peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,145 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

37,037 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-1581 A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access… In your normal cycle 9.8 critical 3.2% 2019-08-23
CVE-2019-8527 A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote… In your normal cycle 9.1 critical 3.2% 2019-12-18
CVE-2017-13026 The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c, several functions. In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13027 The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13031 The IPv6 fragmentation header parser in tcpdump before 4.9.2 has a buffer over-read in print-frag6.c:frag6_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13032 The RADIUS parser in tcpdump before 4.9.2 has a buffer over-read in print-radius.c:print_attr_string(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13034 The PGM parser in tcpdump before 4.9.2 has a buffer over-read in print-pgm.c:pgm_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13042 The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv6_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13043 The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_multicast_vpn(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13046 The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13047 The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13048 The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13051 The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13053 The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13054 The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13055 The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13688 The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2017-13689 The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print(). In your normal cycle 9.8 critical 3.2% 2017-09-14
CVE-2020-27304 The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file u… In your normal cycle 9.8 critical 3.2% 2021-10-21
CVE-2017-1000235 I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised. In your normal cycle 9.8 critical 3.2% 2017-11-17
CVE-2022-1664 Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal… In your normal cycle 9.8 critical 3.2% 2022-05-26
CVE-2023-37895 Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (inc… In your normal cycle 9.8 critical 3.2% 2023-07-25
CVE-2020-28333 Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not us… In your normal cycle 9.8 critical 3.2% 2020-11-24
CVE-2022-40083 Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by… In your normal cycle 9.6 critical 3.2% 2022-09-28
CVE-2017-6519 avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows r… In your normal cycle 9.1 critical 3.2% 2017-05-01
CVE-2018-16518 A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 22… In your normal cycle 9.8 critical 3.2% 2018-09-05
CVE-2015-0855 The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file… In your normal cycle 9.8 critical 3.2% 2017-03-23
CVE-2015-8212 CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted a… In your normal cycle 9.8 critical 3.2% 2017-01-19
CVE-2020-6017 Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when co… In your normal cycle 9.8 critical 3.2% 2020-12-03
CVE-2020-6018 Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when… In your normal cycle 9.8 critical 3.2% 2020-12-02
← previous page 277 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt