CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,295 CVEs
1,734 on KEV
17,292 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-05
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-0465 EXP | Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files pa… | Patch early | 5.0 medium | 3.4% | 2008-01-25 |
| CVE-2020-13152 EXP | A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Am… | Patch early | 5.5 medium | 3.4% | 2020-05-20 |
| CVE-2011-3852 EXP | Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3855 EXP | Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3859 EXP | Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-3863 EXP | Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 3.4% | 2011-09-28 |
| CVE-2011-4713 EXP | Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot… | Patch early | 5.0 medium | 3.4% | 2011-12-08 |
| CVE-2006-3972 EXP | Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arb… | Patch early | 5.0 medium | 3.4% | 2006-08-02 |
| CVE-2014-9241 EXP | Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 3.4% | 2014-12-03 |
| CVE-2008-6702 EXP | S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which trigger… | Patch early | 5.0 medium | 3.4% | 2009-04-10 |
| CVE-1999-0416 EXP | Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port. | Patch early | 5.0 medium | 3.4% | 1999-03-11 |
| CVE-2004-0302 EXP | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.ph… | Patch early | 5.0 medium | 3.4% | 2004-11-23 |
| CVE-2005-3789 EXP | Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang p… | Patch early | 5.0 medium | 3.4% | 2005-11-24 |
| CVE-2005-4202 EXP | Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (tr… | Patch early | 5.0 medium | 3.4% | 2005-12-13 |
| CVE-2017-8470 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… | Patch early | 5.0 medium | 3.4% | 2017-06-15 |
| CVE-2017-8472 EXP | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allow an authenticated attacker to run a specially crafted applic… | Patch early | 5.0 medium | 3.4% | 2017-06-15 |
| CVE-2017-8476 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.4% | 2017-06-15 |
| CVE-2017-8480 EXP | The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… | Patch early | 5.0 medium | 3.4% | 2017-06-15 |
| CVE-2002-1897 EXP | MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer o… | Patch early | 5.0 medium | 3.4% | 2002-12-31 |
| CVE-2007-5417 EXP | Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) i… | Patch early | 5.0 medium | 3.4% | 2007-10-12 |
| CVE-2006-3989 EXP | PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code v… | Patch early | 5.1 medium | 3.4% | 2006-08-05 |
| CVE-2006-4053 EXP | PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a… | Patch early | 5.1 medium | 3.4% | 2006-08-10 |
| CVE-2006-4242 EXP | PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary… | Patch early | 5.1 medium | 3.4% | 2006-08-21 |
| CVE-2019-6208 EXP | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A mal… | Patch early | 5.5 medium | 3.4% | 2019-03-05 |
| CVE-2006-3929 EXP | Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allow… | Patch early | 4.3 medium | 3.4% | 2006-07-31 |
| CVE-2018-5407 EXP | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att… | Patch early | 4.7 medium | 3.4% | 2018-11-15 |
| CVE-2017-15878 EXP | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us featur… | Patch early | 6.1 medium | 3.4% | 2017-10-24 |
| CVE-2001-0250 EXP | The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server ro… | Patch early | 5.0 medium | 3.4% | 2001-06-02 |
| CVE-2006-6696 EXP | Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with… | Patch early | 6.9 medium | 3.4% | 2006-12-22 |
| CVE-2000-0708 EXP | Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null charact… | Patch early | 5.0 medium | 3.4% | 2000-10-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt