peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,265 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,616 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-2917 The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path… Patch early 9.8 critical 72.2% 2023-08-17
CVE-2023-27482 homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API t… Patch early 10.0 critical 72.2% 2023-03-08
CVE-2021-33564 An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a craf… Patch early 9.8 critical 72.1% 2021-05-29
CVE-2023-30547 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 f… Patch early 9.8 critical 72.1% 2023-04-17
CVE-2024-12084 A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2len… Patch early 9.8 critical 72.1% 2025-01-15
CVE-2021-30117 The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed desc… Patch early 9.8 critical 72.1% 2021-07-09
CVE-2020-4429 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker c… Patch early 9.8 critical 72% 2020-05-07
CVE-2024-49112 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Patch early 9.8 critical 71.9% 2024-12-12
CVE-2023-2825 An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability t… Patch early 10.0 critical 71.6% 2023-05-26
CVE-2022-1386 The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate… Patch early 9.8 critical 71.4% 2022-05-16
CVE-2019-0547 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows… Patch early 9.8 critical 71.4% 2019-01-08
CVE-2021-28480 Microsoft Exchange Server Remote Code Execution Vulnerability Patch early 9.8 critical 71.2% 2021-04-13
CVE-2018-2893 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch early 9.8 critical 71.2% 2018-07-18
CVE-2023-45138 Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prio… Patch early 10.0 critical 71.2% 2023-10-12
CVE-2020-4211 IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP c… Patch early 9.8 critical 71.1% 2020-02-24
CVE-2020-2950 Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported… Patch early 9.8 critical 71% 2020-04-15
CVE-2019-5620 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. Patch early 9.8 critical 70.9% 2020-04-29
CVE-2024-22729 NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page. Patch early 9.8 critical 70.8% 2024-01-25
CVE-2021-45467 In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to regis… Patch early 9.8 critical 70.7% 2022-12-26
CVE-2018-17532 Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi an… Patch early 9.8 critical 70.7% 2018-10-15
CVE-2022-47523 Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. Patch early 9.8 critical 70.6% 2023-01-05
CVE-2024-38063 Windows TCP/IP Remote Code Execution Vulnerability Patch early 9.8 critical 70.6% 2024-08-13
CVE-2023-20864 VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Opera… Patch early 9.8 critical 70.4% 2023-04-20
CVE-2022-28381 Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TC… Patch early 9.8 critical 70.4% 2022-04-03
CVE-2022-26133 SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 a… Patch early 9.8 critical 70.4% 2022-04-20
CVE-2023-32071 XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to… Patch early 9.0 critical 70.4% 2023-05-09
CVE-2021-35393 Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usua… Patch early 9.8 critical 70.3% 2021-08-16
CVE-2021-42847 Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. Patch early 9.8 critical 70.3% 2021-11-11
CVE-2023-29711 An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET reque… Patch early 9.8 critical 70.3% 2023-06-22
CVE-2016-6309 statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of ser… Patch early 9.8 critical 70.2% 2016-09-26
← previous page 74 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt