peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-7846 A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Qu… Patch early 9.8 critical 29.6% 2019-05-22
CVE-2019-19825 On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin… Patch early 9.8 critical 29.6% 2020-01-27
CVE-2019-19492 FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. Patch early 9.8 critical 29.4% 2019-12-02
CVE-2024-4548 An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is sp… Patch early 9.8 critical 29.4% 2024-05-06
CVE-2012-1891 Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote atta… Patch early 9.8 critical 29.4% 2012-07-10
CVE-2018-14699 System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execu… Patch early 9.8 critical 29.4% 2018-12-03
CVE-2020-9480 In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a share… Patch early 9.8 critical 29.4% 2020-06-23
CVE-2022-4101 The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthentic… Patch early 9.1 critical 29.4% 2023-01-16
CVE-2023-34800 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. Patch early 9.8 critical 29.3% 2023-06-15
CVE-2023-20032 On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of C… Patch early 9.8 critical 29.3% 2023-03-01
CVE-2018-14767 In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and… Patch early 9.8 critical 29.3% 2018-07-31
CVE-2024-32002 Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be cr… Patch early 9.0 critical 29.2% 2024-05-14
CVE-2025-59719 An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4… Patch early 9.8 critical 29.2% 2025-12-09
CVE-2018-8273 A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Se… Patch early 9.8 critical 29.2% 2018-08-15
CVE-2020-12011 A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This i… Patch early 9.8 critical 29.2% 2020-07-16
CVE-2024-39907 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, lea… Patch early 9.8 critical 29.2% 2024-07-18
CVE-2022-25017 Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. Patch early 9.1 critical 29.1% 2022-04-01
CVE-2018-8421 A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulner… Patch early 9.8 critical 29.1% 2018-09-13
CVE-2021-30176 The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. Patch early 9.8 critical 29% 2021-04-13
CVE-2024-6366 The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via… Patch early 9.1 critical 29% 2024-07-29
CVE-2020-15568 TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerabi… Patch early 9.8 critical 29% 2021-01-30
CVE-2017-7577 XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. Patch early 9.8 critical 29% 2017-04-07
CVE-2019-7107 Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execu… Patch early 9.8 critical 28.9% 2019-05-23
CVE-2020-35613 An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend… Patch early 9.8 critical 28.9% 2020-12-28
CVE-2019-9848 LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. L… Patch early 9.8 critical 28.9% 2019-07-17
CVE-2023-34991 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 thro… Patch early 9.8 critical 28.8% 2023-11-14
CVE-2025-1128 The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file… Patch early 9.8 critical 28.8% 2025-02-25
CVE-2022-47945 ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). A… Patch early 9.8 critical 28.7% 2022-12-23
CVE-2024-8353 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… Patch early 9.8 critical 28.7% 2024-09-28
CVE-2015-8277 Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to… Patch early 9.8 critical 28.7% 2016-02-24
← previous page 97 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt