peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,457 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-10594 EXP Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS… Patch early 9.8 critical 68.6% 2018-06-26
CVE-2016-6195 EXP SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remot… Patch early 9.8 critical 68.5% 2016-08-30
CVE-2024-28000 EXP Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a th… Patch early 9.8 critical 68.3% 2024-08-21
CVE-2017-12477 EXP It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its… Patch early 9.8 critical 68.2% 2017-08-07
CVE-2012-5357 EXP Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attacker… Patch early 9.8 critical 67.8% 2017-10-30
CVE-2016-6662 EXP Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17;… Patch early 9.8 critical 67.7% 2016-09-20
CVE-2020-0610 EXP A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target sy… Patch early 9.8 critical 67.6% 2020-01-14
CVE-2026-23744 EXP MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vul… Patch early 9.8 critical 67.5% 2026-01-16
CVE-2012-0694 EXP SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. Patch early 9.8 critical 67.3% 2019-10-29
CVE-2019-13101 EXP An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead… Patch early 9.8 critical 67.1% 2019-08-08
CVE-2019-6443 EXP An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_contro… Patch early 9.1 critical 66.9% 2019-01-16
CVE-2017-11394 EXP Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable install… Patch early 9.8 critical 66.8% 2017-08-03
CVE-2021-32172 EXP Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. Patch early 9.8 critical 66.4% 2021-10-07
CVE-2021-37425 EXP Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobil… Patch early 9.1 critical 66.3% 2021-08-10
CVE-2012-2926 EXP Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, a… Patch early 9.1 critical 66.3% 2012-05-22
CVE-2017-6360 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. Patch early 9.8 critical 66.1% 2017-03-23
CVE-2025-55315 EXP Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security fe… Patch early 9.9 critical 65.9% 2025-10-14
CVE-2019-10123 EXP SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker t… Patch early 9.8 critical 65.9% 2019-05-31
CVE-2017-14147 EXP An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its f… Patch early 9.8 critical 65.6% 2017-09-07
CVE-2016-10175 EXP The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user… Patch early 9.8 critical 65% 2017-01-30
CVE-2020-7115 EXP The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker coul… Patch early 9.8 critical 64.6% 2020-06-03
CVE-2018-6328 EXP It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unaut… Patch early 9.8 critical 64.4% 2018-03-14
CVE-2016-2296 EXP Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attack… Patch early 9.4 critical 64.3% 2016-05-14
CVE-2018-7297 EXP Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to obtain read/write access a… Patch early 9.8 critical 64.3% 2018-02-22
CVE-2017-9417 EXP Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. Patch early 9.8 critical 64% 2017-06-04
CVE-2017-11165 EXP dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /service… Patch early 9.8 critical 63.9% 2017-07-12
CVE-2018-16283 EXP The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. Patch early 9.8 critical 63.1% 2018-09-24
CVE-2012-0911 EXP TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1)… Patch early 9.8 critical 63% 2012-07-12
CVE-2026-0740 EXP The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Con… Patch early 9.8 critical 62.9% 2026-04-07
CVE-2024-8522 EXP The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress… Patch early 10.0 critical 62.9% 2024-09-12
← previous page 29 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt