peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,991 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-7934 The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print(). In your normal cycle 9.8 critical 3.4% 2017-01-28
CVE-2016-7940 The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions. In your normal cycle 9.8 critical 3.4% 2017-01-28
CVE-2016-7975 The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print(). In your normal cycle 9.8 critical 3.4% 2017-01-28
CVE-2016-7993 A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightw… In your normal cycle 9.8 critical 3.4% 2017-01-28
CVE-2017-5486 The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). In your normal cycle 9.8 critical 3.4% 2017-01-28
CVE-2018-19873 An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. In your normal cycle 9.8 critical 3.4% 2018-12-26
CVE-2025-70219 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. In your normal cycle 9.8 critical 3.4% 2026-03-04
CVE-2026-29042 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a c… In your normal cycle 9.8 critical 3.4% 2026-03-06
CVE-2019-8648 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3.… In your normal cycle 9.8 critical 3.4% 2019-12-18
CVE-2017-5410 Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is manag… In your normal cycle 9.8 critical 3.4% 2018-06-11
CVE-2017-1000218 LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution. In your normal cycle 9.8 critical 3.4% 2017-11-17
CVE-2019-10979 SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password. In your normal cycle 9.8 critical 3.4% 2019-07-01
CVE-2016-1000003 Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code. In your normal cycle 9.8 critical 3.4% 2016-10-07
CVE-2005-1141 Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via… In your normal cycle 9.8 critical 3.4% 2005-04-15
CVE-2009-2422 The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request… In your normal cycle 9.8 critical 3.4% 2009-07-10
CVE-2017-7818 A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through t… In your normal cycle 9.8 critical 3.4% 2018-06-11
CVE-2017-7819 A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from… In your normal cycle 9.8 critical 3.4% 2018-06-11
CVE-2020-7707 The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function. In your normal cycle 9.8 critical 3.4% 2020-08-18
CVE-2019-15304 Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Serv… In your normal cycle 9.1 critical 3.4% 2019-08-26
CVE-2021-24148 A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauth… In your normal cycle 9.8 critical 3.4% 2021-03-18
CVE-2018-18501 Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of… In your normal cycle 9.8 critical 3.4% 2019-02-05
CVE-2021-44127 In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands wh… In your normal cycle 9.8 critical 3.4% 2022-03-27
CVE-2023-26822 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main. In your normal cycle 9.8 critical 3.4% 2023-04-01
CVE-2026-74233 Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink… In your normal cycle 9.8 critical 3.4% 2026-08-27
CVE-2021-27391 A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3… In your normal cycle 9.8 critical 3.4% 2021-09-14
CVE-2022-29622 An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third partie… In your normal cycle 9.8 critical 3.4% 2022-05-16
CVE-2020-17142 Microsoft Exchange Remote Code Execution Vulnerability In your normal cycle 9.1 critical 3.4% 2020-12-10
CVE-2016-10312 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04… In your normal cycle 9.8 critical 3.4% 2017-04-03
CVE-2019-5085 An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A speci… In your normal cycle 9.8 critical 3.4% 2019-12-12
CVE-2022-2848 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is no… In your normal cycle 9.1 critical 3.4% 2023-03-29
← previous page 264 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt