CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
321,940 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-2636 EXP | The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL… | Patch early | 8.8 high | 6.9% | 2023-07-17 |
| CVE-2000-0571 EXP | LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request. | Patch early | 6.4 medium | 6.9% | 2000-07-05 |
| CVE-2002-1427 EXP | The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify hom… | Patch early | 7.5 high | 6.9% | 2003-04-11 |
| CVE-2001-1044 EXP | Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which cou… | Patch early | 7.5 high | 6.9% | 2001-01-11 |
| CVE-2004-1724 EXP | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execut… | Patch early | 7.5 high | 6.9% | 2004-08-18 |
| CVE-2005-1366 EXP | Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. | Patch early | 7.5 high | 6.9% | 2005-05-16 |
| CVE-2007-1455 EXP | Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbi… | Patch early | 9.0 high | 6.9% | 2007-03-14 |
| CVE-2008-4194 EXP | The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long… | Patch early | 5.0 medium | 6.9% | 2008-09-24 |
| CVE-2008-6793 EXP | The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell met… | Patch early | 6.8 medium | 6.9% | 2009-05-07 |
| CVE-2011-3713 EXP | cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error… | Patch early | 5.0 medium | 6.9% | 2011-09-23 |
| CVE-2019-8765 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web… | Patch early | 8.8 high | 6.9% | 2019-12-18 |
| CVE-2005-4799 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitr… | Patch early | 5.1 medium | 6.9% | 2005-12-31 |
| CVE-2004-0242 EXP | X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. | Patch early | 5.0 medium | 6.9% | 2004-11-23 |
| CVE-2004-1854 EXP | Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet. | Patch early | 7.5 high | 6.9% | 2004-03-24 |
| CVE-2004-2037 EXP | Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute a… | Patch early | 7.5 high | 6.9% | 2004-03-24 |
| CVE-2002-1828 EXP | Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. | Patch early | 5.0 medium | 6.9% | 2002-12-31 |
| CVE-2005-0788 EXP | LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. | Patch early | 5.0 medium | 6.9% | 2005-03-14 |
| CVE-2006-0319 EXP | Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via "..… | Patch early | 5.0 medium | 6.9% | 2006-01-19 |
| CVE-2006-3556 EXP | PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code vi… | Patch early | 6.8 medium | 6.9% | 2006-07-13 |
| CVE-2005-2767 EXP | Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file. | Patch early | 7.5 high | 6.9% | 2005-09-02 |
| CVE-2010-3136 EXP | Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and co… | Patch early | 9.3 high | 6.9% | 2010-08-26 |
| CVE-2018-5715 EXP | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | Patch early | 6.1 medium | 6.9% | 2018-01-16 |
| CVE-2018-10255 EXP | A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command th… | Patch early | 8.8 high | 6.9% | 2018-05-01 |
| CVE-2002-1463 EXP | Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5… | Patch early | 7.5 high | 6.9% | 2003-06-09 |
| CVE-2015-6639 EXP | The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted… | Patch early | 7.8 high | 6.9% | 2016-01-06 |
| CVE-2018-4240 EXP | An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchO… | Patch early | 6.5 medium | 6.9% | 2018-06-08 |
| CVE-2000-0780 EXP | The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack. | Patch early | 6.4 medium | 6.9% | 2000-10-20 |
| CVE-2008-3285 EXP | The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell me… | Patch early | 9.3 high | 6.9% | 2008-07-24 |
| CVE-2016-1594 EXP | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as dem… | Patch early | 6.5 medium | 6.9% | 2016-04-22 |
| CVE-2018-13980 EXP | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser… | Patch early | 5.5 medium | 6.9% | 2018-07-16 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt