CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,359 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-10-01
206,338 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1718 EXP | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers t… | Patch early | 6.8 medium | 9.5% | 2010-05-04 |
| CVE-2002-1178 EXP | Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (… | Patch early | 5.0 medium | 9.5% | 2002-10-11 |
| CVE-2008-3332 EXP | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the… | Patch early | 6.5 medium | 9.5% | 2008-07-27 |
| CVE-2000-0883 EXP | The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allo… | Patch early | 5.0 medium | 9.5% | 2000-11-14 |
| CVE-2012-6151 EXP | Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of s… | Patch early | 4.3 medium | 9.5% | 2013-12-13 |
| CVE-2010-2507 EXP | Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read a… | Patch early | 6.8 medium | 9.4% | 2010-06-28 |
| CVE-2006-6352 EXP | FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file… | Patch early | 5.0 medium | 9.4% | 2006-12-07 |
| CVE-2012-6050 EXP | The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router versi… | Patch early | 6.4 medium | 9.4% | 2012-11-27 |
| CVE-2017-11309 EXP | Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response. | Patch early | 9.6 critical | 9.4% | 2017-11-10 |
| CVE-2026-0926 EXP | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templa… | Patch early | 9.8 critical | 9.4% | 2026-02-19 |
| CVE-2010-3490 EXP | Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlie… | Patch early | 6.5 medium | 9.4% | 2010-09-28 |
| CVE-2007-1199 EXP | Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with <</URI(file://… | Patch early | 4.3 medium | 9.4% | 2007-03-02 |
| CVE-2019-1978 EXP | A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Fi… | Patch early | 5.8 medium | 9.4% | 2019-11-05 |
| CVE-2012-0981 EXP | Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r… | Patch early | 5.0 medium | 9.4% | 2012-02-02 |
| CVE-2010-1719 EXP | Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and… | Patch early | 6.8 medium | 9.4% | 2010-05-04 |
| CVE-2004-2565 EXP | Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP… | Patch early | 5.0 medium | 9.4% | 2004-12-31 |
| CVE-2006-2896 EXP | profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action. | Patch early | 5.0 medium | 9.4% | 2006-06-07 |
| CVE-2006-3735 EXP | Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP co… | Patch early | 5.1 medium | 9.4% | 2006-07-21 |
| CVE-2009-2535 EXP | Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpti… | Patch early | 5.0 medium | 9.4% | 2009-07-20 |
| CVE-2019-14280 EXP | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,… | Patch early | 5.3 medium | 9.4% | 2019-07-26 |
| CVE-2001-0784 EXP | Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack us… | Patch early | 5.0 medium | 9.4% | 2001-10-18 |
| CVE-2009-3840 EXP | The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a d… | Patch early | 5.0 medium | 9.3% | 2009-11-19 |
| CVE-2010-0519 EXP | Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicat… | Patch early | 6.8 medium | 9.3% | 2010-03-30 |
| CVE-2001-0009 EXP | Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. | Patch early | 5.0 medium | 9.3% | 2001-02-12 |
| CVE-2012-0298 EXP | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrar… | Patch early | 6.4 medium | 9.3% | 2012-05-21 |
| CVE-2004-0129 EXP | Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) seque… | Patch early | 5.0 medium | 9.3% | 2004-03-03 |
| CVE-2006-6493 EXP | Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable… | Patch early | 5.1 medium | 9.3% | 2006-12-13 |
| CVE-2011-5233 EXP | Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pi… | Patch early | 4.3 medium | 9.3% | 2012-10-25 |
| CVE-2018-9038 EXP | Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request. | Patch early | 6.5 medium | 9.3% | 2018-04-10 |
| CVE-2012-5878 EXP | Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in… | Patch early | 9.8 critical | 9.3% | 2020-01-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt