CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,957 CVEs
1,734 on KEV
17,295 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-06
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5618 EXP | Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in… | Patch early | 5.0 medium | 2.9% | 2006-10-31 |
| CVE-2006-6781 EXP | HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[… | Patch early | 5.0 medium | 2.9% | 2006-12-28 |
| CVE-2006-5789 EXP | War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1)… | Patch early | 4.0 medium | 2.9% | 2006-11-07 |
| CVE-2008-0438 EXP | Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 2.9% | 2008-01-23 |
| CVE-2012-0865 EXP | Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phis… | Patch early | 5.8 medium | 2.9% | 2012-02-21 |
| CVE-2018-0975 EXP | An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel… | Patch early | 5.5 medium | 2.9% | 2018-04-12 |
| CVE-2022-47880 EXP | An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify datab… | Patch early | 5.3 medium | 2.9% | 2023-05-12 |
| CVE-2005-3579 EXP | ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring. | Patch early | 5.0 medium | 2.9% | 2005-11-16 |
| CVE-2011-4712 EXP | Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request. | Patch early | 5.0 medium | 2.9% | 2011-12-08 |
| CVE-2012-3350 EXP | SQL injection vulnerability in index.php in Webmatic 3.1.1 allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. | Patch early | 6.8 medium | 2.9% | 2012-07-12 |
| CVE-2005-1893 EXP | FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in… | Patch early | 5.0 medium | 2.9% | 2005-06-09 |
| CVE-2007-0329 EXP | download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as d… | Patch early | 5.0 medium | 2.9% | 2007-01-18 |
| CVE-2006-5784 EXP | Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read… | Patch early | 4.6 medium | 2.9% | 2006-11-07 |
| CVE-2018-1002002 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.9% | 2018-12-03 |
| CVE-2018-1002003 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.9% | 2018-12-03 |
| CVE-2018-1002004 EXP | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileg… | Patch early | 4.8 medium | 2.9% | 2018-12-03 |
| CVE-2006-1205 EXP | Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 2.9% | 2006-03-14 |
| CVE-2009-2397 EXP | Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal s… | Patch early | 5.0 medium | 2.9% | 2009-07-09 |
| CVE-2009-3425 EXP | Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via direc… | Patch early | 5.0 medium | 2.9% | 2009-09-25 |
| CVE-2009-4726 EXP | Directory traversal vulnerability in download.php in Quickdev 4 PHP allows remote attackers to read arbitrary files via a .. (dot dot) in the file par… | Patch early | 5.0 medium | 2.9% | 2010-03-18 |
| CVE-2009-4978 EXP | Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename par… | Patch early | 5.0 medium | 2.9% | 2010-08-25 |
| CVE-2015-4072 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web… | Patch early | 5.4 medium | 2.9% | 2017-09-20 |
| CVE-2006-5510 EXP | Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." seq… | Patch early | 6.4 medium | 2.9% | 2006-10-25 |
| CVE-2008-0435 EXP | Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 2.9% | 2008-01-23 |
| CVE-2008-1400 EXP | Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote… | Patch early | 5.0 medium | 2.9% | 2008-03-20 |
| CVE-2008-1730 EXP | Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as o… | Patch early | 5.0 medium | 2.9% | 2008-04-11 |
| CVE-2008-3675 EXP | Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and pos… | Patch early | 5.0 medium | 2.9% | 2008-08-14 |
| CVE-2008-4151 EXP | Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl paramet… | Patch early | 5.0 medium | 2.9% | 2008-09-24 |
| CVE-2008-1541 EXP | Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 4.3 medium | 2.9% | 2008-03-28 |
| CVE-2002-2404 EXP | Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 por… | Patch early | 5.0 medium | 2.9% | 2002-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt