CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,286 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,280 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2010-1461 EXP | Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 8.2% | 2010-04-16 |
| CVE-2010-1540 EXP | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary file… | Patch early | 5.0 medium | 8.2% | 2010-04-26 |
| CVE-2005-0316 EXP | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which co… | Patch early | 7.5 high | 8.2% | 2005-01-28 |
| CVE-2009-2100 EXP | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbit… | Patch early | 5.0 medium | 8.2% | 2009-06-17 |
| CVE-2009-0879 EXP | The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a lon… | Patch early | 5.0 medium | 8.2% | 2009-03-12 |
| CVE-2016-10504 EXP | Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial o… | Patch early | 6.5 medium | 8.2% | 2017-08-30 |
| CVE-2009-4251 EXP | Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via… | Patch early | 9.3 high | 8.2% | 2009-12-10 |
| CVE-2007-4907 EXP | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter… | Patch early | 7.5 high | 8.2% | 2007-09-17 |
| CVE-2007-4553 EXP | The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via… | Patch early | 5.0 medium | 8.2% | 2007-08-28 |
| CVE-2019-12252 EXP | In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the… | Patch early | 6.5 medium | 8.2% | 2019-05-21 |
| CVE-2019-17080 EXP | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickl… | Patch early | 7.8 high | 8.2% | 2019-10-02 |
| CVE-2007-2274 EXP | The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malforme… | Patch early | 7.8 high | 8.2% | 2007-04-25 |
| CVE-2007-2372 EXP | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentia… | Patch early | 10.0 high | 8.2% | 2007-04-30 |
| CVE-2013-6025 EXP | The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL s… | Patch early | 4.0 medium | 8.2% | 2013-10-19 |
| CVE-2010-1219 EXP | Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a ..… | Patch early | 6.8 medium | 8.2% | 2010-03-30 |
| CVE-2007-3883 EXP | The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in… | Patch early | 5.1 medium | 8.2% | 2007-07-18 |
| CVE-2009-1553 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbit… | Patch early | 4.3 medium | 8.2% | 2009-05-06 |
| CVE-2008-5314 EXP | Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via… | Patch early | 4.3 medium | 8.2% | 2008-12-03 |
| CVE-2017-11398 EXP | A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthe… | Patch early | 8.8 high | 8.2% | 2018-01-19 |
| CVE-2018-14336 EXP | TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses. | Patch early | 7.5 high | 8.2% | 2018-07-19 |
| CVE-2009-3625 EXP | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (do… | Patch early | 7.5 high | 8.2% | 2009-10-26 |
| CVE-2001-1335 EXP | Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GE… | Patch early | 5.0 medium | 8.2% | 2001-05-27 |
| CVE-2007-3162 EXP | Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows rem… | Patch early | 5.0 medium | 8.2% | 2007-06-11 |
| CVE-2000-0444 EXP | HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000. | Patch early | 5.0 medium | 8.2% | 2000-05-24 |
| CVE-2012-4354 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2012-4355 EXP | TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary c… | Patch early | 9.3 high | 8.2% | 2012-08-19 |
| CVE-2004-1118 EXP | Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.… | Patch early | 10.0 high | 8.2% | 2005-01-10 |
| CVE-2019-16645 EXP | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostnam… | Patch early | 8.6 high | 8.2% | 2019-09-20 |
| CVE-2007-2608 EXP | PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to execute arbitrary PHP code via… | Patch early | 7.5 high | 8.2% | 2007-05-11 |
| CVE-2000-1050 EXP | Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in… | Patch early | 5.0 medium | 8.2% | 2000-12-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt