peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,045 CVEs 1,733 on KEV 17,286 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,701 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2020-24338 An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_com… Patch early 9.8 critical 37.2% 2020-12-11
CVE-2018-11143 Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). Patch early 9.8 critical 37.2% 2018-06-02
CVE-2022-0739 The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL… Patch early 9.8 critical 37.2% 2022-03-21
CVE-2022-1905 The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX a… Patch early 9.8 critical 37.1% 2022-06-20
CVE-2022-27255 In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker… Patch early 9.8 critical 37.1% 2022-08-01
CVE-2024-4434 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, an… Patch early 9.8 critical 36.9% 2024-05-14
CVE-2020-28017 Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: re… Patch early 9.8 critical 36.9% 2021-05-06
CVE-2020-11896 The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. Patch early 10.0 critical 36.9% 2020-06-17
CVE-2021-22652 Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to cha… Patch early 9.8 critical 36.8% 2021-02-11
CVE-2021-3120 An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve… Patch early 9.8 critical 36.8% 2021-02-22
CVE-2022-35712 Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could res… Patch early 9.8 critical 36.8% 2022-10-14
CVE-2024-45622 ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass. Patch early 9.8 critical 36.7% 2024-09-02
CVE-2023-20126 A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute… Patch early 9.8 critical 36.7% 2023-05-04
CVE-2021-30461 A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR va… Patch early 9.8 critical 36.6% 2021-05-29
CVE-2021-47667 An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to exec… Patch early 10.0 critical 36.6% 2025-04-05
CVE-2024-51482 ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Inj… Patch early 9.9 critical 36.6% 2024-10-31
CVE-2017-8220 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placi… Patch early 9.9 critical 36.6% 2017-04-25
CVE-2020-10547 rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stor… Patch early 9.8 critical 36.6% 2020-06-04
CVE-2020-11981 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ)… Patch early 9.8 critical 36.5% 2020-07-17
CVE-2019-17564 Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in… Patch early 9.8 critical 36.5% 2020-04-01
CVE-2020-10548 rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext,… Patch early 9.8 critical 36.5% 2020-06-04
CVE-2022-25064 TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. Patch early 9.8 critical 36.5% 2022-02-25
CVE-2022-39428 Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are af… Patch early 9.8 critical 36.5% 2022-10-18
CVE-2021-22930 Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption,… Patch early 9.8 critical 36.5% 2021-10-07
CVE-2019-8917 SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes… Patch early 9.8 critical 36.4% 2019-02-18
CVE-2021-25274 The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queu… Patch early 9.8 critical 36.4% 2021-02-03
CVE-2025-32814 An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. Patch early 9.8 critical 36.4% 2025-05-22
CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew… Patch early 9.8 critical 36.4% 2024-10-26
CVE-2023-41727 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 36.4% 2023-12-19
CVE-2023-46216 An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (… Patch early 9.8 critical 36.4% 2023-12-19
← previous page 91 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt