CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,143 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,087 with exploits
synced 2026-09-30
169,595 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-4329 EXP | Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_o… | Patch early | 6.8 medium | 7% | 2007-08-14 |
| CVE-2009-0967 EXP | The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of S… | Patch early | 4.0 medium | 7% | 2009-03-19 |
| CVE-2007-6567 EXP | Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbit… | Patch early | 6.4 medium | 7% | 2007-12-28 |
| CVE-2001-1010 EXP | Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via… | Patch early | 5.0 medium | 7% | 2001-07-22 |
| CVE-2002-2353 EXP | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | Patch early | 6.4 medium | 7% | 2002-12-31 |
| CVE-2006-2735 EXP | PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register… | Patch early | 5.1 medium | 7% | 2006-06-01 |
| CVE-2006-4963 EXP | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot… | Patch early | 6.4 medium | 7% | 2006-09-23 |
| CVE-2005-1382 EXP | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter… | Patch early | 5.0 medium | 7% | 2005-05-03 |
| CVE-2013-6366 EXP | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().e… | Patch early | 6.5 medium | 7% | 2013-11-04 |
| CVE-2016-7851 EXP | Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in… | Patch early | 6.1 medium | 7% | 2016-11-08 |
| CVE-2005-1333 EXP | Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitra… | Patch early | 5.0 medium | 7% | 2005-05-04 |
| CVE-2017-9147 EXP | LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash)… | Patch early | 6.5 medium | 7% | 2017-05-22 |
| CVE-2004-2082 EXP | The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request… | Patch early | 5.0 medium | 7% | 2004-02-13 |
| CVE-2004-1741 EXP | Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument… | Patch early | 5.0 medium | 7% | 2004-08-23 |
| CVE-2005-0986 EXP | NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of serv… | Patch early | 5.0 medium | 7% | 2005-05-02 |
| CVE-2005-3187 EXP | The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP reque… | Patch early | 5.0 medium | 7% | 2005-12-31 |
| CVE-2000-0045 EXP | MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. | Patch early | 6.4 medium | 7% | 2000-01-11 |
| CVE-2001-0302 EXP | Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary comman… | Patch early | 5.0 medium | 7% | 2001-05-03 |
| CVE-2019-15811 EXP | In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | Patch early | 6.1 medium | 7% | 2019-08-29 |
| CVE-2006-4922 EXP | Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers t… | Patch early | 5.0 medium | 7% | 2006-09-21 |
| CVE-2003-0442 EXP | Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attacker… | Patch early | 4.3 medium | 7% | 2003-07-24 |
| CVE-2014-2399 EXP | Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unkn… | Patch early | 4.3 medium | 7% | 2014-04-16 |
| CVE-2001-0563 EXP | ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) stri… | Patch early | 5.0 medium | 7% | 2001-08-14 |
| CVE-2014-4688 EXP | pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias acti… | Patch early | 6.5 medium | 7% | 2014-07-02 |
| CVE-2017-15270 EXP | The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attac… | Patch early | 5.3 medium | 7% | 2017-11-15 |
| CVE-2001-1491 EXP | Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. | Patch early | 5.0 medium | 7% | 2001-12-31 |
| CVE-2002-1811 EXP | Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending… | Patch early | 5.0 medium | 7% | 2002-12-31 |
| CVE-2008-6960 EXP | download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url p… | Patch early | 5.0 medium | 7% | 2009-08-12 |
| CVE-2006-5250 EXP | PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute ar… | Patch early | 5.1 medium | 7% | 2006-10-12 |
| CVE-2000-0526 EXP | mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Patch early | 5.0 medium | 7% | 2000-06-09 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt