peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,045 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,701 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-5129 A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthent… Patch early 9.8 critical 38.5% 2019-10-25
CVE-2023-5399 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files… Patch early 9.8 critical 38.5% 2023-10-04
CVE-2017-11383 SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation… Patch early 9.8 critical 38.5% 2017-08-02
CVE-2017-11384 SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation… Patch early 9.8 critical 38.5% 2017-08-02
CVE-2017-11385 SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation… Patch early 9.8 critical 38.5% 2017-08-02
CVE-2024-29849 Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. Patch early 9.8 critical 38.4% 2024-05-22
CVE-2023-51572 Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e… Patch early 9.8 critical 38.4% 2024-04-01
CVE-2022-2754 The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL s… Patch early 9.8 critical 38.3% 2022-09-19
CVE-2015-5254 Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitra… Patch early 9.8 critical 38.2% 2016-01-08
CVE-2023-50917 MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Major… Patch early 9.8 critical 38% 2023-12-15
CVE-2016-0003 Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." Patch early 9.6 critical 38% 2016-01-13
CVE-2017-14469 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 10.0 critical 38% 2018-04-05
CVE-2017-14470 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 10.0 critical 38% 2018-04-05
CVE-2017-14471 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 10.0 critical 38% 2018-04-05
CVE-2017-14472 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 10.0 critical 38% 2018-04-05
CVE-2017-14473 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 10.0 critical 38% 2018-04-05
CVE-2017-14464 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 9.8 critical 38% 2018-04-05
CVE-2017-14466 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 9.8 critical 38% 2018-04-05
CVE-2017-14468 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 9.8 critical 38% 2018-04-05
CVE-2022-28127 A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request c… Patch early 9.1 critical 37.9% 2022-06-30
CVE-2017-12556 A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Patch early 9.8 critical 37.9% 2018-02-15
CVE-2017-12558 A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. Patch early 9.8 critical 37.9% 2018-02-15
CVE-2021-43711 The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The pa… Patch early 9.8 critical 37.8% 2022-01-04
CVE-2017-7525 A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user t… Patch early 9.8 critical 37.7% 2018-02-06
CVE-2023-39367 An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted… Patch early 9.1 critical 37.7% 2024-04-17
CVE-2024-7094 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i… Patch early 9.8 critical 37.6% 2024-08-13
CVE-2022-26833 An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafte… Patch early 9.4 critical 37.6% 2022-05-25
CVE-2024-2083 A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit thi… Patch early 9.9 critical 37.5% 2024-04-16
CVE-2021-32955 Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code. Patch early 9.8 critical 37.3% 2021-08-30
CVE-2017-14467 An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400… Patch early 9.8 critical 37.3% 2018-04-05
← previous page 90 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt