peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

400,973 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,699 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-7102 Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue… Patch early 9.8 critical 44.6% 2023-12-24
CVE-1999-0043 Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. Patch early 9.8 critical 44.6% 1996-12-04
CVE-2022-24313 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remot… Patch early 9.8 critical 44.6% 2022-02-09
CVE-2016-2177 OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of se… Patch early 9.8 critical 44.5% 2016-06-20
CVE-2024-56511 DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.Tok… Patch early 9.8 critical 44.5% 2025-01-10
CVE-2023-32564 An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Patch early 9.8 critical 44.4% 2023-08-10
CVE-2021-35042 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web applica… Patch early 9.8 critical 44.4% 2021-07-02
CVE-2019-13635 The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal. Patch early 9.1 critical 44.4% 2019-07-30
CVE-2024-48307 JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. Patch early 9.8 critical 44.3% 2024-10-31
CVE-2020-5505 Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-ph… Patch early 9.8 critical 44.3% 2020-01-14
CVE-2021-42887 In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. Patch early 9.8 critical 44.3% 2022-06-03
CVE-2022-41903 Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality i… Patch early 9.8 critical 44.3% 2023-01-17
CVE-2016-2182 The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to c… Patch early 9.8 critical 44.2% 2016-09-16
CVE-2024-55556 A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server b… Patch early 9.8 critical 44.1% 2025-01-07
CVE-2020-5514 Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI. Patch early 9.1 critical 44.1% 2020-01-06
CVE-2019-7839 ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploita… Patch early 9.8 critical 44.1% 2019-06-12
CVE-2017-17733 Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. Patch early 9.8 critical 44.1% 2017-12-18
CVE-2023-2227 Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. Patch early 9.1 critical 44% 2023-04-21
CVE-2024-26304 There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sendin… Patch early 9.8 critical 44% 2024-05-01
CVE-2019-12583 Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts… Patch early 9.1 critical 43.9% 2019-06-27
CVE-2022-0479 The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL stateme… Patch early 9.8 critical 43.8% 2022-03-28
CVE-2025-30065 Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recom… Patch early 9.8 critical 43.6% 2025-04-01
CVE-2024-8672 The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… Patch early 9.9 critical 43.6% 2024-11-28
CVE-2024-7591 Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * EC… Patch early 10.0 critical 43.5% 2024-09-05
CVE-2021-25833 A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an… Patch early 9.8 critical 43.5% 2021-03-01
CVE-2025-61622 Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows… Patch early 9.8 critical 43.5% 2025-10-01
CVE-2024-3080 Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. Patch early 9.8 critical 43.5% 2024-06-14
CVE-2019-14314 A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability… Patch early 9.8 critical 43.4% 2019-08-27
CVE-2022-0773 The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then exe… Patch early 9.8 critical 43.3% 2022-05-02
CVE-2023-35042 GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData with… Patch early 9.8 critical 43.2% 2023-06-12
← previous page 86 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt