peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,157 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,608 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-32563 An unauthenticated attacker could achieve the code execution through a RemoteControl server. Patch early 9.8 critical 89.1% 2023-08-10
CVE-2020-12720 vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. Patch early 9.8 critical 88.9% 2020-05-08
CVE-2021-45456 Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch betw… Patch early 9.8 critical 88.9% 2022-01-06
CVE-2023-39361 Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_vi… Patch early 9.8 critical 88.8% 2023-09-05
CVE-2023-40504 LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Patch early 9.8 critical 88.7% 2024-05-03
CVE-2023-46731 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL… Patch early 10.0 critical 88.5% 2023-11-06
CVE-2020-3243 Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authe… Patch early 9.8 critical 88.4% 2020-04-15
CVE-2018-19207 The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $w… Patch early 9.8 critical 88.1% 2018-11-12
CVE-2022-0540 A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This af… Patch early 9.8 critical 88.1% 2022-04-20
CVE-2020-8772 The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows… Patch early 9.8 critical 88% 2020-02-06
CVE-2024-36104 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Patch early 9.1 critical 87.9% 2024-06-04
CVE-2021-3711 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this… Patch early 9.8 critical 87.8% 2021-08-24
CVE-2023-46359 An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to exe… Patch early 9.8 critical 87.6% 2024-02-06
CVE-2003-0545 Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL… Patch early 9.8 critical 87.5% 2003-11-17
CVE-2020-10546 rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in… Patch early 9.8 critical 87.3% 2020-06-04
CVE-2021-3122 CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to po… Patch early 9.8 critical 87.3% 2021-02-07
CVE-2018-15381 A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands… Patch early 9.8 critical 87.3% 2018-11-08
CVE-2020-26948 Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. Patch early 9.8 critical 87.2% 2020-10-10
CVE-2022-31706 The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system… Patch early 9.8 critical 87.1% 2023-01-26
CVE-2021-40323 Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. Patch early 9.8 critical 86.8% 2021-10-04
CVE-2023-35813 Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. Patch early 9.8 critical 86.7% 2023-06-17
CVE-2020-10915 This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not re… Patch early 9.8 critical 86.6% 2020-04-22
CVE-2018-17153 It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated a… Patch early 9.8 critical 86.6% 2018-09-18
CVE-2023-28121 An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an e… Patch early 9.8 critical 86.5% 2023-04-12
CVE-2021-45232 In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all… Patch early 9.8 critical 86.3% 2021-12-27
CVE-2022-2992 A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achi… Patch early 9.9 critical 86.2% 2022-10-17
CVE-2016-20016 MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenti… Patch early 9.8 critical 86.2% 2022-10-19
CVE-2024-29973 ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.1… Patch early 9.8 critical 86.1% 2024-06-04
CVE-2024-3094 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma bui… Patch early 10.0 critical 86% 2024-03-29
CVE-2020-17523 Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Patch early 9.8 critical 85.9% 2021-02-03
← previous page 67 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt