CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,354 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,252 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-4116 EXP | A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the… | Patch early | 4.3 medium | 8.4% | 2023-08-03 |
| CVE-2005-4720 EXP | Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large valu… | Patch early | 5.0 medium | 8.4% | 2005-12-31 |
| CVE-2010-1723 EXP | Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read a… | Patch early | 6.8 medium | 8.4% | 2010-05-04 |
| CVE-2011-4531 EXP | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and d… | Patch early | 5.0 medium | 8.4% | 2012-01-08 |
| CVE-2007-6268 EXP | Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot… | Patch early | 5.0 medium | 8.4% | 2007-12-07 |
| CVE-2015-2184 EXP | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. | Patch early | 5.0 medium | 8.4% | 2015-03-10 |
| CVE-2001-0385 EXP | GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | Patch early | 5.0 medium | 8.4% | 2001-07-02 |
| CVE-2009-1959 EXP | Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (cr… | Patch early | 5.0 medium | 8.4% | 2009-06-08 |
| CVE-2008-1321 EXP | The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of s… | Patch early | 5.0 medium | 8.4% | 2008-03-13 |
| CVE-2010-3213 EXP | Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the au… | Patch early | 6.8 medium | 8.4% | 2010-09-07 |
| CVE-2004-1859 EXP | Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files v… | Patch early | 5.0 medium | 8.4% | 2004-03-24 |
| CVE-2004-2516 EXP | Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of… | Patch early | 5.0 medium | 8.4% | 2004-12-31 |
| CVE-2004-1475 EXP | Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2… | Patch early | 5.1 medium | 8.4% | 2004-12-31 |
| CVE-2016-5063 EXP | The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization… | Patch early | 5.3 medium | 8.4% | 2017-05-02 |
| CVE-2006-3353 EXP | Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-bounds memory access, related to a… | Patch early | 5.0 medium | 8.4% | 2006-07-06 |
| CVE-2010-3460 EXP | Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a… | Patch early | 5.0 medium | 8.4% | 2010-09-17 |
| CVE-2008-0069 EXP | Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in… | Patch early | 6.8 medium | 8.4% | 2008-04-02 |
| CVE-2000-0920 EXP | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) a… | Patch early | 5.0 medium | 8.4% | 2000-12-19 |
| CVE-2015-8357 EXP | Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and… | Patch early | 6.5 medium | 8.4% | 2015-12-16 |
| CVE-2012-3578 EXP | Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to ex… | Patch early | 6.8 medium | 8.4% | 2012-06-17 |
| CVE-2006-4900 EXP | Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated use… | Patch early | 5.5 medium | 8.3% | 2006-09-22 |
| CVE-2001-0571 EXP | Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remot… | Patch early | 5.0 medium | 8.3% | 2001-08-22 |
| CVE-2002-1004 EXP | Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary… | Patch early | 5.0 medium | 8.3% | 2002-10-04 |
| CVE-1999-1509 EXP | Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a… | Patch early | 5.0 medium | 8.3% | 1999-11-04 |
| CVE-2000-1171 EXP | Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in… | Patch early | 5.0 medium | 8.3% | 2001-01-09 |
| CVE-2001-0360 EXP | Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) atta… | Patch early | 5.0 medium | 8.3% | 2001-06-27 |
| CVE-2007-1001 EXP | Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 t… | Patch early | 6.8 medium | 8.3% | 2007-04-06 |
| CVE-2012-0276 EXP | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execut… | Patch early | 6.8 medium | 8.3% | 2012-07-17 |
| CVE-2010-1930 EXP | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree par… | Patch early | 5.0 medium | 8.3% | 2010-06-28 |
| CVE-2005-3048 EXP | Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a… | Patch early | 6.4 medium | 8.3% | 2005-09-24 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt