peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,331 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,621 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-4350 Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager… Patch early 9.8 critical 70.2% 2016-05-09
CVE-2024-53677 File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances thi… Patch early 9.8 critical 70.1% 2024-12-11
CVE-2021-32682 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerab… Patch early 9.8 critical 69.9% 2021-06-14
CVE-2022-44456 CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the p… Patch early 9.8 critical 69.9% 2022-12-19
CVE-2021-21805 An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTT… Patch early 9.8 critical 69.8% 2021-08-05
CVE-2017-18044 A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside th… Patch early 9.8 critical 69.8% 2018-01-19
CVE-2023-1177 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. Patch early 9.3 critical 69.7% 2023-03-24
CVE-2023-3368 Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code… Patch early 9.8 critical 69.7% 2023-11-28
CVE-2023-22463 KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys fo… Patch early 9.8 critical 69.7% 2023-01-04
CVE-2023-26801 LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injec… Patch early 9.8 critical 69.7% 2023-03-26
CVE-2023-5074 Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 Patch early 9.8 critical 69.6% 2023-09-20
CVE-2019-17444 Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow un… Patch early 9.8 critical 69.4% 2020-10-12
CVE-2020-7388 Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attac… Patch early 10.0 critical 69.4% 2021-07-22
CVE-2023-40497 LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code… Patch early 9.8 critical 69.4% 2024-05-03
CVE-2021-33690 Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -… Patch early 9.9 critical 69.1% 2021-09-15
CVE-2019-12196 A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute a… Patch early 9.8 critical 69.1% 2019-06-05
CVE-2019-17571 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbit… Patch early 9.8 critical 69.1% 2019-12-20
CVE-2017-5791 The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via uns… Patch early 9.8 critical 68.9% 2017-10-11
CVE-2014-9614 The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to ob… Patch early 9.8 critical 68.7% 2020-02-19
CVE-2019-0626 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Wi… Patch early 9.8 critical 68.6% 2019-03-05
CVE-2020-13117 Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a log… Patch early 9.8 critical 68.6% 2021-02-09
CVE-2017-17736 Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx an… Patch early 9.8 critical 68.5% 2018-03-23
CVE-2020-13942 It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vec… Patch early 9.8 critical 68.3% 2020-11-24
CVE-2021-29203 A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software… Patch early 9.8 critical 68.3% 2021-05-06
CVE-2021-26691 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow Patch early 9.8 critical 68.3% 2021-06-10
CVE-2018-10931 It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use… Patch early 9.8 critical 68.1% 2018-08-09
CVE-2018-11714 An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Buil… Patch early 9.8 critical 68.1% 2018-06-04
CVE-2019-13373 An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements… Patch early 9.8 critical 68% 2019-07-06
CVE-2025-40553 SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic… Patch early 9.8 critical 68% 2026-01-28
CVE-2021-41765 A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to… Patch early 9.8 critical 67.8% 2021-11-15
← previous page 75 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt