peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-26

398,436 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-11978 KEV EXP An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DA… Patch first 8.8 high 99.2% 2020-07-17
CVE-2022-36804 KEV EXP Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from vers… Patch first 8.8 high 99.2% 2022-08-25
CVE-2021-44529 KEV EXP A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited… Patch first 9.8 critical 99.1% 2021-12-08
CVE-2020-10199 KEV EXP Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). Patch first 8.8 high 99.1% 2020-04-01
CVE-2019-16278 KEV EXP Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTT… Patch first 9.8 critical 99% 2019-10-14
CVE-2020-0618 KEV EXP A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL… Patch first 8.8 high 99% 2020-02-11
CVE-2026-24061 KEV EXP telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. Patch first 9.8 critical 99% 2026-01-21
CVE-2020-7247 KEV EXP smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as… Patch first 9.8 critical 99% 2020-01-29
CVE-2019-3929 KEV EXP The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befor… Patch first 9.8 critical 99% 2019-04-30
CVE-2017-3881 KEV EXP A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,… Patch first 9.8 critical 99% 2017-03-17
CVE-2017-9791 KEV EXP The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Acti… Patch first 9.8 critical 98.9% 2017-07-10
CVE-2025-49113 KEV EXP Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is no… Patch first 9.9 critical 98.9% 2025-06-02
CVE-2013-2465 KEV EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0… Patch first 9.8 critical 98.8% 2013-06-18
CVE-2012-3152 KEV EXP Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… Patch first 9.1 critical 98.8% 2012-10-16
CVE-2008-4250 KEV EXP The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remo… Patch first 9.8 critical 98.8% 2008-10-23
CVE-2019-17558 KEV EXP Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provid… Patch first 7.5 high 98.6% 2019-12-30
CVE-2019-11539 KEV EXP In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Po… Patch first 7.2 high 98.5% 2019-04-26
CVE-2012-4681 KEV EXP Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute ar… Patch first 9.8 critical 98.5% 2012-08-28
CVE-2026-41940 KEV EXP cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to g… Patch first 9.8 critical 98.5% 2026-04-29
CVE-2016-3088 KEV EXP The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT foll… Patch first 9.8 critical 98.5% 2016-06-01
CVE-2024-20767 KEV EXP ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system re… Patch first 7.4 high 98.5% 2024-03-18
CVE-2019-5418 KEV EXP There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers… Patch first 7.5 high 98.5% 2019-03-27
CVE-2008-2992 KEV EXP Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls… Patch first 7.8 high 98.5% 2008-11-04
CVE-2017-15944 KEV EXP Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary… Patch first 9.8 critical 98.3% 2017-12-11
CVE-2016-1555 KEV EXP (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802T… Patch first 9.8 critical 98.3% 2017-04-21
CVE-2022-22947 KEV EXP In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoin… Patch first 10.0 critical 98.3% 2022-03-03
CVE-2012-0507 KEV EXP Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 U… Patch first 9.8 critical 98.1% 2012-06-07
CVE-2022-29303 KEV EXP SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. Patch first 9.8 critical 98% 2022-05-12
CVE-2022-22536 KEV EXP SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulner… Patch first 10.0 critical 97.9% 2022-02-09
CVE-2020-11738 KEV EXP The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parame… Patch first 7.5 high 97.8% 2020-04-13
← previous page 5 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt