CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
401,061 CVEs
1,733 on KEV
17,290 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-03
206,641 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3447 EXP | The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, p… | Patch early | 5.0 medium | 7.9% | 2008-08-04 |
| CVE-2000-0664 EXP | AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL enc… | Patch early | 5.0 medium | 7.9% | 2000-07-26 |
| CVE-2020-27422 EXP | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link t… | Patch early | 9.8 critical | 7.9% | 2020-11-16 |
| CVE-2014-3004 EXP | The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) att… | Patch early | 4.3 medium | 7.9% | 2014-06-11 |
| CVE-2013-5696 EXP | inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows… | Patch early | 6.8 medium | 7.9% | 2013-09-23 |
| CVE-2006-0701 EXP | readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. | Patch early | 5.0 medium | 7.9% | 2006-02-15 |
| CVE-2018-7653 EXP | In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | Patch early | 6.1 medium | 7.9% | 2018-03-04 |
| CVE-2006-2059 EXP | action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a sea… | Patch early | 5.0 medium | 7.9% | 2006-04-26 |
| CVE-2000-0634 EXP | The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.9% | 2000-04-03 |
| CVE-2000-0925 EXP | The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, whic… | Patch early | 5.0 medium | 7.9% | 2000-12-19 |
| CVE-2000-1181 EXP | Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive inform… | Patch early | 5.0 medium | 7.9% | 2001-01-09 |
| CVE-2002-0107 EXP | Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET reque… | Patch early | 5.0 medium | 7.9% | 2002-03-25 |
| CVE-1999-1050 EXP | Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the… | Patch early | 5.0 medium | 7.9% | 1999-11-12 |
| CVE-2000-0924 EXP | Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) a… | Patch early | 5.0 medium | 7.9% | 2000-12-19 |
| CVE-2003-0290 EXP | Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is… | Patch early | 5.0 medium | 7.8% | 2003-06-16 |
| CVE-2020-10387 EXP | Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-d… | Patch early | 4.9 medium | 7.8% | 2020-03-12 |
| CVE-2013-1806 EXP | Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via… | Patch early | 6.5 medium | 7.8% | 2014-04-30 |
| CVE-2006-2330 EXP | PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary… | Patch early | 6.4 medium | 7.8% | 2006-05-12 |
| CVE-2007-1362 EXP | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via… | Patch early | 4.3 medium | 7.8% | 2007-06-01 |
| CVE-2007-2425 EXP | Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album par… | Patch early | 5.0 medium | 7.8% | 2007-05-02 |
| CVE-2007-2611 EXP | Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code via a URL in the pathCGX param… | Patch early | 6.8 medium | 7.8% | 2007-05-11 |
| CVE-2005-3293 EXP | Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a… | Patch early | 5.0 medium | 7.8% | 2005-10-23 |
| CVE-2008-1488 EXP | Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long… | Patch early | 6.8 medium | 7.8% | 2008-03-24 |
| CVE-2022-34128 EXP | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. | Patch early | 9.8 critical | 7.8% | 2023-04-16 |
| CVE-2009-2478 EXP | Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, rel… | Patch early | 5.0 medium | 7.8% | 2009-07-16 |
| CVE-2017-6805 EXP | Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a .. (dot d… | Patch early | 5.3 medium | 7.8% | 2017-03-20 |
| CVE-2009-1353 EXP | Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon cr… | Patch early | 5.0 medium | 7.8% | 2009-04-21 |
| CVE-2005-2719 EXP | Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than… | Patch early | 5.0 medium | 7.8% | 2005-08-30 |
| CVE-2004-0285 EXP | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers t… | Patch early | 9.8 critical | 7.8% | 2004-11-23 |
| CVE-2008-6713 EXP | World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block… | Patch early | 5.0 medium | 7.8% | 2009-04-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt