peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,033 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,701 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-13050 A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_c… Patch early 9.8 critical 39.8% 2018-07-02
CVE-2023-26258 Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID t… Patch early 9.8 critical 39.8% 2023-07-03
CVE-2021-32671 Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when re… Patch early 10.0 critical 39.7% 2021-06-07
CVE-2024-53944 An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2… Patch early 9.8 critical 39.7% 2025-02-27
CVE-2025-10230 A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validatio… Patch early 10.0 critical 39.7% 2025-11-07
CVE-2023-29374 In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. Patch early 9.8 critical 39.7% 2023-04-05
CVE-2020-29390 Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated a… Patch early 9.8 critical 39.6% 2020-11-30
CVE-2019-12985 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). Patch early 9.8 critical 39.5% 2019-07-16
CVE-2019-12986 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). Patch early 9.8 critical 39.5% 2019-07-16
CVE-2017-3192 D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page… Patch early 9.8 critical 39.5% 2017-12-16
CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have… Patch early 9.9 critical 39.5% 2024-07-04
CVE-2021-39275 ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but th… Patch early 9.8 critical 39.4% 2021-09-16
CVE-2022-0888 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found… Patch early 9.8 critical 39.4% 2022-03-23
CVE-2020-10826 /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a r… Patch early 9.8 critical 39.4% 2020-03-26
CVE-2024-28988 SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Patch early 9.8 critical 39.4% 2025-09-01
CVE-2017-7679 In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type… Patch early 9.8 critical 39.3% 2017-06-20
CVE-2019-12990 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. Patch early 9.8 critical 39.3% 2019-07-16
CVE-2017-18349 parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code… Patch early 9.8 critical 39.2% 2018-10-23
CVE-2019-16932 A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. Patch early 10.0 critical 39.1% 2019-09-30
CVE-2022-46020 WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. Patch early 9.8 critical 39% 2022-12-20
CVE-2017-7504 HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Ser… Patch early 9.8 critical 38.9% 2017-05-19
CVE-2017-14463 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 9.8 critical 38.9% 2018-04-05
CVE-2020-21224 A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control… Patch early 9.8 critical 38.7% 2021-02-22
CVE-2019-16314 Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. Patch early 9.8 critical 38.7% 2019-09-14
CVE-2025-20282 A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affe… Patch early 10.0 critical 38.7% 2025-06-25
CVE-2022-39396 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1… Patch early 9.8 critical 38.7% 2022-11-10
CVE-2022-22916 O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. Patch early 9.8 critical 38.7% 2022-02-17
CVE-2021-28476 Windows Hyper-V Remote Code Execution Vulnerability Patch early 9.9 critical 38.6% 2021-05-11
CVE-2022-4305 The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which… Patch early 9.8 critical 38.6% 2023-01-23
CVE-2023-49442 Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. Patch early 9.8 critical 38.5% 2024-01-03
← previous page 89 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt