CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
10,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-1828 EXP | Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. | Patch early | 5.0 medium | 6.9% | 2002-12-31 |
| CVE-2005-0788 EXP | LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. | Patch early | 5.0 medium | 6.9% | 2005-03-14 |
| CVE-2006-0319 EXP | Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via "..… | Patch early | 5.0 medium | 6.9% | 2006-01-19 |
| CVE-2006-3556 EXP | PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 6.9% | 2006-07-13 |
| CVE-2018-5715 EXP | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | Patch early | 6.1 medium | 6.9% | 2018-01-16 |
| CVE-2018-4240 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 6.5 medium | 6.9% | 2018-06-08 |
| CVE-2000-0780 EXP | The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 2000-10-20 |
| CVE-2016-1594 EXP | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as dem… | Patch early | 6.5 medium | 6.9% | 2016-04-22 |
| CVE-2018-13980 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser… | Patch early | 5.5 medium | 6.9% | 2018-07-16 |
| CVE-2006-0658 EXP | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload an… | Patch early | 5.0 medium | 6.9% | 2006-02-13 |
| CVE-1999-0174 EXP | The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 1997-02-01 |
| CVE-2011-2201 EXP | The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of d… | Patch early | 4.3 medium | 6.9% | 2011-09-14 |
| CVE-2016-8017 EXP | Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers… | Patch early | 4.1 medium | 6.9% | 2017-03-14 |
| CVE-2014-3975 EXP | Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir… | Patch early | 5.0 medium | 6.9% | 2014-06-05 |
| CVE-2014-9436 EXP | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes)… | Patch early | 5.0 medium | 6.9% | 2015-01-02 |
| CVE-2008-6280 EXP | Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the ac… | Patch early | 4.3 medium | 6.9% | 2009-02-25 |
| CVE-2012-0550 EXP | Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote at… | Patch early | 6.8 medium | 6.9% | 2012-05-03 |
| CVE-2008-4048 EXP | Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot… | Patch early | 6.8 medium | 6.9% | 2008-09-11 |
| CVE-2008-4729 EXP | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows re… | Patch early | 6.8 medium | 6.9% | 2008-10-24 |
| CVE-2010-0315 EXP | WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a sp… | Patch early | 5.0 medium | 6.9% | 2010-01-14 |
| CVE-2006-4858 EXP | PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remo… | Patch early | 6.8 medium | 6.9% | 2006-09-19 |
| CVE-2010-0166 EXP | The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when t… | Patch early | 5.1 medium | 6.9% | 2010-03-25 |
| CVE-2013-4093 EXP | The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information vi… | Patch early | 5.0 medium | 6.9% | 2013-06-28 |
| CVE-2005-0731 EXP | PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Fi… | Patch early | 5.0 medium | 6.9% | 2005-03-10 |
| CVE-2004-1381 EXP | Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported… | Patch early | 5.0 medium | 6.9% | 2004-10-20 |
| CVE-2014-8604 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which a… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2014-8605 EXP | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient… | Patch early | 5.0 medium | 6.9% | 2015-06-10 |
| CVE-2016-0075 EXP | The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain p… | Patch early | 5.5 medium | 6.9% | 2016-10-14 |
| CVE-2016-5309 EXP | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;… | Patch early | 5.5 medium | 6.9% | 2017-04-14 |
| CVE-2006-6808 EXP | Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 6.8 medium | 6.9% | 2006-12-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt