peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,917 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

398,917 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-16040 EXP Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a craft… Patch early 6.5 medium 99.6% 2021-01-08
CVE-2014-0094 EXP The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is p… Patch early 5.0 medium 99.6% 2014-03-11
CVE-2024-6387 EXP A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals… Patch early 8.1 high 99.5% 2024-07-01
CVE-2017-1000028 EXP Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can b… Patch early 7.5 high 99.5% 2017-07-17
CVE-2013-0156 EXP active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not… Patch early 7.5 high 99.4% 2013-01-13
CVE-2023-32560 EXP An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… Patch early 9.8 critical 99.4% 2023-08-10
CVE-2025-1974 EXP A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… Patch early 9.8 critical 99.4% 2025-03-25
CVE-2021-34429 EXP For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of th… Patch early 5.3 medium 99.3% 2021-07-15
CVE-2017-12542 EXP A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. Patch early 10.0 critical 99.3% 2018-02-15
CVE-2023-23333 EXP There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… Patch early 9.8 critical 99.3% 2023-02-06
CVE-2025-29927 EXP Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… Patch early 9.1 critical 99.2% 2025-03-21
CVE-2020-11022 EXP In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation… Patch early 6.9 medium 99.2% 2020-04-29
CVE-2015-1538 EXP Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote… Patch early 10.0 high 99.1% 2015-10-01
CVE-2022-24637 EXP Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… Patch early 9.8 critical 99.1% 2022-03-18
CVE-2014-0114 EXP Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring common… Patch early 7.5 high 99% 2014-04-30
CVE-2020-9496 EXP XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 Patch early 6.1 medium 98.9% 2020-07-15
CVE-2011-3192 EXP The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of serv… Patch early 7.8 high 98.8% 2011-08-29
CVE-2020-7209 EXP LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. Patch early 9.8 critical 98.8% 2020-02-13
CVE-2018-19276 EXP OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… Patch early 9.8 critical 98.7% 2019-03-21
CVE-2018-15473 EXP OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet… Patch early 5.3 medium 98.6% 2018-08-17
CVE-2003-0352 EXP Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrar… Patch early 7.5 high 98.5% 2003-08-18
CVE-2019-5736 EXP runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain… Patch early 8.6 high 98.5% 2019-02-11
CVE-2009-1122 EXP The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attac… Patch early 7.5 high 98.4% 2009-06-10
CVE-2019-1003000 EXP A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/… Patch early 8.8 high 98.4% 2019-01-22
CVE-2018-12613 EXP An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vul… Patch early 8.8 high 98.4% 2018-06-21
CVE-2018-11409 EXP Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by… Patch early 5.3 medium 98.3% 2018-06-08
CVE-2015-8562 EXP Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP Us… Patch early 7.5 high 98.3% 2015-12-16
CVE-2020-15920 EXP There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… Patch early 9.8 critical 98.2% 2020-07-24
CVE-2012-3153 EXP Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attacke… Patch early 6.4 medium 98.2% 2012-10-16
CVE-2020-35847 EXP Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. Patch early 9.8 critical 98.2% 2020-12-30
← previous page 59 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt