CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
402,899 CVEs
1,734 on KEV
17,293 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
320,990 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-9181 EXP | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 9.5% | 2014-12-02 |
| CVE-2005-4557 EXP | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attacker… | Patch early | 5.0 medium | 9.5% | 2005-12-28 |
| CVE-2020-5811 EXP | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary f… | Patch early | 6.5 medium | 9.5% | 2020-12-30 |
| CVE-2015-2862 EXP | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1… | Patch early | 4.0 medium | 9.5% | 2015-07-20 |
| CVE-2005-1532 EXP | Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, whi… | Patch early | 7.5 high | 9.5% | 2005-05-12 |
| CVE-2010-3676 EXP | storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertio… | Patch early | 4.0 medium | 9.5% | 2011-01-11 |
| CVE-2010-1474 EXP | Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files… | Patch early | 6.8 medium | 9.5% | 2010-04-19 |
| CVE-2010-1475 EXP | Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitra… | Patch early | 6.8 medium | 9.5% | 2010-04-19 |
| CVE-2010-1722 EXP | Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and poss… | Patch early | 6.8 medium | 9.5% | 2010-05-04 |
| CVE-2005-3934 EXP | Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application… | Patch early | 7.8 high | 9.5% | 2005-12-01 |
| CVE-2006-3879 EXP | Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial o… | Patch early | 5.0 medium | 9.5% | 2006-07-27 |
| CVE-2006-3192 EXP | PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath paramet… | Patch early | 7.5 high | 9.5% | 2006-06-23 |
| CVE-2007-2456 EXP | Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root pa… | Patch early | 7.5 high | 9.5% | 2007-05-02 |
| CVE-2015-7259 EXP | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, w… | Patch early | 8.8 high | 9.5% | 2017-08-24 |
| CVE-2010-1718 EXP | Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers t… | Patch early | 6.8 medium | 9.5% | 2010-05-04 |
| CVE-2002-1178 EXP | Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (… | Patch early | 5.0 medium | 9.5% | 2002-10-11 |
| CVE-2008-3332 EXP | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the… | Patch early | 6.5 medium | 9.5% | 2008-07-27 |
| CVE-2000-0883 EXP | The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allo… | Patch early | 5.0 medium | 9.5% | 2000-11-14 |
| CVE-2012-6151 EXP | Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of s… | Patch early | 4.3 medium | 9.5% | 2013-12-13 |
| CVE-1999-0926 EXP | Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. | Patch early | 10.0 high | 9.4% | 1999-09-03 |
| CVE-2002-0068 EXP | Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL… | Patch early | 7.5 high | 9.4% | 2002-03-08 |
| CVE-2005-0838 EXP | Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via… | Patch early | 7.5 high | 9.4% | 2005-05-02 |
| CVE-1999-0266 EXP | The info2www CGI script allows remote file access or remote command execution. | Patch early | 7.5 high | 9.4% | 1998-03-01 |
| CVE-2007-4586 EXP | Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary… | Patch early | 7.5 high | 9.4% | 2007-08-29 |
| CVE-2013-5948 EXP | The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows rem… | Patch early | 8.5 high | 9.4% | 2014-04-22 |
| CVE-2007-2428 EXP | Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1… | Patch early | 7.5 high | 9.4% | 2007-05-02 |
| CVE-2000-0011 EXP | Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. | Patch early | 7.5 high | 9.4% | 1999-12-31 |
| CVE-2009-3850 EXP | Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad… | Patch early | 9.3 high | 9.4% | 2009-11-06 |
| CVE-2010-4233 EXP | The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default passwo… | Patch early | 10.0 high | 9.4% | 2010-11-17 |
| CVE-2015-3203 EXP | Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable… | Patch early | 7.5 high | 9.4% | 2015-09-28 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt