peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,935 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-29

398,935 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-24186 EXP A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to up… Patch early 10.0 critical 94.6% 2020-08-24
CVE-2016-5674 EXP __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 throu… Patch early 9.8 critical 94.6% 2016-08-31
CVE-2014-0515 EXP Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on… Patch early 10.0 high 94.6% 2014-04-29
CVE-2015-0235 EXP Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attac… Patch early 10.0 high 94.6% 2015-01-28
CVE-2010-3972 EXP Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Informati… Patch early 10.0 high 94.5% 2010-12-23
CVE-2015-7857 EXP SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5… Patch early 7.5 high 94.5% 2015-10-29
CVE-2009-0580 EXP Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enume… Patch early 4.3 medium 94.4% 2009-06-05
CVE-2021-46422 EXP Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authe… Patch early 9.8 critical 94.3% 2022-04-27
CVE-2018-3245 EXP Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch early 9.8 critical 94.3% 2018-10-17
CVE-2016-2004 EXP HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors rela… Patch early 9.8 critical 94.3% 2016-04-21
CVE-2023-30258 EXP Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP… Patch early 9.8 critical 94.3% 2023-06-23
CVE-2010-0425 EXP modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when runnin… Patch early 10.0 high 94.2% 2010-03-05
CVE-2010-3964 EXP Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document… Patch early 7.5 high 94.2% 2010-12-16
CVE-2016-1524 EXP Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary… Patch early 9.6 critical 94.1% 2016-02-13
CVE-2024-8856 EXP The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the… Patch early 9.8 critical 94% 2024-11-16
CVE-2020-17506 EXP Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injectio… Patch early 9.8 critical 94% 2020-08-12
CVE-2017-5753 EXP Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit… Patch early 5.6 medium 93.8% 2018-01-04
CVE-2018-1335 EXP From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the comm… Patch early 8.1 high 93.8% 2018-04-25
CVE-2020-8617 EXP Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successful… Patch early 7.5 high 93.4% 2020-05-19
CVE-2018-6892 EXP An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listeni… Patch early 9.8 critical 93.4% 2018-02-11
CVE-2019-7276 EXP Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. Patch early 9.8 critical 93.4% 2019-07-01
CVE-2016-3081 EXP Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execu… Patch early 8.1 high 93.4% 2016-04-26
CVE-2017-14492 EXP Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted… Patch early 9.8 critical 93.3% 2017-10-03
CVE-2005-1983 EXP Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to exe… Patch early 10.0 high 93% 2005-08-10
CVE-2016-4010 EXP Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialize… Patch early 9.8 critical 92.9% 2017-01-23
CVE-2019-15976 EXP Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Patch early 9.8 critical 92.8% 2020-01-06
CVE-2022-21907 EXP HTTP Protocol Stack Remote Code Execution Vulnerability Patch early 9.8 critical 92.8% 2022-01-11
CVE-2020-2096 EXP Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. Patch early 6.1 medium 92.8% 2020-01-15
CVE-2022-21371 EXP Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 1… Patch early 7.5 high 92.6% 2022-01-19
CVE-2019-8943 EXP WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an a… Patch early 6.5 medium 92.6% 2019-02-20
← previous page 62 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt