peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,759 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,483 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-1002003 EXP Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://… Patch early 9.8 critical 12.3% 2017-09-14
CVE-1999-0066 EXP AnyForm CGI remote execution. Patch early 9.8 critical 12.3% 1995-07-31
CVE-2018-7264 EXP The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign error… Patch early 9.8 critical 12.3% 2018-02-28
CVE-2016-6599 EXP BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service co… Patch early 9.8 critical 12.3% 2018-01-30
CVE-2017-11153 EXP Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain ad… Patch early 9.8 critical 12.2% 2017-08-08
CVE-2016-1741 EXP The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or… Patch early 9.8 critical 12.2% 2016-03-24
CVE-2017-5358 EXP Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argu… Patch early 9.8 critical 12.1% 2017-03-15
CVE-1999-0006 EXP Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. Patch early 9.8 critical 12.1% 1998-07-14
CVE-2014-5289 EXP Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request. Patch early 9.8 critical 12% 2019-12-27
CVE-2014-8673 EXP Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPl… Patch early 9.8 critical 11.9% 2020-01-07
CVE-2021-33990 EXP Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue be… Patch early 9.8 critical 11.9% 2023-04-16
CVE-2017-17739 EXP The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an atta… Patch early 9.8 critical 11.9% 2017-12-18
CVE-2021-42325 EXP Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. Patch early 9.8 critical 11.8% 2021-10-12
CVE-2009-2168 EXP cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are… Patch early 9.8 critical 11.8% 2009-06-22
CVE-2014-7279 EXP The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority"… Patch early 9.8 critical 11.7% 2017-03-23
CVE-2019-17132 EXP vBulletin through 5.5.4 mishandles custom avatars. Patch early 9.8 critical 11.7% 2019-10-04
CVE-2017-6506 EXP In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. T… Patch early 9.8 critical 11.7% 2017-03-10
CVE-2017-3897 EXP A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security… Patch early 9.8 critical 11.7% 2017-09-01
CVE-2016-6566 EXP The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software ver… Patch early 9.8 critical 11.6% 2018-07-13
CVE-2018-18957 EXP An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c. Patch early 9.8 critical 11.6% 2018-11-05
CVE-2016-9683 EXP The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative i… Patch early 9.8 critical 11.6% 2017-02-22
CVE-2018-5724 EXP MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. Patch early 9.8 critical 11.5% 2018-01-16
CVE-2019-10709 EXP AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potenti… Patch early 9.8 critical 11.5% 2019-09-04
CVE-2022-38580 EXP Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). Patch early 9.8 critical 11.5% 2022-10-25
CVE-2017-2523 EXP An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. wa… Patch early 9.8 critical 11.5% 2017-05-22
CVE-2014-9148 EXP Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administr… Patch early 9.8 critical 11.4% 2017-10-16
CVE-2022-22831 EXP An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. Patch early 9.8 critical 11.4% 2022-02-06
CVE-2024-40422 EXP The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker ca… Patch early 9.1 critical 11.4% 2024-07-24
CVE-2017-9430 EXP Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified ot… Patch early 9.8 critical 11.3% 2017-06-05
CVE-2020-25762 EXP An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and… Patch early 9.1 critical 11.3% 2020-09-30
← previous page 46 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt