peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,587 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,458 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-43857 EXP Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched… Patch early 9.8 critical 55.3% 2021-12-27
CVE-2016-6602 EXP ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartex… Patch early 9.8 critical 55.1% 2017-01-23
CVE-2022-36267 EXP In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can… Patch early 9.8 critical 54.5% 2022-08-08
CVE-2022-24562 EXP In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the enti… Patch early 9.8 critical 54.5% 2022-06-16
CVE-2024-11972 EXP The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install an… Patch early 9.8 critical 54.5% 2024-12-31
CVE-2025-49132 EXP Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespac… Patch early 10.0 critical 54.5% 2025-06-20
CVE-2021-36356 EXP KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary e… Patch early 9.8 critical 54.4% 2021-08-31
CVE-2018-5347 EXP Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because… Patch early 9.8 critical 54.2% 2018-01-12
CVE-2025-27007 EXP Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a… Patch early 9.8 critical 53.9% 2025-05-01
CVE-2018-8734 EXP SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL comm… Patch early 9.8 critical 53.8% 2018-04-18
CVE-2019-6441 EXP An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The passw… Patch early 9.8 critical 53.6% 2019-03-21
CVE-2017-17932 EXP A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute ar… Patch early 9.8 critical 53.6% 2017-12-28
CVE-2023-27823 EXP An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. Patch early 9.8 critical 53.6% 2023-05-12
CVE-2019-19844 EXP Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing… Patch early 9.8 critical 53.6% 2019-12-18
CVE-2023-29689 EXP PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vuln… Patch early 9.8 critical 53.5% 2023-08-04
CVE-2018-7739 EXP antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demons… Patch early 9.8 critical 53.2% 2018-03-07
CVE-2019-9760 EXP FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends craf… Patch early 9.8 critical 53.1% 2019-03-14
CVE-2018-8021 EXP Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. N… Patch early 9.8 critical 52.8% 2018-11-07
CVE-2022-31126 EXP Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauth… Patch early 10.0 critical 52.6% 2022-07-06
CVE-2018-11686 EXP The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. Patch early 9.8 critical 52.5% 2019-07-03
CVE-2017-5174 EXP An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has bee… Patch early 9.8 critical 52.3% 2017-05-19
CVE-2016-2345 EXP Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbit… Patch early 9.8 critical 51.2% 2016-03-17
CVE-2018-1217 EXP Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affec… Patch early 9.8 critical 50.9% 2018-04-09
CVE-2021-34646 EXP Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_ve… Patch early 9.8 critical 50.9% 2021-08-30
CVE-2019-12518 EXP Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. Patch early 9.8 critical 50.7% 2019-12-02
CVE-2024-25735 EXP An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config… Patch early 9.1 critical 50.6% 2024-03-27
CVE-2018-19524 EXP An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 dev… Patch early 9.8 critical 50.5% 2019-03-21
CVE-2017-16720 EXP A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the t… Patch early 9.8 critical 50.3% 2018-01-05
CVE-2017-6465 EXP Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; howeve… Patch early 9.8 critical 50.3% 2017-03-10
CVE-2012-3363 EXP Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attac… Patch early 9.1 critical 50.2% 2013-02-13
← previous page 31 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt