peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,648 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,465 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2014-8322 EXP Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code… Patch early 9.8 critical 23.9% 2020-01-31
CVE-2024-27747 EXP File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Imag… Patch early 9.8 critical 23.6% 2024-03-01
CVE-2018-6396 EXP SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or… Patch early 9.8 critical 23.6% 2018-02-17
CVE-2018-5997 EXP An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it… Patch early 9.8 critical 23.5% 2018-01-25
CVE-2023-37629 EXP Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig… Patch early 9.8 critical 23.3% 2023-07-12
CVE-2016-9682 EXP The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrati… Patch early 9.8 critical 23.3% 2017-02-22
CVE-2005-3120 EXP Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article… Patch early 9.8 critical 23.3% 2005-10-17
CVE-2013-1360 EXP An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Ma… Patch early 9.8 critical 23.2% 2020-02-11
CVE-2019-7265 EXP Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). Patch early 9.8 critical 23.1% 2019-07-02
CVE-2021-44567 EXP An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. Patch early 9.8 critical 23.1% 2022-02-24
CVE-2017-15367 EXP Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depe… Patch early 9.8 critical 23.1% 2018-03-07
CVE-2023-48292 EXP The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site… Patch early 9.6 critical 22.9% 2023-11-20
CVE-2021-44596 EXP Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can commu… Patch early 9.8 critical 22.9% 2022-04-29
CVE-2019-8196 EXP Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… Patch early 9.8 critical 22.9% 2019-10-17
CVE-2019-8195 EXP Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… Patch early 9.8 critical 22.9% 2019-10-17
CVE-2015-8617 EXP Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute… Patch early 9.8 critical 22.8% 2016-01-19
CVE-2018-6871 EXP LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.M… Patch early 9.8 critical 22.8% 2018-02-09
CVE-2016-9565 EXP MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing… Patch early 9.8 critical 22.7% 2016-12-15
CVE-2019-17124 EXP Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. Patch early 9.8 critical 22.5% 2019-10-09
CVE-2018-19126 EXP PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload. Patch early 9.8 critical 22.5% 2018-11-09
CVE-2018-12596 EXP Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via… Patch early 9.8 critical 22.4% 2018-10-10
CVE-2016-3987 EXP The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefa… Patch early 9.8 critical 22.3% 2016-04-12
CVE-2017-3077 EXP Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitatio… Patch early 9.8 critical 22.3% 2017-06-20
CVE-2003-0899 EXP Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '… Patch early 9.8 critical 22.2% 2003-11-03
CVE-2019-8016 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 22% 2019-08-20
CVE-2017-3623 EXP Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see n… Patch early 10.0 critical 22% 2017-04-24
CVE-2018-8057 EXP A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/ad… Patch early 9.8 critical 21.8% 2018-03-11
CVE-2017-6542 EXP The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent proto… Patch early 9.8 critical 21.8% 2017-03-27
CVE-2018-20525 EXP Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. Patch early 9.1 critical 21.6% 2019-03-21
CVE-2017-3195 EXP Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnera… Patch early 9.8 critical 21.4% 2017-12-16
← previous page 38 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt