peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,359 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,624 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-7816 ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Success… Patch early 9.8 critical 67.8% 2019-05-24
CVE-2017-18369 The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function… Patch early 9.8 critical 67.6% 2019-05-02
CVE-2025-13486 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_f… Patch early 9.8 critical 67.6% 2025-12-03
CVE-2023-3765 Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. Patch early 10.0 critical 67.6% 2023-07-19
CVE-2023-2732 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verifi… Patch early 9.8 critical 67.5% 2023-05-25
CVE-2023-34039 Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor w… Patch early 9.8 critical 67.2% 2023-08-29
CVE-2022-29806 ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribute… Patch early 9.8 critical 67.1% 2022-04-26
CVE-2020-26935 An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMy… Patch early 9.8 critical 67.1% 2020-10-10
CVE-2022-43672 Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different softw… Patch early 9.8 critical 67.1% 2022-11-12
CVE-2024-3552 The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action av… Patch early 9.8 critical 67.1% 2024-06-13
CVE-2019-5096 An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application i… Patch early 9.8 critical 67% 2019-12-03
CVE-2023-32521 A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote atta… Patch early 9.1 critical 66.8% 2023-06-26
CVE-2018-1161 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13. Authentication is… Patch early 9.8 critical 66.7% 2018-02-08
CVE-2021-24321 The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt… Patch early 9.8 critical 66.6% 2021-06-01
CVE-2022-23305 By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from P… Patch early 9.8 critical 66.5% 2022-01-18
CVE-2022-3229 Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated at… Patch early 9.8 critical 66.4% 2023-02-06
CVE-2023-38204 Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vul… Patch early 9.8 critical 66.2% 2023-09-14
CVE-2019-6553 A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic… Patch early 9.8 critical 66.1% 2019-04-04
CVE-2020-26214 In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to u… Patch early 9.1 critical 65.9% 2020-11-06
CVE-2020-27130 A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability i… Patch early 9.1 critical 65.9% 2020-11-17
CVE-2023-29516 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.Attachmen… Patch early 9.9 critical 65.9% 2023-04-19
CVE-2019-12630 A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitra… Patch early 9.8 critical 65.8% 2019-10-02
CVE-2021-42127 A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via D… Patch early 9.8 critical 65.8% 2021-12-07
CVE-2023-30805 The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauth… Patch early 9.8 critical 65.8% 2023-10-10
CVE-2023-30806 The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauth… Patch early 9.8 critical 65.8% 2023-10-10
CVE-2025-8943 The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inhe… Patch early 9.8 critical 65.8% 2025-08-14
CVE-2023-25076 A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc… Patch early 9.8 critical 65.8% 2023-03-30
CVE-2024-35286 A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due… Patch early 9.8 critical 65.7% 2024-10-21
CVE-2020-7471 Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in… Patch early 9.8 critical 65.6% 2020-02-03
CVE-2019-10883 Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. Patch early 9.8 critical 65.5% 2019-06-03
← previous page 76 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt