CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,891 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2145 EXP | Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded sp… | Patch early | 7.5 high | 7.7% | 2002-12-31 |
| CVE-2014-7910 EXP | Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 7.5 high | 7.7% | 2014-11-19 |
| CVE-1999-0800 EXP | The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. | Patch early | 5.0 medium | 7.7% | 2001-03-12 |
| CVE-2000-0240 EXP | vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack. | Patch early | 5.0 medium | 7.7% | 2000-03-21 |
| CVE-2000-0782 EXP | netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.7% | 2000-10-20 |
| CVE-2000-0930 EXP | Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. | Patch early | 5.0 medium | 7.7% | 2000-12-19 |
| CVE-2006-0881 EXP | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attac… | Patch early | 7.5 high | 7.7% | 2006-02-24 |
| CVE-2011-4336 EXP | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | Patch early | 6.1 medium | 7.7% | 2020-01-15 |
| CVE-2005-0229 EXP | CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card informati… | Patch early | 5.0 medium | 7.7% | 2005-04-27 |
| CVE-2012-5907 EXP | Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 7.7% | 2012-11-17 |
| CVE-2013-2619 EXP | Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI. | Patch early | 5.0 medium | 7.7% | 2014-03-18 |
| CVE-2014-10010 EXP | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id… | Patch early | 5.0 medium | 7.7% | 2015-01-13 |
| CVE-2014-3806 EXP | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 7.7% | 2014-05-21 |
| CVE-2002-2400 EXP | Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute… | Patch early | 10.0 high | 7.7% | 2002-12-31 |
| CVE-2014-3085 EXP | systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arb… | Patch early | 7.1 high | 7.6% | 2014-08-17 |
| CVE-2011-4162 EXP | The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Devi… | Patch early | 7.5 high | 7.6% | 2011-12-05 |
| CVE-2015-0514 EXP | EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by l… | Patch early | 5.0 medium | 7.6% | 2015-01-21 |
| CVE-2007-3606 EXP | Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote atta… | Patch early | 7.6 high | 7.6% | 2007-07-06 |
| CVE-2019-10273 EXP | Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active u… | Patch early | 4.3 medium | 7.6% | 2019-04-04 |
| CVE-2003-1181 EXP | Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function. | Patch early | 5.0 medium | 7.6% | 2003-10-25 |
| CVE-2009-3749 EXP | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remo… | Patch early | 5.0 medium | 7.6% | 2009-10-22 |
| CVE-2002-1581 EXP | Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot do… | Patch early | 5.0 medium | 7.6% | 2004-12-06 |
| CVE-2004-1696 EXP | EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage return… | Patch early | 5.0 medium | 7.6% | 2004-09-21 |
| CVE-2012-0937 EXP | wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MyS… | Patch early | 5.0 medium | 7.6% | 2012-01-30 |
| CVE-2009-5067 EXP | Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI… | Patch early | 4.3 medium | 7.6% | 2012-10-10 |
| CVE-2002-0948 EXP | Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as t… | Patch early | 7.5 high | 7.6% | 2002-10-04 |
| CVE-2006-4424 EXP | PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the… | Patch early | 5.1 medium | 7.6% | 2006-08-29 |
| CVE-2015-6401 EXP | Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecif… | Patch early | 7.5 high | 7.6% | 2015-12-14 |
| CVE-2006-2480 EXP | Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tri… | Patch early | 5.1 medium | 7.6% | 2006-05-19 |
| CVE-2011-2963 EXP | TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to… | Patch early | 10.0 high | 7.6% | 2011-07-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt