peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,061 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-03

36,703 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2023-21690 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Patch early 9.8 critical 27.5% 2023-02-14
CVE-2023-36177 An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafte… Patch early 9.8 critical 27.5% 2024-01-23
CVE-2017-8686 The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHC… Patch early 9.8 critical 27.5% 2017-09-13
CVE-2025-20188 A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco… Patch early 10.0 critical 27.5% 2025-05-07
CVE-2025-32011 KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get acce… Patch early 9.8 critical 27.5% 2025-05-01
CVE-2018-14714 System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" U… Patch early 9.8 critical 27.4% 2019-05-13
CVE-2025-52688 Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading… Patch early 9.8 critical 27.4% 2025-07-16
CVE-2020-11945 An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are… Patch early 9.8 critical 27.2% 2020-04-23
CVE-2017-11389 Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-f… Patch early 9.8 critical 27.2% 2017-08-02
CVE-2024-4323 A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and… Patch early 9.8 critical 27.2% 2024-05-20
CVE-2024-5765 The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX actio… Patch early 9.8 critical 27.2% 2024-07-30
CVE-2020-15906 tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. Patch early 9.8 critical 27.2% 2020-10-22
CVE-2016-2148 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involvi… Patch early 9.8 critical 27.1% 2017-02-09
CVE-2007-4559 Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attacker… Patch early 9.8 critical 27.1% 2007-08-28
CVE-2025-70161 EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the s… Patch early 9.8 critical 27.1% 2026-01-09
CVE-2022-37130 In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is m… Patch early 9.8 critical 26.9% 2022-08-31
CVE-2021-4119 bookstack is vulnerable to Improper Access Control Patch early 9.8 critical 26.9% 2021-12-15
CVE-2024-5452 A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialize… Patch early 9.8 critical 26.8% 2024-06-06
CVE-2022-35628 A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. Patch early 9.8 critical 26.8% 2022-07-12
CVE-2018-20148 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLR… Patch early 9.8 critical 26.8% 2018-12-14
CVE-2024-27172 Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL. Patch early 9.8 critical 26.8% 2024-06-14
CVE-2019-9827 Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host vi… Patch early 9.8 critical 26.8% 2019-07-03
CVE-2017-6403 An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username… Patch early 9.8 critical 26.7% 2017-03-02
CVE-2019-12256 Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of… Patch early 9.8 critical 26.6% 2019-08-09
CVE-2020-8840 FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiCo… Patch early 9.8 critical 26.6% 2020-02-10
CVE-2023-21689 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Patch early 9.8 critical 26.5% 2023-02-14
CVE-2025-11201 MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a… Patch early 9.8 critical 26.5% 2025-10-29
CVE-2016-0705 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remo… Patch early 9.8 critical 26.3% 2016-03-03
CVE-2020-24589 The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. Patch early 9.1 critical 26.3% 2020-08-21
CVE-2017-2805 An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially cr… Patch early 9.8 critical 26.2% 2017-06-21
← previous page 99 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt