CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,373 CVEs
1,739 on KEV
17,298 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-08
321,352 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-0197 EXP | Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a lo… | Patch early | 6.8 medium | 8.1% | 2007-01-11 |
| CVE-2013-4984 EXP | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… | Patch early | 7.2 high | 8.1% | 2013-09-10 |
| CVE-2007-1043 EXP | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config… | Patch early | 7.5 high | 8.1% | 2007-02-21 |
| CVE-2000-0921 EXP | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot do… | Patch early | 5.0 medium | 8.1% | 2000-12-19 |
| CVE-2001-0295 EXP | Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." c… | Patch early | 5.0 medium | 8.1% | 2001-05-03 |
| CVE-2001-0924 EXP | Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in t… | Patch early | 5.0 medium | 8.1% | 2001-11-22 |
| CVE-2006-6853 EXP | Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cra… | Patch early | 10.0 high | 8.1% | 2006-12-31 |
| CVE-2006-1470 EXP | OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an… | Patch early | 5.0 medium | 8.1% | 2006-06-27 |
| CVE-2009-0497 EXP | Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot back… | Patch early | 5.0 medium | 8.1% | 2009-02-10 |
| CVE-2018-4241 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 7.8 high | 8.1% | 2018-06-08 |
| CVE-2012-0389 EXP | Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.… | Patch early | 4.3 medium | 8.1% | 2012-01-24 |
| CVE-1999-1533 EXP | Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file i… | Patch early | 7.5 high | 8.1% | 1999-11-07 |
| CVE-2014-7288 EXP | Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell c… | Patch early | 9.0 high | 8.1% | 2015-02-01 |
| CVE-2004-1937 EXP | Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in… | Patch early | 5.0 medium | 8.1% | 2004-12-31 |
| CVE-2004-2640 EXP | Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequence… | Patch early | 5.0 medium | 8.1% | 2004-12-31 |
| CVE-1999-0950 EXP | Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | Patch early | 10.0 high | 8.1% | 1999-10-28 |
| CVE-2015-6787 EXP | Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact v… | Patch early | 10.0 high | 8.1% | 2015-12-06 |
| CVE-2017-3132 EXP | A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the… | Patch early | 6.1 medium | 8.1% | 2017-09-12 |
| CVE-2014-9304 EXP | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrativ… | Patch early | 7.5 high | 8.1% | 2014-12-07 |
| CVE-2009-4202 EXP | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 8.1% | 2009-12-04 |
| CVE-2009-4050 EXP | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequen… | Patch early | 5.0 medium | 8.1% | 2009-11-23 |
| CVE-2002-2084 EXP | Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2… | Patch early | 5.0 medium | 8.1% | 2002-12-31 |
| CVE-2005-4208 EXP | Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id… | Patch early | 5.0 medium | 8.1% | 2005-12-13 |
| CVE-2002-1014 EXP | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an… | Patch early | 7.5 high | 8.1% | 2002-10-04 |
| CVE-2008-0625 EXP | Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code vi… | Patch early | 4.3 medium | 8.1% | 2008-02-06 |
| CVE-2008-3318 EXP | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar… | Patch early | 7.5 high | 8.1% | 2008-07-25 |
| CVE-2008-1119 EXP | Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 8.1% | 2008-03-03 |
| CVE-2001-1408 EXP | Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 8.1% | 2001-07-05 |
| CVE-2003-0277 EXP | Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot… | Patch early | 5.0 medium | 8.1% | 2003-06-16 |
| CVE-2004-1951 EXP | xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) aud… | Patch early | 5.0 medium | 8.1% | 2004-12-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt