peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,152 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,608 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-9047 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.p… Patch early 9.8 critical 93.3% 2024-10-12
CVE-2020-35846 Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. Patch early 9.8 critical 93.3% 2020-12-30
CVE-2016-7552 On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated att… Patch early 9.8 critical 93.2% 2017-04-12
CVE-2024-45507 Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach… Patch early 9.8 critical 93.2% 2024-09-04
CVE-2021-27905 The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter t… Patch early 9.8 critical 93.1% 2021-04-13
CVE-2024-2389 In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can… Patch early 10.0 critical 93% 2024-04-02
CVE-2021-37539 Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. Patch early 9.8 critical 92.9% 2021-09-27
CVE-2024-45216 Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authent… Patch early 9.8 critical 92.7% 2024-10-16
CVE-2016-7547 A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interfa… Patch early 9.8 critical 92.7% 2017-04-12
CVE-2022-40022 Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. Patch early 9.8 critical 92.5% 2023-02-13
CVE-2021-25282 An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. Patch early 9.1 critical 92.4% 2021-02-27
CVE-2022-29535 Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. Patch early 9.8 critical 91.8% 2022-05-05
CVE-2023-37462 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.… Patch early 9.9 critical 91.6% 2023-07-14
CVE-2016-3510 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers… Patch early 9.8 critical 91.4% 2016-07-21
CVE-2024-11320 Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pa… Patch early 9.8 critical 91% 2024-11-21
CVE-2021-22962 An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Patch early 9.1 critical 91% 2023-12-19
CVE-2022-26809 Remote Procedure Call Runtime Remote Code Execution Vulnerability Patch early 9.8 critical 91% 2022-04-15
CVE-2022-36553 Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. Patch early 9.8 critical 90.9% 2022-08-29
CVE-2022-31137 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executio… Patch early 10.0 critical 90.6% 2022-07-08
CVE-2023-37582 The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5… Patch early 9.8 critical 90.4% 2023-07-12
CVE-2023-6875 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized a… Patch early 9.8 critical 90.3% 2024-01-11
CVE-2023-46264 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Patch early 9.8 critical 90.2% 2023-12-19
CVE-2024-5276 A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of admin… Patch early 9.8 critical 90.1% 2024-06-25
CVE-2024-7954 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and un… Patch early 9.8 critical 90.1% 2024-08-23
CVE-2020-11984 Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE Patch early 9.8 critical 90% 2020-08-07
CVE-2020-17132 Microsoft Exchange Remote Code Execution Vulnerability Patch early 9.1 critical 89.9% 2020-12-10
CVE-2017-5645 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a s… Patch early 9.8 critical 89.8% 2017-04-17
CVE-2024-1071 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… Patch early 9.8 critical 89.4% 2024-03-13
CVE-2024-29972 ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.2… Patch early 9.8 critical 89.3% 2024-06-04
CVE-2020-35489 The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename… Patch early 10.0 critical 89.3% 2020-12-17
← previous page 66 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt