peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,612 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,461 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-10718 EXP Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary c… Patch early 10.0 critical 30.2% 2018-05-03
CVE-2024-22836 EXP An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to… Patch early 9.8 critical 30% 2024-02-08
CVE-2017-0561 EXP A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of th… Patch early 9.8 critical 29.8% 2017-04-07
CVE-2026-3891 EXP The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation… Patch early 9.8 critical 29.7% 2026-03-13
CVE-2017-5173 EXP An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An im… Patch early 9.8 critical 29.6% 2017-05-19
CVE-2012-6664 EXP Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write… Patch early 9.1 critical 29.5% 2024-06-21
CVE-2020-14011 EXP Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is… Patch early 9.8 critical 29.5% 2020-06-15
CVE-2017-11517 EXP Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary c… Patch early 9.8 critical 29.1% 2017-07-21
CVE-2019-7274 EXP Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. Patch early 9.8 critical 29% 2019-07-01
CVE-2010-0211 EXP The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows rem… Patch early 9.8 critical 28.5% 2010-07-28
CVE-2022-31161 EXP Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via th… Patch early 10.0 critical 28.4% 2022-07-15
CVE-2018-12327 EXP Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges vi… Patch early 9.8 critical 28% 2018-06-20
CVE-2019-8982 EXP com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to discl… Patch early 9.6 critical 28% 2019-02-21
CVE-2018-9032 EXP An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version… Patch early 9.8 critical 27.7% 2018-03-27
CVE-2019-25024 EXP OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service paramete… Patch early 9.8 critical 27.6% 2021-02-19
CVE-2017-1002000 EXP Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/im… Patch early 9.8 critical 27.4% 2017-09-14
CVE-2017-16562 EXP The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and… Patch early 9.8 critical 27.4% 2017-11-10
CVE-2018-7750 EXP transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.… Patch early 9.8 critical 27.1% 2018-03-13
CVE-2016-4203 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 26.9% 2016-07-13
CVE-2020-35314 EXP A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to uploa… Patch early 9.8 critical 26.9% 2021-04-20
CVE-2007-5775 EXP Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029… Patch early 9.8 critical 26.9% 2007-11-01
CVE-2017-6359 EXP QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors. Patch early 9.8 critical 26.9% 2017-03-23
CVE-2020-11819 EXP In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. Patch early 9.8 critical 26.8% 2020-04-16
CVE-2013-2570 EXP A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the bi… Patch early 9.8 critical 26.6% 2020-01-29
CVE-2013-6225 EXP LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability Patch early 9.8 critical 26.6% 2020-01-13
CVE-2018-8733 EXP Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to ma… Patch early 9.8 critical 26.6% 2018-04-18
CVE-2022-24627 EXP An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the… Patch early 9.8 critical 26.4% 2023-05-29
CVE-2019-19576 EXP class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar… Patch early 9.8 critical 26.4% 2019-12-04
CVE-2020-20277 EXP There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to impro… Patch early 9.8 critical 26.2% 2020-12-18
CVE-2018-17057 EXP An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. Patch early 9.8 critical 26.2% 2018-09-14
← previous page 36 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt