peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-4879 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier v… Patch early 9.8 critical 28.6% 2018-02-27
CVE-2022-27115 In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. Patch early 9.8 critical 28.6% 2022-04-11
CVE-2023-31222 Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an… Patch early 9.8 critical 28.5% 2023-06-29
CVE-2024-24116 An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. Patch early 9.8 critical 28.4% 2024-10-02
CVE-2020-3657 u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webs… Patch early 9.8 critical 28.3% 2020-11-02
CVE-2024-3429 A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` fu… Patch early 9.8 critical 28.3% 2024-06-06
CVE-2017-14706 DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices… Patch early 9.8 critical 28.2% 2017-09-22
CVE-2019-0725 A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote… Patch early 9.8 critical 28.2% 2019-05-16
CVE-2018-15957 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data… Patch early 9.8 critical 28.2% 2018-09-25
CVE-2019-13375 A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeA… Patch early 9.8 critical 28.2% 2019-07-06
CVE-2022-22720 Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server t… Patch early 9.8 critical 28.2% 2022-03-14
CVE-2016-0857 Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors. Patch early 9.8 critical 28.2% 2016-01-15
CVE-2022-28573 D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows at… Patch early 9.8 critical 28.2% 2022-05-02
CVE-2023-52755 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds wri… Patch early 9.8 critical 28.1% 2024-05-21
CVE-2026-22557 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on th… Patch early 10.0 critical 28.1% 2026-03-19
CVE-2016-3109 The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code. Patch early 9.8 critical 28.1% 2017-04-21
CVE-2019-14529 OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. Patch early 9.8 critical 28.1% 2019-08-02
CVE-2024-10443 Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhot… Patch early 9.8 critical 28% 2024-11-15
CVE-2026-1492 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin… Patch early 9.8 critical 28% 2026-03-03
CVE-2025-47539 Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a t… Patch early 9.8 critical 27.9% 2025-05-23
CVE-2018-15531 JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. Patch early 9.8 critical 27.9% 2018-09-26
CVE-2020-25112 An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denia… Patch early 9.8 critical 27.9% 2020-12-11
CVE-2021-27162 An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. Patch early 9.8 critical 27.8% 2021-02-10
CVE-2018-3252 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are aff… Patch early 9.8 critical 27.8% 2018-10-17
CVE-2024-49368 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the… Patch early 9.8 critical 27.7% 2024-10-21
CVE-2016-4532 Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to… Patch early 9.1 critical 27.6% 2016-06-09
CVE-2022-29805 A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code vi… Patch early 9.8 critical 27.6% 2022-08-19
CVE-2016-8519 A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. Patch early 9.8 critical 27.6% 2018-02-15
CVE-2019-16124 In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, a… Patch early 9.8 critical 27.6% 2019-09-09
CVE-2025-27590 In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account… Patch early 9.0 critical 27.6% 2025-03-03
← previous page 98 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt