peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,603 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,458 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-12943 EXP D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path trav… Patch early 9.8 critical 39.2% 2017-08-18
CVE-2020-25494 EXP Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels paramete… Patch early 9.8 critical 39.2% 2020-12-18
CVE-2018-5262 EXP A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context… Patch early 9.8 critical 39.1% 2018-01-12
CVE-2018-17440 EXP An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has… Patch early 9.8 critical 38.5% 2018-10-08
CVE-2016-10034 EXP The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before… Patch early 9.8 critical 38.4% 2016-12-30
CVE-2021-3817 EXP wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Patch early 9.8 critical 38.4% 2021-12-09
CVE-2018-14009 EXP Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. Patch early 9.8 critical 38% 2018-07-12
CVE-2019-10945 EXP An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to ac… Patch early 9.8 critical 38% 2019-04-10
CVE-2014-5007 EXP Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Provid… Patch early 9.8 critical 37.3% 2020-01-17
CVE-2022-25359 EXP On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. Patch early 9.1 critical 37.3% 2022-02-26
CVE-2022-24629 EXP An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in… Patch early 9.8 critical 37.2% 2023-05-29
CVE-2016-3074 EXP Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentiall… Patch early 9.8 critical 37.2% 2016-04-26
CVE-2014-8686 EXP CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when t… Patch early 9.8 critical 37.2% 2017-09-19
CVE-2018-14064 EXP The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80. Patch early 9.8 critical 37.2% 2018-07-15
CVE-2015-8351 EXP PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote au… Patch early 9.0 critical 37% 2017-09-11
CVE-2015-6835 EXP The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow… Patch early 9.8 critical 37% 2016-05-16
CVE-2019-6814 EXP A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to conf… Patch early 9.8 critical 36.7% 2019-05-22
CVE-2017-16887 EXP The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized… Patch early 9.8 critical 36.6% 2018-01-12
CVE-2017-14322 EXP The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attacke… Patch early 9.8 critical 36.5% 2017-10-18
CVE-2021-46424 EXP Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system int… Patch early 9.1 critical 36.5% 2022-04-27
CVE-2018-6580 EXP Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request. Patch early 9.8 critical 36.3% 2018-02-02
CVE-2013-4976 EXP Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials Patch early 9.8 critical 36.1% 2019-12-27
CVE-2021-43936 EXP The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the p… Patch early 10.0 critical 35.8% 2021-12-06
CVE-2021-31251 EXP An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a… Patch early 9.8 critical 35.7% 2021-06-04
CVE-2022-0848 EXP OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. Patch early 9.8 critical 35.4% 2022-03-04
CVE-2020-24214 EXP An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP r… Patch early 9.8 critical 35.4% 2020-10-06
CVE-2017-8225 EXP On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentica… Patch early 9.8 critical 35.4% 2017-04-25
CVE-2020-35391 EXP Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request… Patch early 9.6 critical 35.2% 2021-01-01
CVE-2017-11282 EXP Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code exe… Patch early 9.8 critical 34.8% 2017-12-01
CVE-2016-9150 EXP Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1… Patch early 9.8 critical 34.8% 2016-11-19
← previous page 34 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt