CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,556 CVEs
1,734 on KEV
17,294 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-07
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-2946 EXP | Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username… | Patch early | 5.0 medium | 2.8% | 2006-06-12 |
| CVE-2009-4700 EXP | Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout para… | Patch early | 5.0 medium | 2.8% | 2010-03-15 |
| CVE-2009-0640 EXP | Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (d… | Patch early | 5.0 medium | 2.8% | 2009-02-20 |
| CVE-2007-2184 EXP | Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc p… | Patch early | 5.0 medium | 2.8% | 2007-04-24 |
| CVE-2016-9316 EXP | Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Secu… | Patch early | 5.4 medium | 2.8% | 2017-02-21 |
| CVE-2007-1224 EXP | Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the dest… | Patch early | 5.0 medium | 2.8% | 2007-03-02 |
| CVE-2008-7015 EXP | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of s… | Patch early | 5.0 medium | 2.8% | 2009-08-19 |
| CVE-2013-5058 EXP | Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a… | Patch early | 6.9 medium | 2.8% | 2013-12-11 |
| CVE-2006-1162 EXP | Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in t… | Patch early | 5.1 medium | 2.8% | 2006-03-12 |
| CVE-2006-4979 EXP | Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arb… | Patch early | 5.0 medium | 2.8% | 2006-09-25 |
| CVE-2012-5243 EXP | functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request. | Patch early | 5.0 medium | 2.8% | 2014-10-21 |
| CVE-2005-0506 EXP | The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows loc… | Patch early | 5.0 medium | 2.8% | 2005-03-14 |
| CVE-2008-5209 EXP | Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 2.8% | 2008-11-24 |
| CVE-2009-1602 EXP | Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via mul… | Patch early | 5.0 medium | 2.8% | 2009-05-11 |
| CVE-2007-3159 EXP | http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Lengt… | Patch early | 5.0 medium | 2.8% | 2007-06-11 |
| CVE-2014-8775 EXP | MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote a… | Patch early | 5.0 medium | 2.8% | 2014-12-03 |
| CVE-2015-5075 EXP | Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators fo… | Patch early | 6.8 medium | 2.8% | 2015-09-29 |
| CVE-2007-2252 EXP | Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information v… | Patch early | 5.0 medium | 2.8% | 2007-04-25 |
| CVE-2018-0895 EXP | The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold… | Patch early | 4.7 medium | 2.8% | 2018-03-14 |
| CVE-2006-2397 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 5.8 medium | 2.8% | 2006-05-16 |
| CVE-2008-0703 EXP | Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or… | Patch early | 5.0 medium | 2.8% | 2008-02-12 |
| CVE-2008-1415 EXP | Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../.… | Patch early | 5.0 medium | 2.8% | 2008-03-20 |
| CVE-2008-4759 EXP | Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the i… | Patch early | 5.0 medium | 2.8% | 2008-10-28 |
| CVE-2008-7084 EXP | Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 2.8% | 2009-08-26 |
| CVE-2009-4809 EXP | Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 2.8% | 2010-04-23 |
| CVE-2010-2848 EXP | Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for… | Patch early | 5.0 medium | 2.8% | 2010-07-25 |
| CVE-2008-3676 EXP | Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion… | Patch early | 4.3 medium | 2.8% | 2008-08-14 |
| CVE-2013-5757 EXP | Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in… | Patch early | 4.0 medium | 2.8% | 2014-08-03 |
| CVE-2006-3602 EXP | Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files vi… | Patch early | 5.0 medium | 2.8% | 2006-07-18 |
| CVE-2004-2017 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web scrip… | Patch early | 4.3 medium | 2.8% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt