CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,529 CVEs
1,726 on KEV
17,265 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-27
169,004 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-16133 EXP | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | Patch early | 5.3 medium | 39.3% | 2018-08-29 |
| CVE-2017-14537 EXP | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.p… | Patch early | 6.5 medium | 39.3% | 2018-02-16 |
| CVE-2014-2383 EXP | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitra… | Patch early | 6.8 medium | 39.2% | 2014-04-28 |
| CVE-2006-4301 EXP | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media… | Patch early | 5.0 medium | 39.1% | 2006-08-23 |
| CVE-2009-3641 EXP | Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packe… | Patch early | 4.3 medium | 38.8% | 2009-10-28 |
| CVE-2018-8716 EXP | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | Patch early | 5.4 medium | 38.7% | 2018-04-25 |
| CVE-2013-5093 EXP | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows… | Patch early | 6.8 medium | 38.7% | 2013-09-27 |
| CVE-2015-7309 EXP | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitr… | Patch early | 6.5 medium | 38.6% | 2015-09-22 |
| CVE-2007-5315 EXP | PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitra… | Patch early | 6.8 medium | 38.6% | 2007-10-09 |
| CVE-2007-5781 EXP | PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PA… | Patch early | 6.8 medium | 38.6% | 2007-11-01 |
| CVE-2007-5102 EXP | PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute a… | Patch early | 6.8 medium | 38.6% | 2007-09-26 |
| CVE-2007-5015 EXP | Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a… | Patch early | 6.8 medium | 38.6% | 2007-09-20 |
| CVE-2014-8598 EXP | The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the impor… | Patch early | 6.4 medium | 38.5% | 2014-11-18 |
| CVE-2012-6636 EXP | The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary met… | Patch early | 6.8 medium | 38.5% | 2014-03-03 |
| CVE-2001-1501 EXP | The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption)… | Patch early | 5.0 medium | 38.4% | 2001-12-31 |
| CVE-2007-4906 EXP | PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attacker… | Patch early | 6.8 medium | 38.4% | 2007-09-17 |
| CVE-2007-5388 EXP | Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app par… | Patch early | 6.8 medium | 38.4% | 2007-10-12 |
| CVE-2006-1518 EXP | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via craft… | Patch early | 6.5 medium | 38.4% | 2006-05-05 |
| CVE-2018-7286 EXP | An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjs… | Patch early | 6.5 medium | 38.3% | 2018-02-22 |
| CVE-2002-0419 EXP | Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks v… | Patch early | 5.0 medium | 38.2% | 2002-08-12 |
| CVE-2007-6514 EXP | Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed c… | Patch early | 4.3 medium | 38% | 2007-12-21 |
| CVE-2002-0325 EXP | Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | Patch early | 5.0 medium | 37.8% | 2002-06-25 |
| CVE-2007-1683 EXP | Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to… | Patch early | 6.8 medium | 37.7% | 2007-04-26 |
| CVE-2002-1561 EXP | The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a ma… | Patch early | 5.0 medium | 37.7% | 2003-04-02 |
| CVE-2008-1416 EXP | Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the includ… | Patch early | 6.8 medium | 37.7% | 2008-03-20 |
| CVE-2008-1405 EXP | PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 37.7% | 2008-03-20 |
| CVE-2008-6829 EXP | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, f… | Patch early | 5.0 medium | 37.6% | 2009-06-08 |
| CVE-2007-5457 EXP | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for… | Patch early | 6.8 medium | 37.6% | 2007-10-14 |
| CVE-2007-5412 EXP | Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to… | Patch early | 6.8 medium | 37.5% | 2007-10-12 |
| CVE-2007-5843 EXP | PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.8 medium | 37.5% | 2007-11-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt