peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,457 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6622 EXP A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authenticati… Patch early 9.8 critical 62.2% 2017-05-18
CVE-2022-24223 EXP AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. Patch early 9.8 critical 62% 2022-02-01
CVE-2016-1209 EXP The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in… Patch early 9.8 critical 61.6% 2016-05-14
CVE-2017-8835 EXP SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7… Patch early 9.8 critical 61.6% 2017-06-05
CVE-2018-16836 EXP Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbit… Patch early 9.8 critical 61.4% 2018-09-11
CVE-2018-6329 EXP It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote at… Patch early 9.8 critical 61.2% 2018-03-14
CVE-2017-5941 EXP An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to ach… Patch early 9.8 critical 61% 2017-02-09
CVE-2019-7304 EXP Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issu… Patch early 9.8 critical 60.8% 2019-04-23
CVE-2018-7756 EXP RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remot… Patch early 9.8 critical 60.7% 2018-03-15
CVE-2017-15222 EXP Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. Patch early 9.8 critical 60.3% 2017-10-24
CVE-2021-24499 EXP The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks,… Patch early 9.8 critical 60.1% 2021-08-09
CVE-2012-2576 EXP SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWi… Patch early 9.8 critical 59.4% 2017-12-20
CVE-2019-5485 EXP NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository na… Patch early 10.0 critical 58.8% 2019-09-13
CVE-2019-14931 EXP An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote… Patch early 9.8 critical 58.1% 2019-10-28
CVE-2008-0081 EXP Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to… Patch early 9.8 critical 57.9% 2008-01-16
CVE-2018-7314 EXP SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. Patch early 9.8 critical 57.8% 2018-02-22
CVE-2018-6605 EXP SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHov… Patch early 9.8 critical 57.7% 2018-02-05
CVE-2016-8582 EXP A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve da… Patch early 9.8 critical 57.4% 2016-10-28
CVE-2017-6526 EXP An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected admi… Patch early 9.8 critical 57.4% 2017-03-09
CVE-2020-15922 EXP There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pr… Patch early 9.8 critical 57.3% 2020-07-24
CVE-2019-5029 EXP An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands s… Patch early 9.8 critical 57.2% 2019-11-13
CVE-2019-5434 EXP An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in t… Patch early 9.8 critical 57% 2019-05-06
CVE-2021-45428 EXP TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HT… Patch early 9.8 critical 56.9% 2022-01-03
CVE-2017-6361 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. Patch early 9.8 critical 56.8% 2017-03-23
CVE-2018-12634 EXP CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html… Patch early 9.8 critical 56.4% 2018-06-22
CVE-2018-17173 EXP LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. Patch early 9.8 critical 56.2% 2018-09-21
CVE-2016-3078 EXP Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffe… Patch early 9.8 critical 56.1% 2016-08-07
CVE-2011-4908 EXP TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. Patch early 9.8 critical 55.8% 2020-02-12
CVE-2019-8387 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. Patch early 9.8 critical 55.7% 2019-05-08
CVE-2014-7236 EXP Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenablep… Patch early 9.1 critical 55.6% 2020-02-17
← previous page 30 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt