peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,373 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

37,054 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-24171 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vul… In your normal cycle 9.8 critical 3% 2022-02-04
CVE-2022-26994 Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in t… In your normal cycle 9.8 critical 3% 2022-03-15
CVE-2022-27413 Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. In your normal cycle 9.8 critical 3% 2022-05-03
CVE-2014-9921 Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier a… In your normal cycle 9.8 critical 3% 2017-03-14
CVE-2018-4056 An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a… In your normal cycle 9.8 critical 3% 2019-02-05
CVE-2014-8708 Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature. In your normal cycle 9.8 critical 3% 2017-03-17
CVE-2022-31311 An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request. In your normal cycle 9.8 critical 3% 2022-06-14
CVE-2026-48313 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln… In your normal cycle 9.3 critical 3% 2026-06-30
CVE-2015-8880 Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error. In your normal cycle 9.8 critical 3% 2016-05-22
CVE-2016-5254 Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attacke… In your normal cycle 9.8 critical 3% 2016-08-05
CVE-2019-14678 SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local F… In your normal cycle 10.0 critical 3% 2019-11-14
CVE-2018-12242 The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow… In your normal cycle 9.8 critical 3% 2018-09-19
CVE-2018-0545 LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. In your normal cycle 9.8 critical 3% 2018-04-09
CVE-2016-6667 NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to exe… In your normal cycle 9.8 critical 3% 2017-02-07
CVE-2017-10832 "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. In your normal cycle 9.8 critical 3% 2017-08-29
CVE-2016-5336 VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors. In your normal cycle 9.8 critical 2.9% 2016-08-31
CVE-2020-24202 File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote… In your normal cycle 9.8 critical 2.9% 2020-08-27
CVE-2013-7087 ClamAV before 0.97.7 has WWPack corrupt heap memory In your normal cycle 9.8 critical 2.9% 2019-11-15
CVE-2017-12928 A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in vi… In your normal cycle 9.8 critical 2.9% 2017-09-21
CVE-2020-11851 Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remote… In your normal cycle 9.8 critical 2.9% 2020-11-17
CVE-2026-10580 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all ver… In your normal cycle 9.8 critical 2.9% 2026-06-05
CVE-2016-10230 A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: Q… In your normal cycle 9.8 critical 2.9% 2018-04-04
CVE-2019-3412 All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify p… In your normal cycle 9.8 critical 2.9% 2019-06-11
CVE-2026-86148 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the compo… In your normal cycle 9.1 critical 2.9% 2026-09-05
CVE-2026-86149 A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulatio… In your normal cycle 9.1 critical 2.9% 2026-09-05
CVE-2026-86151 A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Netw… In your normal cycle 9.1 critical 2.9% 2026-09-06
CVE-2018-9109 Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attac… In your normal cycle 9.1 critical 2.9% 2018-03-28
CVE-2017-16845 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. In your normal cycle 10.0 critical 2.9% 2017-11-17
CVE-2020-8129 An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code. In your normal cycle 9.8 critical 2.9% 2020-02-14
CVE-2021-27705 Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"… In your normal cycle 9.8 critical 2.9% 2021-04-14
← previous page 299 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt