peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

37,037 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17434 The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in… In your normal cycle 9.8 critical 3.3% 2017-12-06
CVE-2021-30228 The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2021-30230 The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shel… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2021-30231 The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metach… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2021-30232 The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell m… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2021-30233 The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell meta… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2021-30234 The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell me… In your normal cycle 9.8 critical 3.3% 2021-04-29
CVE-2016-6223 The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash… In your normal cycle 9.1 critical 3.3% 2017-01-23
CVE-2017-18201 An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c. In your normal cycle 9.8 critical 3.3% 2018-02-26
CVE-2020-11967 In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note… In your normal cycle 9.8 critical 3.3% 2020-04-21
CVE-2025-59361 The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthen… In your normal cycle 9.8 critical 3.3% 2025-09-15
CVE-2021-21025 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Su… In your normal cycle 9.1 critical 3.3% 2021-02-11
CVE-2021-34423 A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Cl… In your normal cycle 9.8 critical 3.3% 2021-11-24
CVE-2018-6444 A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerab… In your normal cycle 9.8 critical 3.3% 2019-01-22
CVE-2016-4734 WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (me… In your normal cycle 9.6 critical 3.3% 2016-09-25
CVE-2020-13753 The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEW… In your normal cycle 10.0 critical 3.3% 2020-07-14
CVE-2016-5081 ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET sessio… In your normal cycle 9.8 critical 3.3% 2016-08-24
CVE-2016-6532 DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this pas… In your normal cycle 9.8 critical 3.3% 2016-09-24
CVE-2019-6552 Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplie… In your normal cycle 9.8 critical 3.3% 2019-04-05
CVE-2022-25390 DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.ph… In your normal cycle 9.8 critical 3.3% 2022-03-18
CVE-2021-37161 A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions o… In your normal cycle 9.8 critical 3.3% 2021-08-02
CVE-2021-37162 A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus… In your normal cycle 9.8 critical 3.3% 2021-08-02
CVE-2021-37165 A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus… In your normal cycle 9.8 critical 3.3% 2021-08-02
CVE-2017-9521 The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v3… In your normal cycle 9.8 critical 3.3% 2017-07-31
CVE-2018-12407 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuf… In your normal cycle 9.8 critical 3.3% 2019-02-28
CVE-2019-12549 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of… In your normal cycle 9.8 critical 3.3% 2019-06-17
CVE-2018-7096 A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to a… In your normal cycle 9.8 critical 3.3% 2018-08-14
CVE-2022-25809 Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices… In your normal cycle 9.8 critical 3.3% 2022-02-24
CVE-2018-5154 A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable… In your normal cycle 9.8 critical 3.3% 2018-06-11
CVE-2019-16734 Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitra… In your normal cycle 9.8 critical 3.3% 2019-12-13
← previous page 272 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt