peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

37,039 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-21110 Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafte… In your normal cycle 9.6 critical 3.1% 2021-01-08
CVE-1999-1324 VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in l… In your normal cycle 9.8 critical 3.1% 1999-12-31
CVE-2019-5604 In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-… In your normal cycle 9.6 critical 3.1% 2019-07-26
CVE-2016-4598 QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafte… In your normal cycle 9.8 critical 3.1% 2016-07-22
CVE-2021-33970 Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges. In your normal cycle 10.0 critical 3.1% 2023-04-19
CVE-2018-0264 A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker… In your normal cycle 9.6 critical 3.1% 2018-05-02
CVE-2022-28712 A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-cra… In your normal cycle 9.0 critical 3.1% 2022-08-22
CVE-2024-54756 A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supply… In your normal cycle 9.8 critical 3.1% 2025-02-20
CVE-2017-11636 GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widt… In your normal cycle 9.8 critical 3.1% 2017-07-26
CVE-2017-15655 Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378… In your normal cycle 9.6 critical 3.1% 2018-01-31
CVE-2016-7932 The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum(). In your normal cycle 9.8 critical 3.1% 2017-01-28
CVE-2016-2002 The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.… In your normal cycle 9.8 critical 3.1% 2016-04-20
CVE-2024-28991 SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would al… In your normal cycle 9.0 critical 3.1% 2024-09-12
CVE-2024-46256 A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. In your normal cycle 9.8 critical 3.1% 2024-09-27
CVE-2017-5443 An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox E… In your normal cycle 9.8 critical 3.1% 2018-06-11
CVE-2017-5446 An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable… In your normal cycle 9.8 critical 3.1% 2018-06-11
CVE-2016-7938 The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame(). In your normal cycle 9.8 critical 3.1% 2017-01-28
CVE-2021-27449 Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server. In your normal cycle 9.9 critical 3.1% 2021-12-21
CVE-2022-25498 CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php. In your normal cycle 9.8 critical 3.1% 2022-03-15
CVE-2022-36413 Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. In your normal cycle 9.1 critical 3.1% 2023-03-23
CVE-2024-8943 The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verif… In your normal cycle 9.8 critical 3.1% 2024-10-08
CVE-2016-6447 A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected syste… In your normal cycle 9.8 critical 3.1% 2016-11-03
CVE-2016-9020 SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to exec… In your normal cycle 9.8 critical 3.1% 2017-03-07
CVE-2017-9225 An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds wr… In your normal cycle 9.8 critical 3.1% 2017-05-24
CVE-2013-4451 gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating… In your normal cycle 9.8 critical 3.1% 2018-09-21
CVE-2020-3140 A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain… In your normal cycle 9.8 critical 3.1% 2020-07-16
CVE-2018-20813 An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2. In your normal cycle 9.8 critical 3.1% 2019-06-28
CVE-2018-20771 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7… In your normal cycle 9.8 critical 3.1% 2019-02-10
CVE-2016-9366 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.… In your normal cycle 9.8 critical 3.1% 2017-02-13
CVE-2017-8359 Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/s… In your normal cycle 9.8 critical 3.1% 2017-04-30
← previous page 288 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt