CVE-2019-13614 CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-bas… In your normal cycle 9.8 critical 3.4% 2019-07-17
CVE-2018-1000537 Marlin Firmware Marlin version 1.1.x and earlier contains a Buffer Overflow vulnerability in cardreader.cpp (Depending on branch/version) that can res… In your normal cycle 9.8 critical 3.4% 2018-06-26
CVE-2017-13021 The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_print(). In your normal cycle 9.8 critical 3.4% 2017-09-14
CVE-2017-13022 The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute(). In your normal cycle 9.8 critical 3.4% 2017-09-14
CVE-2017-13023 The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print(). In your normal cycle 9.8 critical 3.4% 2017-09-14
← previous page 260 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt