peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,014 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,699 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-30080 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Patch early 9.8 critical 43.1% 2024-06-11
CVE-2022-1281 The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, makin… Patch early 9.8 critical 43.1% 2022-05-02
CVE-2023-49231 An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API t… Patch early 9.8 critical 42.9% 2024-03-29
CVE-2025-64155 An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3… Patch early 9.8 critical 42.8% 2026-01-13
CVE-2021-43421 A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arb… Patch early 9.8 critical 42.8% 2022-04-07
CVE-2023-25826 Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameter… Patch early 9.8 critical 42.8% 2023-05-03
CVE-2022-4060 The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors… Patch early 9.8 critical 42.7% 2023-01-16
CVE-2017-11283 Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 an… Patch early 9.8 critical 42.7% 2017-12-01
CVE-2017-11284 Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 an… Patch early 9.8 critical 42.7% 2017-12-01
CVE-2022-42233 Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability. Patch early 9.8 critical 42.7% 2022-10-20
CVE-2022-35710 Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could re… Patch early 9.8 critical 42.6% 2022-10-14
CVE-2019-12987 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). Patch early 9.8 critical 42.6% 2019-07-16
CVE-2019-12988 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). Patch early 9.8 critical 42.6% 2019-07-16
CVE-2023-2986 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is… Patch early 9.8 critical 42.5% 2023-06-08
CVE-2023-41887 OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any… Patch early 9.8 critical 42.5% 2023-09-15
CVE-2019-13132 In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runnin… Patch early 9.8 critical 42.5% 2019-07-10
CVE-2025-68615 net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd d… Patch early 9.8 critical 42.4% 2025-12-23
CVE-2022-2234 An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. Patch early 9.9 critical 42.3% 2022-08-24
CVE-2009-2494 The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and S… Patch early 9.8 critical 42.3% 2009-08-12
CVE-2025-30220 GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent… Patch early 9.9 critical 42.3% 2025-06-10
CVE-2024-45387 An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "… Patch early 9.9 critical 42.2% 2024-12-23
CVE-2023-28662 The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the t… Patch early 9.8 critical 42.2% 2023-03-22
CVE-2022-34267 An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbi… Patch early 9.8 critical 42.2% 2023-12-25
CVE-2021-24284 The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The sup… Patch early 9.8 critical 42.1% 2021-05-14
CVE-2021-37580 A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affe… Patch early 9.8 critical 41.9% 2021-11-16
CVE-2024-25153 A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’… Patch early 9.8 critical 41.7% 2024-03-13
CVE-2022-22721 If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later cau… Patch early 9.1 critical 41.7% 2022-03-14
CVE-2020-3331 A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an un… Patch early 9.8 critical 41.7% 2020-07-16
CVE-2016-7479 In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.… Patch early 9.8 critical 41.7% 2017-01-12
CVE-2019-19307 An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause a… Patch early 9.8 critical 41.6% 2019-11-26
← previous page 87 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt