CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,810 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
169,461 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-3811 EXP | Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arb… | Patch early | 5.0 medium | 7.3% | 2005-11-25 |
| CVE-2002-0300 EXP | gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly re… | Patch early | 5.0 medium | 7.3% | 2002-05-31 |
| CVE-2005-4086 EXP | Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier all… | Patch early | 5.0 medium | 7.3% | 2005-12-08 |
| CVE-2004-0287 EXP | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a lar… | Patch early | 5.0 medium | 7.3% | 2004-11-23 |
| CVE-2004-1385 EXP | phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shel… | Patch early | 5.0 medium | 7.3% | 2004-12-31 |
| CVE-2011-4640 EXP | Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitrary files via a .. (… | Patch early | 4.0 medium | 7.3% | 2012-10-08 |
| CVE-2014-3865 EXP | Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directori… | Patch early | 6.4 medium | 7.3% | 2014-05-30 |
| CVE-2014-2588 EXP | Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via… | Patch early | 4.0 medium | 7.3% | 2014-03-24 |
| CVE-2008-3292 EXP | constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cook… | Patch early | 6.4 medium | 7.3% | 2008-07-24 |
| CVE-2007-3140 EXP | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value i… | Patch early | 6.5 medium | 7.3% | 2007-06-08 |
| CVE-2001-0224 EXP | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. | Patch early | 5.0 medium | 7.3% | 2001-06-02 |
| CVE-2001-1115 EXP | generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter. | Patch early | 5.0 medium | 7.3% | 2001-08-13 |
| CVE-2014-9094 EXP | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress… | Patch early | 4.3 medium | 7.3% | 2014-11-26 |
| CVE-2019-19143 EXP | TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI. | Patch early | 6.1 medium | 7.3% | 2020-01-27 |
| CVE-2006-3082 EXP | parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly ov… | Patch early | 5.0 medium | 7.3% | 2006-06-19 |
| CVE-2006-2256 EXP | PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a UR… | Patch early | 6.4 medium | 7.3% | 2006-05-09 |
| CVE-2013-4097 EXP | ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reve… | Patch early | 5.0 medium | 7.3% | 2013-06-28 |
| CVE-2022-2941 EXP | The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due t… | Patch early | 5.5 medium | 7.3% | 2022-09-06 |
| CVE-2000-0234 EXP | The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file. | Patch early | 5.0 medium | 7.3% | 2000-03-31 |
| CVE-2000-0243 EXP | AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. | Patch early | 5.0 medium | 7.3% | 2000-03-25 |
| CVE-2000-0644 EXP | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. | Patch early | 5.0 medium | 7.3% | 2000-07-21 |
| CVE-2001-0558 EXP | T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS devic… | Patch early | 5.0 medium | 7.3% | 2001-08-14 |
| CVE-2009-0328 EXP | ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access contro… | Patch early | 5.0 medium | 7.3% | 2009-01-29 |
| CVE-2004-1484 EXP | Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly optio… | Patch early | 5.0 medium | 7.3% | 2004-12-31 |
| CVE-2002-1685 EXP | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary… | Patch early | 4.3 medium | 7.3% | 2002-12-31 |
| CVE-2008-4616 EXP | The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a s… | Patch early | 5.0 medium | 7.3% | 2008-10-20 |
| CVE-2012-5931 EXP | Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2… | Patch early | 5.5 medium | 7.3% | 2012-12-24 |
| CVE-2000-0262 EXP | The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request. | Patch early | 5.0 medium | 7.3% | 2000-04-12 |
| CVE-2000-0279 EXP | BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers. | Patch early | 5.0 medium | 7.3% | 2000-04-07 |
| CVE-2000-0507 EXP | Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command. | Patch early | 5.0 medium | 7.3% | 2000-06-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt