CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,486 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-29
169,328 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-5062 EXP | Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory tr… | Patch early | 5.0 medium | 8.1% | 2008-11-13 |
| CVE-2010-0303 EXP | mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash… | Patch early | 5.0 medium | 8.1% | 2010-02-04 |
| CVE-2011-1425 EXP | xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to crea… | Patch early | 5.1 medium | 8.1% | 2011-04-04 |
| CVE-2002-1525 EXP | Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (… | Patch early | 5.0 medium | 8.1% | 2003-04-02 |
| CVE-2003-0748 EXP | Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary fil… | Patch early | 5.0 medium | 8.1% | 2003-10-20 |
| CVE-1999-1069 EXP | Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the ic… | Patch early | 5.0 medium | 8.1% | 1997-11-08 |
| CVE-2001-0189 EXP | Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP… | Patch early | 5.0 medium | 8.1% | 2001-03-26 |
| CVE-2003-0621 EXP | The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modifie… | Patch early | 5.0 medium | 8% | 2003-12-01 |
| CVE-2007-4583 EXP | Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (… | Patch early | 5.0 medium | 8% | 2007-08-29 |
| CVE-2002-1031 EXP | KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) chara… | Patch early | 5.0 medium | 8% | 2002-10-04 |
| CVE-2000-0919 EXP | Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 8% | 2000-12-19 |
| CVE-2001-1209 EXP | Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Patch early | 5.0 medium | 8% | 2001-12-31 |
| CVE-2006-3532 EXP | PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to… | Patch early | 5.1 medium | 8% | 2006-07-12 |
| CVE-2004-2519 EXP | Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter… | Patch early | 5.0 medium | 8% | 2004-12-31 |
| CVE-2006-0755 EXP | Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute… | Patch early | 5.6 medium | 8% | 2006-02-18 |
| CVE-2004-2132 EXP | Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the… | Patch early | 5.0 medium | 8% | 2004-01-29 |
| CVE-2005-1073 EXP | Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter. | Patch early | 5.0 medium | 8% | 2005-05-02 |
| CVE-2017-13262 EXP | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote inform… | Patch early | 6.5 medium | 8% | 2018-04-04 |
| CVE-2007-5198 EXP | Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web ser… | Patch early | 6.8 medium | 8% | 2007-10-04 |
| CVE-2000-0142 EXP | The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. | Patch early | 5.0 medium | 8% | 2000-02-11 |
| CVE-2008-1888 EXP | Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 8% | 2008-04-18 |
| CVE-2006-4897 EXP | CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to o… | Patch early | 5.0 medium | 8% | 2006-09-19 |
| CVE-2000-0671 EXP | Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by in… | Patch early | 5.0 medium | 8% | 2000-07-21 |
| CVE-2012-0277 EXP | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitra… | Patch early | 6.8 medium | 8% | 2012-07-17 |
| CVE-2008-5856 EXP | Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal… | Patch early | 5.0 medium | 8% | 2009-01-06 |
| CVE-2017-1000367 EXP | Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting i… | Patch early | 6.4 medium | 8% | 2017-06-05 |
| CVE-2015-6972 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 8% | 2015-09-16 |
| CVE-2017-5798 EXP | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (f… | Patch early | 6.1 medium | 8% | 2018-02-15 |
| CVE-2006-6047 EXP | Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to include and execute arbitrary… | Patch early | 5.8 medium | 8% | 2006-11-22 |
| CVE-2002-0741 EXP | psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long passwo… | Patch early | 5.0 medium | 8% | 2002-08-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt