CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,226 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,228 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2067 EXP | Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary… | Patch early | 7.5 high | 8.4% | 2007-04-18 |
| CVE-2007-2569 EXP | Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 8.4% | 2007-05-09 |
| CVE-2012-0996 EXP | Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 8.4% | 2012-02-24 |
| CVE-2016-5063 EXP | The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization… | Patch early | 5.3 medium | 8.4% | 2017-05-02 |
| CVE-2000-0515 EXP | The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration o… | Patch early | 10.0 high | 8.4% | 2000-06-07 |
| CVE-2010-3128 EXP | Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code an… | Patch early | 9.3 high | 8.4% | 2010-08-26 |
| CVE-2010-3460 EXP | Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 8.4% | 2010-09-17 |
| CVE-2006-3353 EXP | Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to a… | Patch early | 5.0 medium | 8.4% | 2006-07-06 |
| CVE-2008-0069 EXP | Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in… | Patch early | 6.8 medium | 8.4% | 2008-04-02 |
| CVE-2000-0920 EXP | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) a… | Patch early | 5.0 medium | 8.4% | 2000-12-19 |
| CVE-2015-8357 EXP | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and… | Patch early | 6.5 medium | 8.4% | 2015-12-16 |
| CVE-2001-1586 EXP | Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%… | Patch early | 10.0 high | 8.4% | 2010-02-12 |
| CVE-2023-1545 EXP | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | Patch early | 7.5 high | 8.4% | 2023-03-21 |
| CVE-2012-3578 EXP | Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to ex… | Patch early | 6.8 medium | 8.4% | 2012-06-17 |
| CVE-2000-0405 EXP | Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet. | Patch early | 10.0 high | 8.4% | 2000-05-16 |
| CVE-2006-4900 EXP | Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated use… | Patch early | 5.5 medium | 8.3% | 2006-09-22 |
| CVE-2014-8393 EXP | DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | Patch early | 7.8 high | 8.3% | 2017-08-29 |
| CVE-2006-2152 EXP | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows… | Patch early | 7.5 high | 8.3% | 2006-05-03 |
| CVE-2002-0681 EXP | Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that gen… | Patch early | 7.5 high | 8.3% | 2002-07-23 |
| CVE-2017-11321 EXP | The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metach… | Patch early | 7.2 high | 8.3% | 2017-10-03 |
| CVE-2002-1004 EXP | Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-2001-0571 EXP | Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remot… | Patch early | 5.0 medium | 8.3% | 2001-08-22 |
| CVE-2000-1171 EXP | Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in… | Patch early | 5.0 medium | 8.3% | 2001-01-09 |
| CVE-2001-0360 EXP | Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) atta… | Patch early | 5.0 medium | 8.3% | 2001-06-27 |
| CVE-1999-1509 EXP | Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.3% | 1999-11-04 |
| CVE-2009-0649 EXP | The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls… | Patch early | 7.8 high | 8.3% | 2009-02-20 |
| CVE-2017-14087 EXP | A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attack… | Patch early | 7.5 high | 8.3% | 2017-10-06 |
| CVE-2008-2015 EXP | Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite ar… | Patch early | 9.3 high | 8.3% | 2008-04-30 |
| CVE-2007-1001 EXP | Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 t… | Patch early | 6.8 medium | 8.3% | 2007-04-06 |
| CVE-2012-0276 EXP | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 6.8 medium | 8.3% | 2012-07-17 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt