CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,929 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-0513 EXP | Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to re… | Patch early | 5.0 medium | 9.5% | 2006-02-06 |
| CVE-2007-4504 EXP | Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read ar… | Patch early | 5.0 medium | 9.5% | 2007-08-23 |
| CVE-2010-3847 EXP | elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGI… | Patch early | 6.9 medium | 9.5% | 2011-01-07 |
| CVE-2014-9181 EXP | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 9.5% | 2014-12-02 |
| CVE-2009-2109 EXP | Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (… | Patch early | 5.0 medium | 9.5% | 2009-06-18 |
| CVE-2005-4557 EXP | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attacker… | Patch early | 5.0 medium | 9.5% | 2005-12-28 |
| CVE-2020-5811 EXP | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary f… | Patch early | 6.5 medium | 9.5% | 2020-12-30 |
| CVE-2015-2862 EXP | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1… | Patch early | 4.0 medium | 9.5% | 2015-07-20 |
| CVE-2010-3676 EXP | storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertio… | Patch early | 4.0 medium | 9.5% | 2011-01-11 |
| CVE-2010-1475 EXP | Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitra… | Patch early | 6.8 medium | 9.5% | 2010-04-19 |
| CVE-2010-1722 EXP | Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and poss… | Patch early | 6.8 medium | 9.5% | 2010-05-04 |
| CVE-2010-1474 EXP | Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files… | Patch early | 6.8 medium | 9.5% | 2010-04-19 |
| CVE-2006-3879 EXP | Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial o… | Patch early | 5.0 medium | 9.5% | 2006-07-27 |
| CVE-2010-1718 EXP | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers t… | Patch early | 6.8 medium | 9.5% | 2010-05-04 |
| CVE-2002-1178 EXP | Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (… | Patch early | 5.0 medium | 9.5% | 2002-10-11 |
| CVE-2008-3332 EXP | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the… | Patch early | 6.5 medium | 9.5% | 2008-07-27 |
| CVE-2000-0883 EXP | The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allo… | Patch early | 5.0 medium | 9.5% | 2000-11-14 |
| CVE-2012-6151 EXP | Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of s… | Patch early | 4.3 medium | 9.5% | 2013-12-13 |
| CVE-2010-2507 EXP | Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read a… | Patch early | 6.8 medium | 9.4% | 2010-06-28 |
| CVE-2006-6352 EXP | FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file… | Patch early | 5.0 medium | 9.4% | 2006-12-07 |
| CVE-2012-6050 EXP | The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router versi… | Patch early | 6.4 medium | 9.4% | 2012-11-27 |
| CVE-2010-3490 EXP | Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlie… | Patch early | 6.5 medium | 9.4% | 2010-09-28 |
| CVE-2007-1199 EXP | Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file://… | Patch early | 4.3 medium | 9.4% | 2007-03-02 |
| CVE-2019-1978 EXP | A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Fi… | Patch early | 5.8 medium | 9.4% | 2019-11-05 |
| CVE-2012-0981 EXP | Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r… | Patch early | 5.0 medium | 9.4% | 2012-02-02 |
| CVE-2010-1719 EXP | Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 6.8 medium | 9.4% | 2010-05-04 |
| CVE-2010-1130 EXP | session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the sessio… | Patch early | 5.0 medium | 9.4% | 2010-03-26 |
| CVE-2004-2565 EXP | Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP… | Patch early | 5.0 medium | 9.4% | 2004-12-31 |
| CVE-2006-2896 EXP | profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. | Patch early | 5.0 medium | 9.4% | 2006-06-07 |
| CVE-2006-3735 EXP | Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP co… | Patch early | 5.1 medium | 9.4% | 2006-07-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt