peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,994 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-9193 The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3… In your normal cycle 9.8 critical 3.3% 2025-02-28
CVE-2016-7935 The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print(). In your normal cycle 9.8 critical 3.3% 2017-01-28
CVE-2016-7984 The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print(). In your normal cycle 9.8 critical 3.3% 2017-01-28
CVE-2016-7992 The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print(). In your normal cycle 9.8 critical 3.3% 2017-01-28
CVE-2017-15714 The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code t… In your normal cycle 9.8 critical 3.3% 2018-01-04
CVE-2020-35636 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::rea… In your normal cycle 9.8 critical 3.3% 2021-03-04
CVE-2017-9363 Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authe… In your normal cycle 9.8 critical 3.3% 2017-06-02
CVE-2022-28568 Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obta… In your normal cycle 9.8 critical 3.3% 2022-05-04
CVE-2020-10109 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header,… In your normal cycle 9.8 critical 3.3% 2020-03-12
CVE-2019-3905 Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. In your normal cycle 10.0 critical 3.3% 2019-01-03
CVE-2014-9746 The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in ty… In your normal cycle 9.8 critical 3.3% 2016-06-07
CVE-2017-17028 A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) b… In your normal cycle 9.8 critical 3.3% 2017-12-21
CVE-2020-26943 An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may tri… In your normal cycle 9.9 critical 3.3% 2020-10-16
CVE-2017-12858 Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors. In your normal cycle 9.8 critical 3.3% 2017-08-23
CVE-2019-15958 A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticate… In your normal cycle 9.8 critical 3.3% 2019-11-26
CVE-2017-4989 In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypas… In your normal cycle 9.8 critical 3.3% 2017-06-21
CVE-2024-22399 Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seata… In your normal cycle 9.8 critical 3.3% 2024-09-16
CVE-2026-8986 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or… In your normal cycle 9.8 critical 3.3% 2026-07-21
CVE-2018-10603 Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, whic… In your normal cycle 9.8 critical 3.3% 2018-07-31
CVE-2017-12896 The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-12899 The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-12987 The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-13020 The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-13687 The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-13725 The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print(). In your normal cycle 9.8 critical 3.3% 2017-09-14
CVE-2017-17027 A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116… In your normal cycle 9.8 critical 3.3% 2017-12-21
CVE-2017-17029 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171… In your normal cycle 9.8 critical 3.3% 2017-12-21
CVE-2017-17030 A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171… In your normal cycle 9.8 critical 3.3% 2017-12-21
CVE-2017-17031 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20… In your normal cycle 9.8 critical 3.3% 2017-12-21
CVE-2017-17032 A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20… In your normal cycle 9.8 critical 3.3% 2017-12-21
← previous page 270 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt