peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,579 CVEs 1,726 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

36,456 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-8741 EXP Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write t… Patch early 9.8 critical 77.2% 2020-01-27
CVE-2016-0854 EXP Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech… Patch early 9.8 critical 77% 2016-01-15
CVE-2017-9101 EXP import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP cod… Patch early 9.8 critical 76.7% 2017-05-21
CVE-2018-14728 EXP upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. Patch early 9.8 critical 76.5% 2018-08-03
CVE-2019-1937 EXP A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Di… Patch early 9.8 critical 75.9% 2019-08-21
CVE-2017-1092 EXP IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X… Patch early 9.8 critical 75.8% 2017-05-22
CVE-2022-2884 EXP A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated… Patch early 9.9 critical 75.7% 2022-10-17
CVE-2004-0847 EXP The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted director… Patch early 9.8 critical 75.7% 2004-11-03
CVE-2022-1162 EXP A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7… Patch early 9.1 critical 75.6% 2022-04-04
CVE-2018-9160 EXP SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. Patch early 9.8 critical 75.6% 2018-03-31
CVE-2022-32429 EXP An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 all… Patch early 9.8 critical 75.6% 2022-08-10
CVE-2019-12255 EXP Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that lead… Patch early 9.8 critical 75.3% 2019-08-09
CVE-2022-23178 EXP An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthent… Patch early 9.8 critical 75.2% 2022-01-15
CVE-2015-2794 EXP The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct r… Patch early 9.8 critical 75.1% 2017-02-06
CVE-2019-20215 EXP D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()… Patch early 9.8 critical 75.1% 2020-01-29
CVE-2013-0803 EXP A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. Patch early 9.8 critical 75% 2020-02-11
CVE-2018-16167 EXP LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. Patch early 9.8 critical 74.9% 2019-01-09
CVE-2023-6019 EXP A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remot… Patch early 9.8 critical 74.6% 2023-11-16
CVE-2020-35848 EXP Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. Patch early 9.8 critical 74.6% 2020-12-30
CVE-2017-8046 EXP Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spri… Patch early 9.8 critical 74.5% 2018-01-04
CVE-2013-7390 EXP Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attacker… Patch early 9.8 critical 74.5% 2020-01-27
CVE-2016-1287 EXP Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before… Patch early 9.8 critical 74.2% 2016-02-11
CVE-2015-9266 EXP The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to u… Patch early 9.8 critical 74% 2018-09-05
CVE-2013-2010 EXP WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability Patch early 9.8 critical 73.9% 2020-02-12
CVE-2020-17456 EXP SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page. Patch early 9.8 critical 73.6% 2020-08-20
CVE-2015-8249 EXP The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the… Patch early 9.8 critical 73.6% 2017-09-28
CVE-2020-24881 EXP SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. Patch early 9.8 critical 73.4% 2020-11-02
CVE-2017-17560 EXP An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php… Patch early 9.8 critical 73.4% 2017-12-12
CVE-2020-11698 EXP An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote at… Patch early 9.8 critical 73.2% 2020-09-17
CVE-2017-11467 EXP OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to exec… Patch early 9.8 critical 73.1% 2017-07-20
← previous page 27 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt