CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
169,548 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-0406 EXP | Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server… | Patch early | 5.0 medium | 7.1% | 2002-07-26 |
| CVE-2004-0071 EXP | Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary f… | Patch early | 5.0 medium | 7.1% | 2004-02-17 |
| CVE-2004-1646 EXP | Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Patch early | 5.0 medium | 7.1% | 2004-08-30 |
| CVE-2004-0520 EXP | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the… | Patch early | 6.8 medium | 7.1% | 2004-08-18 |
| CVE-2008-3578 EXP | HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// U… | Patch early | 5.0 medium | 7.1% | 2008-08-10 |
| CVE-2018-12522 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12523 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12524 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2018-12525 EXP | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | Patch early | 5.3 medium | 7.1% | 2018-06-18 |
| CVE-2001-0697 EXP | NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | Patch early | 5.0 medium | 7.1% | 2001-09-20 |
| CVE-2001-0965 EXP | glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of… | Patch early | 5.0 medium | 7.1% | 2001-08-31 |
| CVE-2007-6315 EXP | Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/ch… | Patch early | 4.0 medium | 7.1% | 2007-12-12 |
| CVE-2009-1839 EXP | Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote… | Patch early | 5.4 medium | 7.1% | 2009-06-12 |
| CVE-2005-2904 EXP | Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (application crash) via a zero in the… | Patch early | 5.0 medium | 7.1% | 2005-09-14 |
| CVE-2002-1169 EXP | IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP requ… | Patch early | 5.0 medium | 7.1% | 2002-11-04 |
| CVE-2002-1236 EXP | The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of se… | Patch early | 5.0 medium | 7.1% | 2002-11-12 |
| CVE-2002-1906 EXP | The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requ… | Patch early | 5.0 medium | 7.1% | 2002-12-31 |
| CVE-2003-1054 EXP | mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as pa… | Patch early | 5.0 medium | 7.1% | 2003-04-16 |
| CVE-2007-1458 EXP | Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path param… | Patch early | 6.8 medium | 7.1% | 2007-03-14 |
| CVE-2000-0436 EXP | MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7.1% | 2000-05-19 |
| CVE-2019-7646 EXP | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_packa… | Patch early | 4.8 medium | 7.1% | 2019-03-26 |
| CVE-2009-4531 EXP | httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI. | Patch early | 5.0 medium | 7.1% | 2009-12-31 |
| CVE-2004-1543 EXP | Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (do… | Patch early | 5.0 medium | 7.1% | 2004-12-31 |
| CVE-2008-6791 EXP | PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field. | Patch early | 5.0 medium | 7.1% | 2009-05-04 |
| CVE-2008-3906 EXP | CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response spl… | Patch early | 4.3 medium | 7.1% | 2008-09-04 |
| CVE-2004-2253 EXP | Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page param… | Patch early | 5.0 medium | 7.1% | 2004-12-31 |
| CVE-2003-1166 EXP | Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .… | Patch early | 5.0 medium | 7.1% | 2003-12-31 |
| CVE-2008-6811 EXP | Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execu… | Patch early | 6.8 medium | 7.1% | 2009-05-18 |
| CVE-2005-1204 EXP | Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP… | Patch early | 5.0 medium | 7.1% | 2005-05-02 |
| CVE-2006-2230 EXP | Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string speci… | Patch early | 5.0 medium | 7.1% | 2006-05-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt