CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,939 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,187 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-0259 EXP | The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows… | Patch early | 4.7 medium | 9.7% | 2017-05-12 |
| CVE-2006-0717 EXP | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532… | Patch early | 5.0 medium | 9.7% | 2006-02-15 |
| CVE-2008-2006 EXP | Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference… | Patch early | 4.3 medium | 9.7% | 2008-05-22 |
| CVE-1999-1431 EXP | ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), inst… | Patch early | 4.6 medium | 9.7% | 2005-01-07 |
| CVE-2017-3546 EXP | Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versi… | Patch early | 6.5 medium | 9.6% | 2017-04-24 |
| CVE-2019-19516 EXP | Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password. | Patch early | 6.5 medium | 9.6% | 2019-12-02 |
| CVE-2001-1083 EXP | Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (… | Patch early | 5.0 medium | 9.6% | 2001-06-26 |
| CVE-2007-5036 EXP | Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of ser… | Patch early | 5.0 medium | 9.6% | 2007-09-24 |
| CVE-2002-1320 EXP | Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that… | Patch early | 5.0 medium | 9.6% | 2002-12-11 |
| CVE-2002-1220 EXP | BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain tha… | Patch early | 5.0 medium | 9.6% | 2002-11-29 |
| CVE-2005-2330 EXP | Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a… | Patch early | 5.0 medium | 9.6% | 2005-07-20 |
| CVE-2020-8866 EXP | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authenticati… | Patch early | 6.5 medium | 9.6% | 2020-03-23 |
| CVE-2001-0042 EXP | PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash)… | Patch early | 5.0 medium | 9.6% | 2001-02-16 |
| CVE-2015-4071 EXP | The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticke… | Patch early | 5.3 medium | 9.6% | 2017-08-18 |
| CVE-2006-2863 EXP | PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in… | Patch early | 5.1 medium | 9.6% | 2006-06-06 |
| CVE-2007-6341 EXP | Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (p… | Patch early | 5.0 medium | 9.5% | 2007-12-20 |
| CVE-2008-1482 EXP | Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary… | Patch early | 6.8 medium | 9.5% | 2008-03-24 |
| CVE-2008-2795 EXP | Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or ov… | Patch early | 4.3 medium | 9.5% | 2008-06-20 |
| CVE-2013-2576 EXP | Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft… | Patch early | 6.8 medium | 9.5% | 2013-08-09 |
| CVE-2011-1470 EXP | The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that… | Patch early | 4.3 medium | 9.5% | 2011-03-20 |
| CVE-2002-0484 EXP | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to uninten… | Patch early | 5.0 medium | 9.5% | 2002-08-12 |
| CVE-2006-2134 EXP | PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to exe… | Patch early | 5.1 medium | 9.5% | 2006-05-02 |
| CVE-2006-0513 EXP | Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to re… | Patch early | 5.0 medium | 9.5% | 2006-02-06 |
| CVE-2007-4504 EXP | Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read ar… | Patch early | 5.0 medium | 9.5% | 2007-08-23 |
| CVE-2010-3847 EXP | elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGI… | Patch early | 6.9 medium | 9.5% | 2011-01-07 |
| CVE-2009-2109 EXP | Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (… | Patch early | 5.0 medium | 9.5% | 2009-06-18 |
| CVE-2014-9181 EXP | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in… | Patch early | 5.0 medium | 9.5% | 2014-12-02 |
| CVE-2005-4557 EXP | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attacker… | Patch early | 5.0 medium | 9.5% | 2005-12-28 |
| CVE-2020-5811 EXP | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary f… | Patch early | 6.5 medium | 9.5% | 2020-12-30 |
| CVE-2015-2862 EXP | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1… | Patch early | 4.0 medium | 9.5% | 2015-07-20 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt