CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,554 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
169,343 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-0229 EXP | CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card informati… | Patch early | 5.0 medium | 7.7% | 2005-04-27 |
| CVE-2012-5907 EXP | Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .… | Patch early | 5.0 medium | 7.7% | 2012-11-17 |
| CVE-2014-10010 EXP | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id… | Patch early | 5.0 medium | 7.7% | 2015-01-13 |
| CVE-2013-2619 EXP | Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI. | Patch early | 5.0 medium | 7.7% | 2014-03-18 |
| CVE-2014-3806 EXP | Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files vi… | Patch early | 5.0 medium | 7.7% | 2014-05-21 |
| CVE-2015-0514 EXP | EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by l… | Patch early | 5.0 medium | 7.6% | 2015-01-21 |
| CVE-2019-10273 EXP | Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active u… | Patch early | 4.3 medium | 7.6% | 2019-04-04 |
| CVE-2003-1181 EXP | Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function. | Patch early | 5.0 medium | 7.6% | 2003-10-25 |
| CVE-2009-3749 EXP | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remo… | Patch early | 5.0 medium | 7.6% | 2009-10-22 |
| CVE-2002-1581 EXP | Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot do… | Patch early | 5.0 medium | 7.6% | 2004-12-06 |
| CVE-2004-1696 EXP | EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage return… | Patch early | 5.0 medium | 7.6% | 2004-09-21 |
| CVE-2012-0937 EXP | wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MyS… | Patch early | 5.0 medium | 7.6% | 2012-01-30 |
| CVE-2009-5067 EXP | Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI… | Patch early | 4.3 medium | 7.6% | 2012-10-10 |
| CVE-2006-4424 EXP | PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the… | Patch early | 5.1 medium | 7.6% | 2006-08-29 |
| CVE-2006-2480 EXP | Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tri… | Patch early | 5.1 medium | 7.6% | 2006-05-19 |
| CVE-2007-1711 EXP | Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting varia… | Patch early | 6.8 medium | 7.6% | 2007-03-27 |
| CVE-2001-1212 EXP | Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter. | Patch early | 5.0 medium | 7.6% | 2001-12-18 |
| CVE-2014-4306 EXP | Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logf… | Patch early | 5.0 medium | 7.6% | 2014-06-18 |
| CVE-2013-1807 EXP | PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow r… | Patch early | 5.0 medium | 7.6% | 2014-04-30 |
| CVE-2007-0821 EXP | Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the ch… | Patch early | 5.0 medium | 7.6% | 2007-02-07 |
| CVE-2005-0739 EXP | The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vu… | Patch early | 5.0 medium | 7.6% | 2005-05-02 |
| CVE-2010-3456 EXP | Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (… | Patch early | 5.0 medium | 7.6% | 2010-09-17 |
| CVE-2021-27519 EXP | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | Patch early | 6.1 medium | 7.6% | 2021-03-19 |
| CVE-2010-0314 EXP | Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL… | Patch early | 5.0 medium | 7.6% | 2010-01-14 |
| CVE-2016-6512 EXP | epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to… | Patch early | 5.9 medium | 7.6% | 2016-08-06 |
| CVE-2008-0624 EXP | Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a… | Patch early | 4.3 medium | 7.6% | 2008-02-06 |
| CVE-2016-2279 EXP | Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote atta… | Patch early | 6.1 medium | 7.6% | 2016-03-02 |
| CVE-2007-0540 EXP | WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that cor… | Patch early | 5.0 medium | 7.6% | 2007-01-29 |
| CVE-2006-6885 EXP | An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long… | Patch early | 4.3 medium | 7.6% | 2006-12-31 |
| CVE-2006-2182 EXP | Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attac… | Patch early | 6.4 medium | 7.6% | 2006-05-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt