peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,806 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

36,488 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17759 EXP Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the confi… Patch early 9.8 critical 11.3% 2017-12-19
CVE-2018-11511 EXP The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' o… Patch early 9.8 critical 11.3% 2018-08-16
CVE-2000-0944 EXP CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allow… Patch early 9.8 critical 11.3% 2000-12-19
CVE-2017-1002001 EXP Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedio… Patch early 9.8 critical 11.1% 2017-09-14
CVE-2015-4667 EXP Multiple hardcoded credentials in Xsuite 2.x. Patch early 9.8 critical 11.1% 2017-09-25
CVE-2022-34668 EXP NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged networ… Patch early 9.8 critical 10.9% 2022-08-29
CVE-2022-41544 EXP GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. Patch early 9.8 critical 10.8% 2022-10-18
CVE-2020-15160 EXP PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with loca… Patch early 9.8 critical 10.8% 2020-09-24
CVE-1999-0426 EXP The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. Patch early 9.8 critical 10.8% 1999-03-01
CVE-2019-16702 EXP Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI… Patch early 9.8 critical 10.7% 2019-09-23
CVE-2018-20218 EXP An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without… Patch early 9.8 critical 10.7% 2019-03-21
CVE-2025-46811 EXP A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any c… Patch early 9.8 critical 10.7% 2025-07-30
CVE-2015-7251 EXP ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to o… Patch early 9.8 critical 10.7% 2015-12-30
CVE-2020-6756 EXP languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the la… Patch early 9.8 critical 10.6% 2020-01-09
CVE-2018-12908 EXP Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct re… Patch early 9.8 critical 10.5% 2018-06-27
CVE-2018-14328 EXP Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct re… Patch early 9.8 critical 10.5% 2018-07-23
CVE-2019-11703 EXP A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting… Patch early 9.8 critical 10.5% 2019-07-23
CVE-2019-11704 EXP A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages,… Patch early 9.8 critical 10.5% 2019-07-23
CVE-2023-29809 EXP SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script… Patch early 9.8 critical 10.5% 2023-05-12
CVE-2019-12765 EXP An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. Patch early 9.8 critical 10.5% 2019-06-11
CVE-2017-9811 EXP The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (… Patch early 9.8 critical 10.5% 2017-07-17
CVE-2014-5081 EXP sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass Patch early 9.8 critical 10.5% 2020-01-10
CVE-2025-4524 EXP The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, an… Patch early 9.8 critical 10.4% 2025-05-21
CVE-2019-16692 EXP phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. Patch early 9.8 critical 10.3% 2019-09-22
CVE-2019-8661 EXP A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to ca… Patch early 9.8 critical 10.3% 2019-12-18
CVE-2018-6228 EXP A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload an… Patch early 9.8 critical 10.2% 2018-03-15
CVE-2018-6229 EXP A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upl… Patch early 9.8 critical 10.2% 2018-03-15
CVE-2013-6236 EXP IZON IP 2.0.2: hard-coded password vulnerability Patch early 9.8 critical 10.2% 2020-02-12
CVE-2015-7247 EXP D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and… Patch early 9.8 critical 10.2% 2017-04-24
CVE-2018-10618 EXP Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker… Patch early 9.8 critical 10.1% 2018-08-01
← previous page 47 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt