peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,143 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-09-30

36,608 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2022-40300 Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 h… Patch early 9.8 critical 99.1% 2022-09-16
CVE-2022-39986 A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter i… Patch early 9.8 critical 99.1% 2023-08-01
CVE-2021-21978 VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorizat… Patch early 9.8 critical 99% 2021-03-03
CVE-2023-38646 Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the serve… Patch early 9.8 critical 98.7% 2023-07-21
CVE-2024-29895 Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthen… Patch early 10.0 critical 98.5% 2024-05-14
CVE-2022-43781 There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control the… Patch early 9.8 critical 98.1% 2022-11-17
CVE-2022-2024 OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. Patch early 9.8 critical 97.8% 2023-02-25
CVE-2021-26295 Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFB… Patch early 9.8 critical 97.8% 2021-03-22
CVE-2016-10108 Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg p… Patch early 9.8 critical 97.8% 2017-01-03
CVE-2022-28219 Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. Patch early 9.8 critical 97.2% 2022-04-05
CVE-2021-37344 Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS… Patch early 9.8 critical 96.8% 2021-08-13
CVE-2023-35708 In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection… Patch early 9.8 critical 96.7% 2023-06-16
CVE-2020-28188 Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/ma… Patch early 9.8 critical 96.6% 2020-12-24
CVE-2023-51467 The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code Patch early 9.8 critical 96% 2023-12-26
CVE-2023-21554 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Patch early 9.8 critical 95.5% 2023-04-11
CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Use… Patch early 9.8 critical 95.4% 2023-12-05
CVE-2023-36934 In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0… Patch early 9.1 critical 95.2% 2023-07-05
CVE-2022-0342 An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware ver… Patch early 9.8 critical 95.1% 2022-03-28
CVE-2019-10173 It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has… Patch early 9.8 critical 95% 2019-07-23
CVE-2020-13167 Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a c… Patch early 9.8 critical 95% 2020-05-19
CVE-2024-9264 The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficien… Patch early 9.9 critical 94.9% 2024-10-18
CVE-2020-6754 dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $T… Patch early 9.8 critical 94.8% 2020-02-05
CVE-2023-24941 Windows Network File System Remote Code Execution Vulnerability Patch early 9.8 critical 94.7% 2023-05-09
CVE-2024-8517 SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operat… Patch early 9.8 critical 94.6% 2024-09-06
CVE-2020-14092 The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. Patch early 9.8 critical 94.5% 2020-07-02
CVE-2023-41892 Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befor… Patch early 10.0 critical 94.2% 2023-09-13
CVE-2024-27956 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This i… Patch early 9.9 critical 94.1% 2024-03-21
CVE-2021-31474 This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Aut… Patch early 9.8 critical 93.9% 2021-05-21
CVE-2024-21650 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code executio… Patch early 10.0 critical 93.5% 2024-01-08
CVE-2021-27850 A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,… Patch early 9.8 critical 93.5% 2021-04-15
← previous page 65 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt