peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,359 CVEs 1,730 on KEV 17,275 EPSS ≥ 10% 25,087 with exploits synced 2026-10-01

36,624 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-46574 An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmware… Patch early 9.8 critical 65.4% 2023-10-25
CVE-2020-36708 The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello… Patch early 9.8 critical 65.3% 2023-06-07
CVE-2025-25292 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-s… Patch early 9.8 critical 65.1% 2025-03-12
CVE-2023-6329 An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" opt… Patch early 9.8 critical 65% 2023-11-27
CVE-2024-54676 Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions a… Patch early 9.8 critical 64.9% 2025-01-08
CVE-2018-8476 A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deploymen… Patch early 9.8 critical 64.8% 2018-11-14
CVE-2022-23221 H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FOR… Patch early 9.8 critical 64.8% 2022-01-19
CVE-2025-25256 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSI… Patch early 9.8 critical 64.7% 2025-08-12
CVE-2021-22707 A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking… Patch early 9.8 critical 64.6% 2021-07-21
CVE-2022-31499 Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists b… Patch early 9.8 critical 64.6% 2022-08-25
CVE-2023-44350 Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could… Patch early 9.8 critical 64.6% 2023-11-17
CVE-2024-4883 In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthe… Patch early 9.8 critical 64.5% 2024-06-25
CVE-2023-41109 SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection. Patch early 9.8 critical 64.5% 2023-08-28
CVE-2022-29155 In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL st… Patch early 9.8 critical 64.5% 2022-05-04
CVE-2018-15727 Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie… Patch early 9.8 critical 64.3% 2018-08-29
CVE-2021-40865 An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (R… Patch early 9.8 critical 64.2% 2021-10-25
CVE-2023-39475 Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulne… Patch early 9.8 critical 64.1% 2024-05-03
CVE-2022-1609 The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API h… Patch early 9.8 critical 64.1% 2024-01-16
CVE-2020-8466 A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled,… Patch early 9.8 critical 64.1% 2020-12-17
CVE-2021-41081 Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search. Patch early 9.8 critical 64.1% 2021-11-11
CVE-2024-47407 A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to i… Patch early 10.0 critical 64% 2024-11-22
CVE-2023-5652 The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it… Patch early 9.8 critical 63.7% 2023-11-20
CVE-2024-37014 Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a P… Patch early 9.8 critical 63.7% 2024-06-10
CVE-2022-30547 A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted… Patch early 9.9 critical 63.7% 2022-08-22
CVE-2023-26475 XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted… Patch early 9.9 critical 63.6% 2023-03-02
CVE-2025-62168 Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows inf… Patch early 10.0 critical 63.4% 2025-10-17
CVE-2023-29017 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host obj… Patch early 10.0 critical 63.2% 2023-04-06
CVE-2023-45878 GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The en… Patch early 9.8 critical 63.1% 2023-11-14
CVE-2023-51409 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:… Patch early 10.0 critical 63.1% 2024-04-12
CVE-2023-49606 A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header… Patch early 9.8 critical 63.1% 2024-05-01
← previous page 77 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt