CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,105 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0571 EXP | Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remot… | Patch early | 5.0 medium | 8.3% | 2001-08-22 |
| CVE-2002-1004 EXP | Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-1999-1509 EXP | Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.3% | 1999-11-04 |
| CVE-2000-1171 EXP | Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in… | Patch early | 5.0 medium | 8.3% | 2001-01-09 |
| CVE-2001-0360 EXP | Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) atta… | Patch early | 5.0 medium | 8.3% | 2001-06-27 |
| CVE-2007-1001 EXP | Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 t… | Patch early | 6.8 medium | 8.3% | 2007-04-06 |
| CVE-2012-0276 EXP | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 6.8 medium | 8.3% | 2012-07-17 |
| CVE-2010-1930 EXP | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree par… | Patch early | 5.0 medium | 8.3% | 2010-06-28 |
| CVE-2005-3048 EXP | Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a… | Patch early | 6.4 medium | 8.3% | 2005-09-24 |
| CVE-2010-0278 EXP | A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allow… | Patch early | 4.3 medium | 8.3% | 2010-01-12 |
| CVE-2023-4114 EXP | A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing… | Patch early | 4.3 medium | 8.3% | 2023-08-03 |
| CVE-2005-0442 EXP | Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. | Patch early | 5.0 medium | 8.3% | 2005-05-02 |
| CVE-2009-2626 EXP | The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive… | Patch early | 6.4 medium | 8.3% | 2009-12-01 |
| CVE-2018-11415 EXP | SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indica… | Patch early | 6.1 medium | 8.3% | 2018-05-24 |
| CVE-2002-0893 EXP | Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-2002-0611 EXP | Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (… | Patch early | 5.0 medium | 8.3% | 2002-06-18 |
| CVE-2005-4212 EXP | Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) se… | Patch early | 5.0 medium | 8.3% | 2005-12-14 |
| CVE-2018-5753 EXP | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev… | Patch early | 6.5 medium | 8.3% | 2018-06-16 |
| CVE-2002-1451 EXP | Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (… | Patch early | 5.0 medium | 8.3% | 2002-08-24 |
| CVE-2008-3195 EXP | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote atta… | Patch early | 6.8 medium | 8.3% | 2008-09-18 |
| CVE-2005-3475 EXP | Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests. | Patch early | 5.0 medium | 8.3% | 2005-11-03 |
| CVE-2007-5299 EXP | Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow remote attackers to read arbitra… | Patch early | 5.0 medium | 8.3% | 2007-10-09 |
| CVE-2013-2218 EXP | Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to… | Patch early | 5.0 medium | 8.3% | 2013-09-30 |
| CVE-2012-0744 EXP | IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reques… | Patch early | 5.0 medium | 8.3% | 2012-08-17 |
| CVE-2012-0789 EXP | Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering… | Patch early | 5.0 medium | 8.3% | 2012-02-14 |
| CVE-2002-0775 EXP | browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | Patch early | 5.0 medium | 8.3% | 2002-08-12 |
| CVE-2015-4038 EXP | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_setti… | Patch early | 6.5 medium | 8.3% | 2015-06-03 |
| CVE-1999-0063 EXP | Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. | Patch early | 5.0 medium | 8.2% | 1999-01-11 |
| CVE-2004-2047 EXP | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 8.2% | 2004-07-23 |
| CVE-2002-0483 EXP | index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to… | Patch early | 5.0 medium | 8.2% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt