peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

37,039 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-28360 Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker c… In your normal cycle 9.8 critical 3.1% 2020-11-23
CVE-2017-2142 Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. In your normal cycle 9.8 critical 3.1% 2017-04-28
CVE-2020-17467 An issue was discovered in FNET through 4.6.4. The code for processing the hostname from an LLMNR request doesn't check for '\0' termination. Therefor… In your normal cycle 9.1 critical 3.1% 2020-12-11
CVE-2016-10764 In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MA… In your normal cycle 9.8 critical 3.1% 2019-07-27
CVE-2019-15741 An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation In your normal cycle 9.8 critical 3.1% 2019-09-16
CVE-2018-10771 Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (applic… In your normal cycle 9.8 critical 3.1% 2018-05-07
CVE-2021-22201 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server… In your normal cycle 9.6 critical 3.1% 2021-04-02
CVE-2021-43523 In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo… In your normal cycle 9.6 critical 3.1% 2021-11-10
CVE-2022-23806 Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that i… In your normal cycle 9.1 critical 3.1% 2022-02-11
CVE-2020-7055 An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to exec… In your normal cycle 9.9 critical 3.1% 2020-04-22
CVE-2018-5098 A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentia… In your normal cycle 9.8 critical 3.1% 2018-06-11
CVE-2022-44621 Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. In your normal cycle 9.8 critical 3.1% 2022-12-30
CVE-2021-33963 China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter… In your normal cycle 9.8 critical 3.1% 2022-01-15
CVE-2020-28276 Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code… In your normal cycle 9.8 critical 3.1% 2020-12-29
CVE-2020-28277 Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code exec… In your normal cycle 9.8 critical 3.1% 2020-12-29
CVE-2020-28278 Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code e… In your normal cycle 9.8 critical 3.1% 2020-12-29
CVE-2020-28280 Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote c… In your normal cycle 9.8 critical 3.1% 2020-12-29
CVE-2018-1999010 FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resul… In your normal cycle 9.8 critical 3.1% 2018-07-23
CVE-2017-8248 A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation… In your normal cycle 9.8 critical 3.1% 2017-08-16
CVE-2021-40883 A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. In your normal cycle 9.8 critical 3.1% 2021-12-14
CVE-2018-14473 OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sendin… In your normal cycle 9.1 critical 3.1% 2018-08-04
CVE-2016-9678 Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. In your normal cycle 9.8 critical 3.1% 2017-01-18
CVE-2021-45742 TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows at… In your normal cycle 9.8 critical 3.1% 2022-02-04
CVE-2020-11966 In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The… In your normal cycle 9.8 critical 3.1% 2020-04-21
CVE-2019-11353 The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities b… In your normal cycle 9.8 critical 3.1% 2019-05-09
CVE-2021-39383 DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. In your normal cycle 9.8 critical 3.1% 2022-03-20
CVE-2019-9025 An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_… In your normal cycle 9.8 critical 3.1% 2019-02-22
CVE-2020-8432 In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what… In your normal cycle 9.8 critical 3.1% 2020-01-29
CVE-2021-35973 NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated att… In your normal cycle 9.8 critical 3.1% 2021-06-30
CVE-2020-5616 [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0,… In your normal cycle 9.8 critical 3.1% 2020-08-04
← previous page 289 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt