peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,596 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,458 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-58434 EXP Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… Patch early 9.8 critical 49.9% 2025-09-12
CVE-2016-6909 EXP Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 a… Patch early 9.8 critical 49.9% 2016-08-24
CVE-2022-37109 EXP patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the passwo… Patch early 9.8 critical 49.5% 2022-11-14
CVE-2018-13862 EXP Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication… Patch early 9.8 critical 49.3% 2018-07-17
CVE-2023-3710 EXP Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 v… Patch early 9.9 critical 49% 2023-09-12
CVE-2018-9126 EXP The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credent… Patch early 9.8 critical 48.9% 2018-04-04
CVE-2013-2568 EXP A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a re… Patch early 9.8 critical 48.5% 2020-01-29
CVE-2017-9232 EXP Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege… Patch early 9.8 critical 48.5% 2017-05-28
CVE-2020-5377 EXP Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote atta… Patch early 9.1 critical 48.3% 2020-07-28
CVE-2018-8096 EXP Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","V… Patch early 9.8 critical 48.2% 2018-03-14
CVE-2021-27964 EXP SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFil… Patch early 9.8 critical 47.5% 2021-03-05
CVE-2018-5767 EXP An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with… Patch early 9.8 critical 47.4% 2018-02-15
CVE-2015-6834 EXP Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary… Patch early 9.8 critical 46.8% 2016-05-16
CVE-2019-9879 EXP The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are all… Patch early 9.8 critical 46.6% 2019-06-10
CVE-2025-29306 EXP An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. Patch early 9.8 critical 46.6% 2025-03-27
CVE-2023-30145 EXP Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. Patch early 9.8 critical 46.1% 2023-05-26
CVE-2015-9323 EXP The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. Patch early 9.8 critical 46.1% 2019-08-16
CVE-2022-35411 EXP rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, althou… Patch early 9.8 critical 45.7% 2022-07-08
CVE-2019-6444 EXP An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data… Patch early 9.1 critical 45.7% 2019-01-16
CVE-2016-1606 EXP Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code v… Patch early 9.8 critical 45.6% 2016-07-03
CVE-2021-29003 EXP Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as… Patch early 9.8 critical 45.4% 2021-04-13
CVE-2018-15839 EXP D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. Patch early 9.8 critical 45.3% 2018-08-28
CVE-2020-35313 EXP A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attack… Patch early 9.8 critical 45.2% 2021-04-20
CVE-2024-48760 EXP An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlc… Patch early 9.8 critical 45.1% 2025-01-14
CVE-2024-42640 EXP angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allow… Patch early 9.8 critical 45.1% 2024-10-11
CVE-2022-0332 EXP A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching u… Patch early 9.8 critical 44.9% 2022-01-25
CVE-2019-8341 EXP An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" paramet… Patch early 9.8 critical 44.8% 2019-02-15
CVE-2018-11510 EXP The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by… Patch early 9.8 critical 44.3% 2018-06-28
CVE-2020-36847 EXP The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which… Patch early 9.8 critical 44.2% 2025-07-12
CVE-2020-13693 EXP An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. Patch early 9.8 critical 43.9% 2020-05-29
← previous page 32 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt