CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,157 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2004-1641 EXP | Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (… | Patch early | 5.0 medium | 8.2% | 2004-08-29 |
| CVE-2007-3955 EXP | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers t… | Patch early | 6.8 medium | 8.2% | 2007-07-24 |
| CVE-2021-34369 EXP | portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified… | Patch early | 6.5 medium | 8.2% | 2021-06-09 |
| CVE-2021-40964 EXP | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin cred… | Patch early | 6.5 medium | 8.2% | 2021-09-15 |
| CVE-2010-1315 EXP | Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla!… | Patch early | 5.0 medium | 8.2% | 2010-04-08 |
| CVE-2010-1461 EXP | Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 8.2% | 2010-04-16 |
| CVE-2010-1540 EXP | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 8.2% | 2010-04-26 |
| CVE-2009-2100 EXP | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbit… | Patch early | 5.0 medium | 8.2% | 2009-06-17 |
| CVE-2009-0879 EXP | The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a lon… | Patch early | 5.0 medium | 8.2% | 2009-03-12 |
| CVE-2016-10504 EXP | Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial o… | Patch early | 6.5 medium | 8.2% | 2017-08-30 |
| CVE-2007-4553 EXP | The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via… | Patch early | 5.0 medium | 8.2% | 2007-08-28 |
| CVE-2019-12252 EXP | In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the… | Patch early | 6.5 medium | 8.2% | 2019-05-21 |
| CVE-2013-6025 EXP | The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL s… | Patch early | 4.0 medium | 8.2% | 2013-10-19 |
| CVE-2010-1219 EXP | Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a ..… | Patch early | 6.8 medium | 8.2% | 2010-03-30 |
| CVE-2007-3883 EXP | The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in… | Patch early | 5.1 medium | 8.2% | 2007-07-18 |
| CVE-2009-1553 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbit… | Patch early | 4.3 medium | 8.2% | 2009-05-06 |
| CVE-2008-5314 EXP | Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via… | Patch early | 4.3 medium | 8.2% | 2008-12-03 |
| CVE-2014-0983 EXP | Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle Vi… | Patch early | 6.9 medium | 8.2% | 2014-03-31 |
| CVE-2001-1335 EXP | Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GE… | Patch early | 5.0 medium | 8.2% | 2001-05-27 |
| CVE-2007-3162 EXP | Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows rem… | Patch early | 5.0 medium | 8.2% | 2007-06-11 |
| CVE-2000-0444 EXP | HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000. | Patch early | 5.0 medium | 8.2% | 2000-05-24 |
| CVE-2007-1308 EXP | ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessin… | Patch early | 4.3 medium | 8.2% | 2007-03-07 |
| CVE-2000-1050 EXP | Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in… | Patch early | 5.0 medium | 8.2% | 2000-12-11 |
| CVE-2010-1715 EXP | Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to… | Patch early | 6.8 medium | 8.2% | 2010-05-04 |
| CVE-2010-1607 EXP | Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote att… | Patch early | 6.8 medium | 8.2% | 2010-04-29 |
| CVE-2015-5696 EXP | Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request. | Patch early | 5.0 medium | 8.2% | 2015-08-14 |
| CVE-2010-1147 EXP | Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary cod… | Patch early | 6.0 medium | 8.2% | 2010-04-06 |
| CVE-2010-1469 EXP | Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers… | Patch early | 6.8 medium | 8.2% | 2010-04-19 |
| CVE-2010-1478 EXP | Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arb… | Patch early | 6.8 medium | 8.2% | 2010-04-19 |
| CVE-2010-1473 EXP | Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 6.8 medium | 8.2% | 2010-04-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt