peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,929 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

398,929 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-1535 EXP The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, a… Patch early 7.5 high 98.1% 2009-06-10
CVE-2019-1821 EXP A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al… Patch early 8.8 high 98.1% 2019-05-16
CVE-2007-0882 EXP Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequen… Patch early 10.0 high 98% 2007-02-12
CVE-2014-5445 EXP Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remot… Patch early 5.0 medium 98% 2014-12-04
CVE-2014-0112 EXP ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manip… Patch early 7.5 high 97.9% 2014-04-29
CVE-2018-1111 EXP DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration… Patch early 7.5 high 97.9% 2018-05-17
CVE-2023-6553 EXP The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-… Patch early 9.8 critical 97.8% 2023-12-15
CVE-2022-21661 EXP WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Qu… Patch early 8.0 high 97.8% 2022-01-06
CVE-2016-10045 EXP The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arb… Patch early 9.8 critical 97.7% 2016-12-30
CVE-2018-15745 EXP Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTP… Patch early 7.5 high 97.7% 2018-08-30
CVE-2019-16662 EXP An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php becau… Patch early 9.8 critical 97.7% 2019-10-28
CVE-2018-11784 EXP When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. r… Patch early 4.3 medium 97.7% 2018-10-04
CVE-2023-0315 EXP Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. Patch early 8.8 high 97.7% 2023-01-16
CVE-2019-18818 EXP strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions… Patch early 9.8 critical 97.6% 2019-11-07
CVE-2013-5211 EXP The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via f… Patch early 5.0 medium 97.5% 2014-01-02
CVE-2012-0392 EXP The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute ar… Patch early 6.8 medium 97.5% 2012-01-08
CVE-2021-3378 EXP FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then… Patch early 9.8 critical 97.5% 2021-02-01
CVE-2016-6601 EXP Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrar… Patch early 7.5 high 97.4% 2017-01-23
CVE-2019-0230 EXP Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Patch early 9.8 critical 97.4% 2020-09-14
CVE-2018-17456 EXP Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code… Patch early 9.8 critical 97.4% 2018-10-06
CVE-2017-3248 EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affecte… Patch early 9.8 critical 97.3% 2017-01-27
CVE-2018-9206 EXP Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 Patch early 9.8 critical 97.3% 2018-10-11
CVE-2016-8869 EXP The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers… Patch early 9.8 critical 97.3% 2016-11-04
CVE-2020-11455 EXP LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. Patch early 9.8 critical 97.2% 2020-04-01
CVE-2025-4123 EXP A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to r… Patch early 7.6 high 97% 2025-05-22
CVE-2022-0824 EXP Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. Patch early 8.8 high 97% 2022-03-02
CVE-2016-9299 EXP The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java objec… Patch early 9.8 critical 96.9% 2017-01-12
CVE-2021-44790 EXP A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd… Patch early 9.8 critical 96.8% 2021-12-20
CVE-2019-17662 EXP ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication i… Patch early 9.8 critical 96.8% 2019-10-16
CVE-2015-3306 EXP The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Patch early 10.0 high 96.8% 2015-05-18
← previous page 60 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt