peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,534 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,566 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-30896 EXP InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access… Patch early 9.1 critical 5.4% 2024-11-21
CVE-2022-40347 EXP SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allow… Patch early 9.8 critical 5.3% 2023-02-17
CVE-2015-6970 EXP The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML… Patch early 9.8 critical 5.3% 2020-02-18
CVE-2022-2025 EXP an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param len… Patch early 9.8 critical 5.3% 2022-09-23
CVE-2016-2417 EXP media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initial… Patch early 9.8 critical 5.3% 2016-04-18
CVE-2017-14507 EXP Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via… Patch early 9.8 critical 5.3% 2017-09-29
CVE-2018-10969 EXP SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the i… Patch early 9.8 critical 5.3% 2018-06-17
CVE-2009-4581 EXP Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers… Patch early 9.8 critical 5.2% 2010-01-06
CVE-2021-40617 EXP An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. Patch early 9.8 critical 5.2% 2021-10-11
CVE-2018-18805 EXP Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. Patch early 9.8 critical 5.2% 2018-11-16
CVE-2007-0681 EXP profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, a… Patch early 9.8 critical 5.2% 2007-02-03
CVE-2019-16383 EXP MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attac… Patch early 9.4 critical 5.2% 2019-09-24
CVE-2021-37593 EXP PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the… Patch early 9.1 critical 5.2% 2021-07-30
CVE-2013-1744 EXP IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. Patch early 9.8 critical 5.1% 2020-01-25
CVE-2017-7402 EXP Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager… Patch early 9.8 critical 5% 2017-04-03
CVE-2009-3421 EXP login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrativ… Patch early 9.8 critical 5% 2009-09-25
CVE-2026-26980 EXP Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the datab… Patch early 9.4 critical 5% 2026-02-20
CVE-2017-8837 EXP Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1… Patch early 9.8 critical 4.9% 2017-06-05
CVE-2012-5699 EXP BabyGekko before 1.2.4 allows PHP file inclusion. Patch early 9.8 critical 4.9% 2020-01-23
CVE-2017-15962 EXP iStock Management System 1.0 allows Arbitrary File Upload via user/profile. Patch early 9.8 critical 4.9% 2017-10-29
CVE-2018-6410 EXP An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. Patch early 9.8 critical 4.9% 2018-05-26
CVE-2014-9612 EXP SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote… Patch early 9.8 critical 4.9% 2020-02-19
CVE-2018-5315 EXP The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. Patch early 9.8 critical 4.9% 2018-01-12
CVE-2012-5686 EXP ZPanel 10.0.1 has insufficient entropy for its password reset process. Patch early 9.8 critical 4.8% 2020-02-04
CVE-2005-0408 EXP CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass au… Patch early 9.8 critical 4.7% 2005-02-14
CVE-2021-43140 EXP SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. Patch early 9.8 critical 4.7% 2021-11-03
CVE-2016-9488 EXP ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker… Patch early 9.8 critical 4.7% 2018-06-05
CVE-2013-2739 EXP MiniDLNA has heap-based buffer overflow Patch early 9.8 critical 4.7% 2019-11-01
CVE-2021-42136 EXP A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute J… Patch early 9.0 critical 4.7% 2022-04-13
CVE-2016-7400 EXP Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter… Patch early 9.8 critical 4.7% 2017-02-07
← previous page 53 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt