peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,165 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,608 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2021-26120 Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. Patch early 9.8 critical 82.3% 2021-02-22
CVE-2025-49844 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua… Patch early 9.9 critical 82.3% 2025-10-03
CVE-2018-17246 Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console… Patch early 9.8 critical 82.3% 2018-12-20
CVE-2020-9465 An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauth… Patch early 9.8 critical 82.2% 2020-02-28
CVE-2023-1698 In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which… Patch early 9.8 critical 82% 2023-05-15
CVE-2023-38096 NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa… Patch early 9.8 critical 82% 2024-05-03
CVE-2023-36469 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile… Patch early 9.9 critical 82% 2023-06-29
CVE-2020-7200 A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow… Patch early 9.8 critical 81.9% 2020-12-18
CVE-2023-46263 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Patch early 9.8 critical 81.9% 2023-12-19
CVE-2021-25114 The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users)… Patch early 9.8 critical 81.8% 2022-02-07
CVE-2023-43177 CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. Patch early 9.8 critical 81.8% 2023-11-18
CVE-2016-10372 The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as… Patch early 9.8 critical 81.8% 2017-05-16
CVE-2015-7871 Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. Patch early 9.8 critical 81.8% 2017-08-07
CVE-2020-27868 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not re… Patch early 9.8 critical 81.8% 2021-02-12
CVE-2024-5806 Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:… Patch early 9.1 critical 81.5% 2024-06-25
CVE-2021-2456 Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The suppo… Patch early 9.8 critical 81.4% 2021-07-21
CVE-2021-33543 Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user aut… Patch early 9.8 critical 81.3% 2021-09-13
CVE-2021-30128 Apache OFBiz has unsafe deserialization prior to 17.12.07 version Patch early 9.8 critical 81.2% 2021-04-27
CVE-2019-17602 An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depend… Patch early 9.8 critical 81.1% 2019-10-15
CVE-2022-31704 The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive fi… Patch early 9.8 critical 81% 2023-01-26
CVE-2021-38540 The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint t… Patch early 9.8 critical 80.9% 2021-09-09
CVE-2025-21298 Windows OLE Remote Code Execution Vulnerability Patch early 9.8 critical 80.9% 2025-01-14
CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which… Patch early 9.8 critical 80.8% 2023-12-07
CVE-2024-2876 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… Patch early 9.8 critical 80.6% 2024-05-02
CVE-2022-34715 Windows Network File System Remote Code Execution Vulnerability Patch early 9.8 critical 80.4% 2022-08-09
CVE-2022-37860 The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerabili… Patch early 9.8 critical 80.4% 2022-09-12
CVE-2024-4990 In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value pa… Patch early 9.1 critical 80.2% 2025-03-20
CVE-2024-56325 Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Exampl… Patch early 9.8 critical 80.2% 2025-04-01
CVE-2023-44353 Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could… Patch early 9.8 critical 80.2% 2023-11-17
CVE-2023-39143 PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads t… Patch early 9.8 critical 80.1% 2023-08-04
← previous page 69 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt