peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,692 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,469 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-8641 EXP An out-of-bounds read was addressed with improved input validation. Patch early 9.8 critical 17% 2019-12-18
CVE-2019-11469 EXP Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user c… Patch early 9.8 critical 17% 2019-04-23
CVE-2017-1002008 EXP Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-membe… Patch early 9.8 critical 16.9% 2017-09-14
CVE-2014-2595 EXP Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obt… Patch early 9.8 critical 16.9% 2020-02-12
CVE-2014-0030 EXP The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Patch early 9.8 critical 16.9% 2017-10-10
CVE-2019-8197 EXP Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, an… Patch early 9.8 critical 16.8% 2019-10-17
CVE-2019-8042 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 16.8% 2019-08-20
CVE-2018-15691 EXP Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute a… Patch early 9.8 critical 16.8% 2018-08-30
CVE-2018-9843 EXP The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialize… Patch early 9.8 critical 16.7% 2018-04-12
CVE-2017-6182 EXP In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command… Patch early 9.8 critical 16.7% 2017-03-30
CVE-2020-15492 EXP An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP p… Patch early 9.8 critical 16.6% 2020-07-23
CVE-2017-6315 EXP Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. Patch early 9.8 critical 16.6% 2017-09-19
CVE-2017-8051 EXP Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of t… Patch early 9.8 critical 16.5% 2017-04-21
CVE-2018-13784 EXP PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php. Patch early 9.1 critical 16.5% 2018-07-09
CVE-2018-18761 EXP SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. Patch early 9.8 critical 16.5% 2018-11-16
CVE-2025-20125 EXP A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,… Patch early 9.1 critical 16.4% 2025-02-05
CVE-2017-11151 EXP A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wit… Patch early 9.8 critical 16.3% 2017-08-08
CVE-2018-14485 EXP BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. Patch early 9.8 critical 16.3% 2019-05-07
CVE-2012-6649 EXP WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. Patch early 9.8 critical 16.3% 2020-01-23
CVE-2020-11749 EXP Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tri… Patch early 9.0 critical 16.2% 2020-07-13
CVE-2013-2571 EXP Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request… Patch early 9.8 critical 16.2% 2020-01-28
CVE-2021-36711 EXP WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. Patch early 9.8 critical 16.1% 2022-07-16
CVE-2019-8375 EXP The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script… Patch early 9.8 critical 16.1% 2019-02-24
CVE-2013-7137 EXP The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting th… Patch early 9.8 critical 16.1% 2014-01-26
CVE-2005-2103 EXP Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly e… Patch early 9.8 critical 16.1% 2005-08-16
CVE-2015-8396 EXP Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDC… Patch early 10.0 critical 16% 2016-01-12
CVE-2019-8045 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 16% 2019-08-20
CVE-2017-12785 EXP The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a… Patch early 9.8 critical 16% 2017-08-22
CVE-2020-23935 EXP Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". Patch early 9.8 critical 15.9% 2020-08-20
CVE-2020-10230 EXP CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parame… Patch early 9.8 critical 15.8% 2020-03-16
← previous page 42 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt