CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,554 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2016-1839 EXP | The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2… | Patch early | 5.5 medium | 7.3% | 2016-05-20 |
| CVE-2019-13237 EXP | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resource… | Patch early | 4.3 medium | 7.3% | 2019-08-27 |
| CVE-2010-2809 EXP | The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assist… | Patch early | 6.8 medium | 7.3% | 2010-08-19 |
| CVE-2008-1278 EXP | The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of serv… | Patch early | 5.0 medium | 7.3% | 2008-03-10 |
| CVE-2008-5280 EXP | The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer d… | Patch early | 5.0 medium | 7.3% | 2008-11-29 |
| CVE-2008-1218 EXP | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to byp… | Patch early | 6.8 medium | 7.3% | 2008-03-10 |
| CVE-2007-3151 EXP | rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device… | Patch early | 5.0 medium | 7.3% | 2007-06-11 |
| CVE-2004-0605 EXP | Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have… | Patch early | 5.0 medium | 7.3% | 2004-12-06 |
| CVE-2002-0300 EXP | gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly re… | Patch early | 5.0 medium | 7.3% | 2002-05-31 |
| CVE-2005-3811 EXP | Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arb… | Patch early | 5.0 medium | 7.3% | 2005-11-25 |
| CVE-2005-4086 EXP | Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier all… | Patch early | 5.0 medium | 7.3% | 2005-12-08 |
| CVE-2004-0287 EXP | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a lar… | Patch early | 5.0 medium | 7.3% | 2004-11-23 |
| CVE-2004-1385 EXP | phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shel… | Patch early | 5.0 medium | 7.3% | 2004-12-31 |
| CVE-2011-4640 EXP | Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (… | Patch early | 4.0 medium | 7.3% | 2012-10-08 |
| CVE-2014-3865 EXP | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directori… | Patch early | 6.4 medium | 7.3% | 2014-05-30 |
| CVE-2014-2588 EXP | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via… | Patch early | 4.0 medium | 7.3% | 2014-03-24 |
| CVE-2008-3292 EXP | constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cook… | Patch early | 6.4 medium | 7.3% | 2008-07-24 |
| CVE-2007-3140 EXP | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value i… | Patch early | 6.5 medium | 7.3% | 2007-06-08 |
| CVE-2001-0224 EXP | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. | Patch early | 5.0 medium | 7.3% | 2001-06-02 |
| CVE-2001-1115 EXP | generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter. | Patch early | 5.0 medium | 7.3% | 2001-08-13 |
| CVE-2014-9094 EXP | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress… | Patch early | 4.3 medium | 7.3% | 2014-11-26 |
| CVE-2019-19143 EXP | TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI. | Patch early | 6.1 medium | 7.3% | 2020-01-27 |
| CVE-2006-3082 EXP | parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly ov… | Patch early | 5.0 medium | 7.3% | 2006-06-19 |
| CVE-2006-2256 EXP | PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 6.4 medium | 7.3% | 2006-05-09 |
| CVE-2013-4097 EXP | ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reve… | Patch early | 5.0 medium | 7.3% | 2013-06-28 |
| CVE-2022-2941 EXP | The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due t… | Patch early | 5.5 medium | 7.3% | 2022-09-06 |
| CVE-2000-0234 EXP | The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file. | Patch early | 5.0 medium | 7.3% | 2000-03-31 |
| CVE-2000-0243 EXP | AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. | Patch early | 5.0 medium | 7.3% | 2000-03-25 |
| CVE-2000-0644 EXP | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. | Patch early | 5.0 medium | 7.3% | 2000-07-21 |
| CVE-2001-0558 EXP | T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS devic… | Patch early | 5.0 medium | 7.3% | 2001-08-14 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt