peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,169 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

37,038 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-7072 A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. In your normal cycle 9.8 critical 3.1% 2018-08-06
CVE-2016-7985 The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print(). In your normal cycle 9.8 critical 3.1% 2017-01-28
CVE-2016-8574 The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print(). In your normal cycle 9.8 critical 3.1% 2017-01-28
CVE-2017-16743 An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32… In your normal cycle 9.8 critical 3.1% 2018-01-12
CVE-2021-46386 File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsof… In your normal cycle 9.8 critical 3.1% 2022-01-26
CVE-2023-48692 Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote c… In your normal cycle 9.0 critical 3.1% 2023-12-05
CVE-2016-6530 Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain a… In your normal cycle 9.8 critical 3.1% 2016-09-21
CVE-2017-1000444 Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure… In your normal cycle 9.8 critical 3.1% 2018-01-02
CVE-2017-7640 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the… In your normal cycle 9.8 critical 3.1% 2018-03-08
CVE-2019-17362 In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequen… In your normal cycle 9.1 critical 3.1% 2019-10-09
CVE-2020-10640 Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code executi… In your normal cycle 10.0 critical 3.1% 2022-02-24
CVE-2019-17455 Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations,… In your normal cycle 9.8 critical 3.1% 2019-10-10
CVE-2022-31794 An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestT… In your normal cycle 9.8 critical 3.1% 2022-06-20
CVE-2022-31795 An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_fin… In your normal cycle 9.8 critical 3.1% 2022-06-20
CVE-2024-13979 A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL comma… In your normal cycle 9.8 critical 3.1% 2025-08-27
CVE-2020-28279 Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote… In your normal cycle 9.8 critical 3.1% 2020-12-29
CVE-2017-10934 All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (AC… In your normal cycle 9.8 critical 3.1% 2018-07-25
CVE-2017-7758 An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vul… In your normal cycle 9.1 critical 3.1% 2018-06-11
CVE-2019-10985 In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of a user-supplied path prior to… In your normal cycle 9.1 critical 3.1% 2019-06-28
CVE-2019-9201 Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as de… In your normal cycle 9.8 critical 3.1% 2019-02-26
CVE-2020-24987 Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authenticatio… In your normal cycle 9.8 critical 3.1% 2020-09-04
CVE-2021-37599 The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthe… In your normal cycle 9.8 critical 3.1% 2021-08-12
CVE-2021-34084 OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via t… In your normal cycle 9.8 critical 3.1% 2022-06-02
CVE-2025-27407 graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, a… In your normal cycle 9.0 critical 3.1% 2025-03-12
CVE-2023-30869 Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads:… In your normal cycle 9.8 critical 3.1% 2023-05-02
CVE-2016-2359 Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously mak… In your normal cycle 9.8 critical 3.1% 2019-10-25
CVE-2018-5440 A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web… In your normal cycle 9.8 critical 3.1% 2018-02-15
CVE-2020-25749 The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full… In your normal cycle 9.8 critical 3.1% 2020-09-25
CVE-2020-36326 PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE… In your normal cycle 9.8 critical 3.1% 2021-04-28
CVE-2017-9785 Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie. In your normal cycle 9.8 critical 3.1% 2017-07-20
← previous page 287 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt