peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

205,507 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-0049 EXP Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read ar… Patch early 5.0 medium 95.4% 2011-02-04
CVE-2021-22911 EXP A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulti… Patch early 9.8 critical 95.2% 2021-05-27
CVE-2008-1447 EXP The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, a… Patch early 6.8 medium 95.2% 2008-07-08
CVE-2006-3918 EXP http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, an… Patch early 4.3 medium 95.1% 2006-07-28
CVE-2002-0840 EXP Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off"… Patch early 6.8 medium 95.1% 2002-10-11
CVE-2024-0204 EXP Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. Patch early 9.8 critical 95.1% 2024-01-22
CVE-2015-5531 EXP Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sna… Patch early 5.0 medium 94.8% 2015-08-17
CVE-2013-2248 EXP Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and condu… Patch early 5.8 medium 94.7% 2013-07-20
CVE-2020-24186 EXP A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to up… Patch early 10.0 critical 94.6% 2020-08-24
CVE-2016-5674 EXP __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 throu… Patch early 9.8 critical 94.6% 2016-08-31
CVE-2009-0580 EXP Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… Patch early 4.3 medium 94.4% 2009-06-05
CVE-2021-46422 EXP Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authe… Patch early 9.8 critical 94.3% 2022-04-27
CVE-2018-3245 EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch early 9.8 critical 94.3% 2018-10-17
CVE-2016-2004 EXP HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rela… Patch early 9.8 critical 94.3% 2016-04-21
CVE-2023-30258 EXP Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP… Patch early 9.8 critical 94.3% 2023-06-23
CVE-2016-1524 EXP Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary… Patch early 9.6 critical 94.1% 2016-02-13
CVE-2024-8856 EXP The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the… Patch early 9.8 critical 94% 2024-11-16
CVE-2020-17506 EXP Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injectio… Patch early 9.8 critical 94% 2020-08-12
CVE-2017-5753 EXP Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… Patch early 5.6 medium 93.8% 2018-01-04
CVE-2018-6892 EXP An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listeni… Patch early 9.8 critical 93.4% 2018-02-11
CVE-2019-7276 EXP Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. Patch early 9.8 critical 93.4% 2019-07-01
CVE-2017-14492 EXP Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted… Patch early 9.8 critical 93.3% 2017-10-03
CVE-2016-4010 EXP Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialize… Patch early 9.8 critical 92.9% 2017-01-23
CVE-2019-15976 EXP Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Patch early 9.8 critical 92.8% 2020-01-06
CVE-2022-21907 EXP HTTP Protocol Stack Remote Code Execution Vulnerability Patch early 9.8 critical 92.8% 2022-01-11
CVE-2020-2096 EXP Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. Patch early 6.1 medium 92.8% 2020-01-15
CVE-2019-8943 EXP WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… Patch early 6.5 medium 92.6% 2019-02-20
CVE-2023-23488 EXP The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of t… Patch early 9.8 critical 92.5% 2023-01-20
CVE-2016-0492 EXP Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows rem… Patch early 6.4 medium 92.1% 2016-01-21
CVE-2010-1870 EXP The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly oth… Patch early 5.0 medium 92% 2010-08-17
← previous page 30 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt