CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
403,746 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-3293 EXP | Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the dlfilename parameter. | Patch early | 5.0 medium | 8.9% | 2008-07-24 |
| CVE-2014-4874 EXP | BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page. | Patch early | 4.0 medium | 8.9% | 2014-10-10 |
| CVE-2014-3225 EXP | Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files vi… | Patch early | 4.0 medium | 8.9% | 2014-05-14 |
| CVE-2011-1715 EXP | Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2… | Patch early | 5.0 medium | 8.9% | 2011-04-18 |
| CVE-2008-0485 EXP | Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV… | Patch early | 9.3 high | 8.9% | 2008-02-05 |
| CVE-2007-2872 EXP | Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of servic… | Patch early | 6.8 medium | 8.9% | 2007-06-04 |
| CVE-2011-0761 EXP | Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability… | Patch early | 5.0 medium | 8.9% | 2011-05-13 |
| CVE-2006-4829 EXP | Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 8.9% | 2006-09-15 |
| CVE-2014-9000 EXP | Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to… | Patch early | 6.5 medium | 8.9% | 2014-11-20 |
| CVE-2019-19743 EXP | On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal. | Patch early | 6.5 medium | 8.9% | 2019-12-16 |
| CVE-2006-3104 EXP | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the install… | Patch early | 5.0 medium | 8.9% | 2006-06-21 |
| CVE-2007-5253 EXP | c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, b… | Patch early | 5.0 medium | 8.9% | 2007-10-06 |
| CVE-2006-2175 EXP | PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 6.4 medium | 8.9% | 2006-05-04 |
| CVE-2013-0145 EXP | Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar… | Patch early | 5.0 medium | 8.9% | 2013-05-20 |
| CVE-2004-1444 EXP | Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ com… | Patch early | 5.0 medium | 8.9% | 2004-12-31 |
| CVE-2018-19287 EXP | XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (… | Patch early | 6.1 medium | 8.9% | 2018-11-15 |
| CVE-2007-0976 EXP | Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD… | Patch early | 10.0 high | 8.9% | 2007-02-16 |
| CVE-2009-0134 EXP | Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers t… | Patch early | 9.3 high | 8.9% | 2009-01-16 |
| CVE-2007-3619 EXP | Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot)… | Patch early | 5.0 medium | 8.9% | 2007-07-09 |
| CVE-2002-2072 EXP | java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM cras… | Patch early | 5.0 medium | 8.9% | 2002-12-31 |
| CVE-2014-4937 EXP | Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a ..… | Patch early | 5.0 medium | 8.9% | 2014-07-11 |
| CVE-1999-0283 EXP | The Java Web Server would allow remote users to obtain the source code for CGI programs. | Patch early | 10.0 high | 8.9% | 1999-01-01 |
| CVE-2015-7894 EXP | The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a… | Patch early | 8.8 high | 8.9% | 2017-08-09 |
| CVE-2022-1631 EXP | Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, the… | Patch early | 8.8 high | 8.9% | 2022-05-09 |
| CVE-2001-1303 EXP | The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the prote… | Patch early | 5.0 medium | 8.8% | 2001-07-18 |
| CVE-2004-2443 EXP | Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null pa… | Patch early | 7.5 high | 8.8% | 2004-12-31 |
| CVE-2001-0507 EXP | IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka th… | Patch early | 7.2 high | 8.8% | 2001-09-20 |
| CVE-2008-5498 EXP | Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory loc… | Patch early | 5.0 medium | 8.8% | 2008-12-26 |
| CVE-2002-1224 EXP | Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL wi… | Patch early | 5.0 medium | 8.8% | 2002-10-28 |
| CVE-1999-0204 EXP | Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | Patch early | 10.0 high | 8.8% | 1997-01-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt