CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,069 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,842 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2001-0900 EXP | Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the inc… | Patch early | 5.0 medium | 7.9% | 2001-11-18 |
| CVE-2018-5755 EXP | Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 bef… | Patch early | 5.5 medium | 7.9% | 2018-06-16 |
| CVE-2005-4171 EXP | The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbi… | Patch early | 7.5 high | 7.9% | 2005-12-11 |
| CVE-2023-0493 EXP | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. | Patch early | 5.3 medium | 7.9% | 2023-01-26 |
| CVE-2006-3845 EXP | Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a L… | Patch early | 9.3 high | 7.9% | 2006-07-25 |
| CVE-2006-5289 EXP | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the… | Patch early | 7.5 high | 7.9% | 2006-10-13 |
| CVE-2018-13042 EXP | The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling… | Patch early | 5.9 medium | 7.9% | 2018-10-05 |
| CVE-2004-1422 EXP | WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | Patch early | 5.0 medium | 7.9% | 2004-12-31 |
| CVE-2004-1720 EXP | The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an inval… | Patch early | 5.0 medium | 7.9% | 2004-08-17 |
| CVE-2013-5680 EXP | Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of… | Patch early | 6.8 medium | 7.9% | 2014-04-06 |
| CVE-2006-3019 EXP | Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INC… | Patch early | 7.5 high | 7.9% | 2006-06-15 |
| CVE-2006-4834 EXP | PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 7.5 high | 7.9% | 2006-09-15 |
| CVE-2012-5100 EXP | Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2)… | Patch early | 5.0 medium | 7.9% | 2012-09-23 |
| CVE-2000-1147 EXP | Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a s… | Patch early | 4.6 medium | 7.9% | 2001-01-09 |
| CVE-2016-3986 EXP | Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to a… | Patch early | 7.8 high | 7.9% | 2016-04-12 |
| CVE-2006-0047 EXP | packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed… | Patch early | 5.0 medium | 7.9% | 2006-03-07 |
| CVE-2006-6885 EXP | An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long… | Patch early | 4.3 medium | 7.9% | 2006-12-31 |
| CVE-2010-4350 EXP | Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to include and execute arbitrary lo… | Patch early | 5.1 medium | 7.9% | 2011-01-03 |
| CVE-2016-9349 EXP | An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can re… | Patch early | 7.5 high | 7.9% | 2017-02-13 |
| CVE-2008-6948 EXP | Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an exe… | Patch early | 6.5 medium | 7.9% | 2009-08-12 |
| CVE-2001-0857 EXP | Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users… | Patch early | 7.5 high | 7.9% | 2001-12-06 |
| CVE-2019-8404 EXP | An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the crea… | Patch early | 6.5 medium | 7.9% | 2019-05-14 |
| CVE-2006-2568 EXP | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute… | Patch early | 5.1 medium | 7.9% | 2006-05-24 |
| CVE-2008-6947 EXP | Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated w… | Patch early | 7.5 high | 7.9% | 2009-08-12 |
| CVE-2000-0350 EXP | A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unen… | Patch early | 5.0 medium | 7.9% | 2000-05-17 |
| CVE-2003-1191 EXP | chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which preven… | Patch early | 5.0 medium | 7.9% | 2003-10-29 |
| CVE-2001-0307 EXP | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP req… | Patch early | 7.5 high | 7.9% | 2001-05-03 |
| CVE-2008-3447 EXP | The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, p… | Patch early | 5.0 medium | 7.9% | 2008-08-04 |
| CVE-2009-4679 EXP | Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include a… | Patch early | 7.5 high | 7.9% | 2010-03-08 |
| CVE-2022-39290 EXP | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mod… | Patch early | 8.0 high | 7.9% | 2022-10-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt