CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,516 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
169,329 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-5123 EXP | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perfor… | Patch early | 5.9 medium | 8% | 2019-11-05 |
| CVE-2004-0580 EXP | DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer con… | Patch early | 5.0 medium | 8% | 2004-08-06 |
| CVE-2008-0399 EXP | Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arb… | Patch early | 6.8 medium | 8% | 2008-01-23 |
| CVE-2000-0652 EXP | IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which co… | Patch early | 5.0 medium | 8% | 2000-07-24 |
| CVE-2004-2117 EXP | Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP ve… | Patch early | 5.0 medium | 8% | 2004-01-24 |
| CVE-2016-9813 EXP | The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference… | Patch early | 5.5 medium | 8% | 2017-01-13 |
| CVE-2012-0789 EXP | Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering… | Patch early | 5.0 medium | 8% | 2012-02-14 |
| CVE-2007-1060 EXP | Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled,… | Patch early | 6.8 medium | 8% | 2007-02-22 |
| CVE-2000-0705 EXP | ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 8% | 2000-10-20 |
| CVE-2000-1177 EXP | bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine… | Patch early | 5.0 medium | 8% | 2001-01-09 |
| CVE-2004-0293 EXP | Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) g… | Patch early | 5.0 medium | 8% | 2004-11-23 |
| CVE-2004-0327 EXP | Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequen… | Patch early | 5.0 medium | 8% | 2004-11-23 |
| CVE-2015-2125 EXP | Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restricti… | Patch early | 4.0 medium | 7.9% | 2015-06-07 |
| CVE-2004-2060 EXP | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request… | Patch early | 5.0 medium | 7.9% | 2004-12-31 |
| CVE-2007-3505 EXP | Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot… | Patch early | 6.4 medium | 7.9% | 2007-07-02 |
| CVE-2001-0037 EXP | Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifie… | Patch early | 5.0 medium | 7.9% | 2001-02-16 |
| CVE-2001-0805 EXP | Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (do… | Patch early | 5.0 medium | 7.9% | 2001-12-06 |
| CVE-2008-3851 EXP | Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a .… | Patch early | 5.0 medium | 7.9% | 2008-08-27 |
| CVE-1999-1005 EXP | Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter… | Patch early | 5.0 medium | 7.9% | 1999-12-19 |
| CVE-2006-2156 EXP | Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) seq… | Patch early | 6.4 medium | 7.9% | 2006-05-03 |
| CVE-2009-1415 EXP | lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denia… | Patch early | 4.3 medium | 7.9% | 2009-04-30 |
| CVE-2006-2142 EXP | PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code… | Patch early | 6.4 medium | 7.9% | 2006-05-02 |
| CVE-2007-3799 EXP | The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the s… | Patch early | 4.3 medium | 7.9% | 2007-07-16 |
| CVE-2013-5680 EXP | Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of… | Patch early | 6.8 medium | 7.9% | 2014-04-06 |
| CVE-2001-1528 EXP | AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote att… | Patch early | 5.0 medium | 7.9% | 2001-12-31 |
| CVE-2001-0123 EXP | Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file… | Patch early | 5.0 medium | 7.9% | 2001-03-12 |
| CVE-2018-18775 EXP | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Log… | Patch early | 6.1 medium | 7.9% | 2018-11-01 |
| CVE-2009-2851 EXP | Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 7.9% | 2009-08-18 |
| CVE-2001-0900 EXP | Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the inc… | Patch early | 5.0 medium | 7.9% | 2001-11-18 |
| CVE-2006-5773 EXP | Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the insta… | Patch early | 5.0 medium | 7.9% | 2006-11-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt