peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,955 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,698 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-18017 The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to ca… Patch early 9.8 critical 52.8% 2018-01-03
CVE-2020-13382 openSIS through 7.4 has Incorrect Access Control. Patch early 9.1 critical 52.8% 2020-07-01
CVE-2025-5394 The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability ch… Patch early 9.8 critical 52.8% 2025-07-15
CVE-2024-39931 Gogs through 0.13.0 allows deletion of internal files. Patch early 9.9 critical 52.7% 2024-07-04
CVE-2021-43778 Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are v… Patch early 9.1 critical 52.7% 2021-11-24
CVE-2025-32375 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deser… Patch early 9.8 critical 52.4% 2025-04-09
CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. Patch early 9.8 critical 52.3% 2023-03-06
CVE-2020-27615 The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip. Patch early 9.8 critical 52.3% 2020-10-21
CVE-2021-33032 A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 fir… Patch early 10.0 critical 52.2% 2021-07-22
CVE-2020-14841 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0… Patch early 9.8 critical 52% 2020-10-21
CVE-2025-40552 SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to exe… Patch early 9.8 critical 52% 2026-01-28
CVE-2017-11771 The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W… Patch early 9.8 critical 51.9% 2017-10-13
CVE-2021-41649 An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post… Patch early 9.8 critical 51.8% 2021-10-01
CVE-2024-7314 anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requ… Patch early 9.8 critical 51.8% 2024-08-02
CVE-2022-45933 KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and… Patch early 9.8 critical 51.7% 2022-11-27
CVE-2017-7925 A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX… Patch early 9.8 critical 51.4% 2017-05-06
CVE-2022-31061 GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affect… Patch early 9.8 critical 51.4% 2022-06-28
CVE-2023-6567 The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5… Patch early 9.8 critical 51.4% 2024-01-11
CVE-2021-3287 Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. Patch early 9.8 critical 51.3% 2021-04-22
CVE-2020-35131 Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/D… Patch early 9.8 critical 51.3% 2021-01-08
CVE-2025-41646 An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to… Patch early 9.8 critical 51.3% 2025-06-06
CVE-2024-26594 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in… Patch early 9.1 critical 51.2% 2024-02-23
CVE-2014-3206 Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_nam… Patch early 9.8 critical 51% 2018-02-23
CVE-2024-2862 This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant. Patch early 9.1 critical 51% 2024-03-25
CVE-2022-26960 connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and… Patch early 9.1 critical 51% 2022-03-21
CVE-2014-8389 cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with… Patch early 9.8 critical 50.8% 2017-12-28
CVE-2020-8010 CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (cont… Patch early 9.8 critical 50.7% 2020-02-18
CVE-2023-6623 The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering template… Patch early 9.8 critical 50.7% 2024-01-15
CVE-2024-5084 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file… Patch early 9.8 critical 50.7% 2024-05-23
CVE-2021-44427 An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute… Patch early 9.8 critical 50.6% 2021-11-29
← previous page 82 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt