peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,014 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,699 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-38476 Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend ap… Patch early 9.8 critical 41.6% 2024-07-01
CVE-2018-19986 In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR… Patch early 9.8 critical 41.6% 2019-05-13
CVE-2016-7480 The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows r… Patch early 9.8 critical 41.6% 2017-01-11
CVE-2020-23584 Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRE… Patch early 9.8 critical 41.4% 2022-11-23
CVE-2023-4473 A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0… Patch early 9.8 critical 41.3% 2023-11-30
CVE-2025-52665 A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that expose… Patch early 10.0 critical 41.1% 2025-10-31
CVE-2022-46476 D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function. Patch early 9.8 critical 41.1% 2023-01-19
CVE-2015-3253 The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause… Patch early 9.8 critical 41% 2015-08-13
CVE-2024-46986 Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the uplo… Patch early 9.9 critical 41% 2024-09-18
CVE-2020-24913 A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to… Patch early 9.8 critical 40.9% 2021-03-04
CVE-2023-4521 The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor… Patch early 9.8 critical 40.8% 2023-09-25
CVE-2016-10329 Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell m… Patch early 9.8 critical 40.8% 2017-05-12
CVE-2019-18939 eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers w… Patch early 9.8 critical 40.8% 2019-11-14
CVE-2023-43654 TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling th… Patch early 10.0 critical 40.7% 2023-09-28
CVE-2025-27520 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability… Patch early 9.8 critical 40.6% 2025-04-04
CVE-2024-38289 A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote att… Patch early 9.8 critical 40.6% 2024-07-25
CVE-2023-1730 The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthen… Patch early 9.8 critical 40.6% 2023-05-02
CVE-2026-2329 An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage t… Patch early 9.8 critical 40.6% 2026-02-18
CVE-2023-2564 OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. Patch early 10.0 critical 40.5% 2023-05-07
CVE-2024-1601 An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete a… Patch early 9.8 critical 40.4% 2024-04-16
CVE-2025-52694 Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vul… Patch early 10.0 critical 40.4% 2026-01-12
CVE-2024-1800 In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deseriali… Patch early 9.9 critical 40.4% 2024-03-20
CVE-2019-18370 An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application use… Patch early 9.8 critical 40.3% 2019-10-23
CVE-2024-50330 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated att… Patch early 9.8 critical 40.3% 2024-11-12
CVE-2022-25060 TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. Patch early 9.8 critical 40.2% 2022-02-25
CVE-2023-36460 Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, a… Patch early 9.9 critical 40.1% 2023-07-06
CVE-2021-26709 D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over… Patch early 9.8 critical 40.1% 2021-04-07
CVE-2022-25369 An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a lo… Patch early 9.8 critical 40% 2026-01-23
CVE-2023-35138 A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmw… Patch early 9.8 critical 40% 2023-11-30
CVE-2024-10081 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs w… Patch early 10.0 critical 39.9% 2024-11-06
← previous page 88 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt