peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,208 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,613 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-35150 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to vers… Patch early 9.9 critical 77.7% 2023-06-23
CVE-2024-1698 The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQ… Patch early 9.8 critical 77.6% 2024-02-27
CVE-2024-1512 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user'… Patch early 9.8 critical 77.6% 2024-02-17
CVE-2019-0192 In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it… Patch early 9.8 critical 77.5% 2019-03-07
CVE-2018-0127 A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unaut… Patch early 9.8 critical 77.5% 2018-02-08
CVE-2020-11532 Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attack… Patch early 9.8 critical 77.5% 2020-05-08
CVE-2018-1270 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over… Patch early 9.8 critical 77.5% 2018-04-06
CVE-2022-25149 The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~… Patch early 9.8 critical 77.5% 2022-02-24
CVE-2020-9850 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iT… Patch early 9.8 critical 77.4% 2020-06-09
CVE-2024-8877 Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database o… Patch early 9.8 critical 77.3% 2024-09-25
CVE-2022-29013 A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a cra… Patch early 9.8 critical 76.9% 2022-06-09
CVE-2024-5932 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… Patch early 10.0 critical 76.8% 2024-08-20
CVE-2016-3236 The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows… Patch early 9.8 critical 76.8% 2016-06-16
CVE-2021-41303 Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should… Patch early 9.8 critical 76.7% 2021-09-17
CVE-2022-2185 A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.… Patch early 9.9 critical 76.7% 2022-07-01
CVE-2024-22120 Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip"… Patch early 9.1 critical 76.6% 2024-05-17
CVE-2022-45699 Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comman… Patch early 9.8 critical 76.6% 2023-02-10
CVE-2020-13638 lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fi… Patch early 9.8 critical 76.6% 2020-11-13
CVE-2021-2394 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… Patch early 9.8 critical 76.6% 2021-07-21
CVE-2024-32640 MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL inject… Patch early 9.8 critical 76.6% 2025-08-11
CVE-2022-36099 XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 a… Patch early 9.9 critical 76.3% 2022-09-08
CVE-2020-35951 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.p… Patch early 9.9 critical 76.3% 2021-01-01
CVE-2022-34721 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Patch early 9.8 critical 76.2% 2022-09-13
CVE-2025-6389 The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pag… Patch early 9.8 critical 76.1% 2025-11-25
CVE-2024-36404 GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) i… Patch early 9.8 critical 76.1% 2024-07-02
CVE-2021-41653 The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cra… Patch early 9.8 critical 76% 2021-11-13
CVE-2022-26937 Windows Network File System Remote Code Execution Vulnerability Patch early 9.8 critical 76% 2022-05-10
CVE-2024-41730 In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a log… Patch early 9.8 critical 75.9% 2024-08-13
CVE-2025-48827 vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.… Patch early 10.0 critical 75.8% 2025-05-27
CVE-2023-48085 Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php. Patch early 9.8 critical 75.8% 2023-12-14
← previous page 71 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt