CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
321,751 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-7449 EXP | SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR comm… | Patch early | 7.5 high | 7.5% | 2018-03-04 |
| CVE-2007-0609 EXP | Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local fi… | Patch early | 5.1 medium | 7.5% | 2007-05-09 |
| CVE-2015-5074 EXP | Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9… | Patch early | 7.5 high | 7.5% | 2015-09-29 |
| CVE-2007-2787 EXP | Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object… | Patch early | 7.5 high | 7.5% | 2007-05-21 |
| CVE-2004-1643 EXP | WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a ".… | Patch early | 5.0 medium | 7.5% | 2004-08-29 |
| CVE-2005-3929 EXP | Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and o… | Patch early | 5.0 medium | 7.5% | 2005-11-30 |
| CVE-2009-0259 EXP | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c… | Patch early | 9.3 high | 7.5% | 2009-01-22 |
| CVE-2000-0411 EXP | Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | Patch early | 5.0 medium | 7.5% | 2000-05-10 |
| CVE-2010-3000 EXP | Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows… | Patch early | 9.3 high | 7.5% | 2010-08-30 |
| CVE-2016-7098 EXP | Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass inte… | Patch early | 8.1 high | 7.5% | 2016-09-26 |
| CVE-2007-6322 EXP | Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file… | Patch early | 5.0 medium | 7.5% | 2007-12-13 |
| CVE-2007-1029 EXP | Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute ar… | Patch early | 7.6 high | 7.5% | 2007-02-21 |
| CVE-2006-4845 EXP | PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrar… | Patch early | 5.1 medium | 7.5% | 2006-09-19 |
| CVE-2008-2326 EXP | mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer… | Patch early | 5.0 medium | 7.5% | 2008-09-11 |
| CVE-2018-20735 EXP | An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation… | Patch early | 7.8 high | 7.5% | 2019-01-17 |
| CVE-2000-0588 EXP | SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents… | Patch early | 5.0 medium | 7.5% | 2000-06-26 |
| CVE-2000-0872 EXP | explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.5% | 2000-11-14 |
| CVE-2000-1002 EXP | POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote at… | Patch early | 5.0 medium | 7.5% | 2000-12-11 |
| CVE-2000-1092 EXP | loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in… | Patch early | 5.0 medium | 7.5% | 2001-01-09 |
| CVE-2001-0255 EXP | FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:… | Patch early | 5.0 medium | 7.5% | 2001-06-02 |
| CVE-2014-9262 EXP | The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. | Patch early | 8.2 high | 7.5% | 2017-08-07 |
| CVE-2007-5248 EXP | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3… | Patch early | 9.3 high | 7.5% | 2007-10-06 |
| CVE-2017-9936 EXP | In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service atta… | Patch early | 6.5 medium | 7.5% | 2017-06-26 |
| CVE-2007-4718 EXP | Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local… | Patch early | 5.1 medium | 7.5% | 2007-09-05 |
| CVE-2011-4221 EXP | Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application cra… | Patch early | 9.3 high | 7.5% | 2011-11-01 |
| CVE-2011-4222 EXP | Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application c… | Patch early | 9.3 high | 7.5% | 2011-11-01 |
| CVE-2007-1074 EXP | Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPa… | Patch early | 9.3 high | 7.5% | 2007-02-22 |
| CVE-2000-0183 EXP | Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability. | Patch early | 5.1 medium | 7.5% | 2000-03-10 |
| CVE-2010-1951 EXP | Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal… | Patch early | 6.8 medium | 7.5% | 2010-05-19 |
| CVE-2011-4450 EXP | Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary… | Patch early | 6.4 medium | 7.5% | 2012-09-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt