peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,367 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

37,054 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-21891 A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A… In your normal cycle 9.1 critical 3% 2021-12-22
CVE-2021-23390 The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. In your normal cycle 9.8 critical 3% 2021-07-12
CVE-2020-14244 A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker re… In your normal cycle 9.8 critical 3% 2020-12-14
CVE-2019-15519 Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. In your normal cycle 9.8 critical 3% 2019-08-23
CVE-2015-9316 The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id… In your normal cycle 9.8 critical 3% 2019-08-14
CVE-2026-81467 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'… In your normal cycle 9.8 critical 3% 2026-09-10
CVE-2020-28172 A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in co… In your normal cycle 9.8 critical 3% 2021-03-31
CVE-2016-1925 Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1… In your normal cycle 9.8 critical 3% 2017-01-23
CVE-2017-1000081 Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. In your normal cycle 9.8 critical 3% 2017-07-17
CVE-2016-7405 The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks… In your normal cycle 9.8 critical 3% 2016-10-03
CVE-2022-20229 In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead… In your normal cycle 9.8 critical 3% 2022-07-13
CVE-2021-42114 Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks… In your normal cycle 9.0 critical 3% 2021-11-16
CVE-2022-37968 Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allo… In your normal cycle 10.0 critical 3% 2022-10-11
CVE-2026-18072 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Ha… In your normal cycle 9.8 critical 3% 2026-07-29
CVE-2011-1180 Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow rem… In your normal cycle 9.8 critical 3% 2013-06-08
CVE-2019-17042 An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser… In your normal cycle 9.8 critical 3% 2019-10-07
CVE-2017-5668 bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrar… In your normal cycle 9.8 critical 3% 2017-03-14
CVE-2021-42343 An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalC… In your normal cycle 9.8 critical 3% 2021-10-26
CVE-2026-6942 radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by byp… In your normal cycle 9.8 critical 3% 2026-04-23
CVE-2021-43905 Microsoft Office app Remote Code Execution Vulnerability In your normal cycle 9.6 critical 3% 2021-12-15
CVE-2017-14008 GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successfu… In your normal cycle 9.8 critical 3% 2018-03-20
CVE-2021-33806 The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObje… In your normal cycle 9.8 critical 3% 2021-06-03
CVE-2017-6869 A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user t… In your normal cycle 9.8 critical 3% 2017-08-08
CVE-2017-9944 A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of… In your normal cycle 9.8 critical 3% 2017-12-27
CVE-2018-5187 Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough e… In your normal cycle 9.8 critical 3% 2018-10-18
CVE-2017-12368 A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… In your normal cycle 9.6 critical 3% 2017-11-30
CVE-2017-12369 A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF… In your normal cycle 9.6 critical 3% 2017-11-30
CVE-2017-12370 A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… In your normal cycle 9.6 critical 3% 2017-11-30
CVE-2017-12371 A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… In your normal cycle 9.6 critical 3% 2017-11-30
CVE-2017-12372 A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording For… In your normal cycle 9.6 critical 3% 2017-11-30
← previous page 296 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt