peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,994 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1219 Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. In your normal cycle 9.8 critical 3.3% 2017-04-20
CVE-2021-24036 Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possib… In your normal cycle 9.8 critical 3.3% 2021-07-23
CVE-2019-11411 An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow. In your normal cycle 9.8 critical 3.3% 2019-04-22
CVE-2025-23266 NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute ar… In your normal cycle 9.0 critical 3.3% 2025-07-17
CVE-2023-4666 The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauth… In your normal cycle 9.8 critical 3.3% 2023-10-16
CVE-2020-13393 An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19… In your normal cycle 9.8 critical 3.3% 2020-05-22
CVE-2008-2369 manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the serv… In your normal cycle 9.1 critical 3.3% 2008-08-14
CVE-2017-5219 An issue was discovered in SageCRM 7.x before 7.3 SP3. The Component Manager functionality, provided by SageCRM, permits additional components to be a… In your normal cycle 9.8 critical 3.3% 2017-02-02
CVE-2019-19839 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=im… In your normal cycle 9.8 critical 3.3% 2020-01-23
CVE-2019-19841 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=pa… In your normal cycle 9.8 critical 3.3% 2020-01-22
CVE-2015-7411 The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain… In your normal cycle 9.9 critical 3.3% 2016-03-12
CVE-2023-40743 ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "Se… In your normal cycle 9.8 critical 3.3% 2023-09-05
CVE-2022-34592 Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows a… In your normal cycle 9.8 critical 3.3% 2022-07-07
CVE-2025-66039 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the au… In your normal cycle 9.8 critical 3.3% 2025-12-09
CVE-2019-5074 An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07… In your normal cycle 9.8 critical 3.3% 2019-12-18
CVE-2016-8721 An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running… In your normal cycle 9.1 critical 3.3% 2017-04-20
CVE-2007-6013 Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtain… In your normal cycle 9.8 critical 3.3% 2007-11-19
CVE-2020-12828 An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhos… In your normal cycle 9.8 critical 3.3% 2020-05-21
CVE-2026-82689 A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/i… In your normal cycle 9.9 critical 3.3% 2026-08-31
CVE-2026-82692 A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a… In your normal cycle 9.9 critical 3.3% 2026-08-31
CVE-2026-85223 A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the com… In your normal cycle 9.9 critical 3.3% 2026-09-03
CVE-2026-90699 A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manip… In your normal cycle 9.9 critical 3.3% 2026-09-14
CVE-2017-0356 A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker t… In your normal cycle 9.8 critical 3.3% 2018-04-13
CVE-2017-9479 The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitra… In your normal cycle 9.8 critical 3.3% 2017-07-31
CVE-2021-31757 An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows a… In your normal cycle 9.8 critical 3.3% 2021-05-07
CVE-2021-40722 AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that co… In your normal cycle 9.8 critical 3.3% 2022-01-13
CVE-2017-7544 libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by i… In your normal cycle 9.1 critical 3.3% 2017-09-21
CVE-2026-12571 An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. In your normal cycle 9.8 critical 3.3% 2026-08-11
CVE-2026-42364 An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configur… In your normal cycle 9.9 critical 3.3% 2026-05-04
CVE-2019-18671 Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss… In your normal cycle 9.8 critical 3.3% 2019-12-06
← previous page 271 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt