CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,746 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-5825 EXP | Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.7% | 2006-11-10 |
| CVE-2008-5044 EXP | Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded applica… | Patch early | 4.0 medium | 1.7% | 2008-11-12 |
| CVE-2011-1668 EXP | Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers… | Patch early | 4.3 medium | 1.7% | 2011-04-10 |
| CVE-2020-5147 EXP | SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in th… | Patch early | 5.3 medium | 1.7% | 2021-01-09 |
| CVE-2018-20448 EXP | Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | Patch early | 5.4 medium | 1.7% | 2018-12-25 |
| CVE-2006-4985 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary web script or HTML via (1) th… | Patch early | 4.3 medium | 1.7% | 2006-09-26 |
| CVE-2006-4742 EXP | Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.7% | 2006-09-13 |
| CVE-2006-4771 EXP | Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte… | Patch early | 4.3 medium | 1.7% | 2006-09-14 |
| CVE-2017-15291 EXP | Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject ar… | Patch early | 6.1 medium | 1.7% | 2017-10-20 |
| CVE-2009-2882 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show param… | Patch early | 4.3 medium | 1.7% | 2009-08-20 |
| CVE-2012-2996 EXP | Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow… | Patch early | 6.8 medium | 1.7% | 2012-09-17 |
| CVE-2007-5027 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94… | Patch early | 4.3 medium | 1.7% | 2007-09-21 |
| CVE-2007-2090 EXP | Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 1.7% | 2007-04-18 |
| CVE-2006-6536 EXP | Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 6.8 medium | 1.7% | 2006-12-14 |
| CVE-2021-31327 EXP | Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. | Patch early | 5.4 medium | 1.7% | 2021-04-21 |
| CVE-2021-31329 EXP | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php | Patch early | 5.4 medium | 1.7% | 2021-04-21 |
| CVE-2001-0941 EXP | Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. | Patch early | 4.6 medium | 1.7% | 2001-11-30 |
| CVE-2004-0678 EXP | Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other… | Patch early | 4.3 medium | 1.7% | 2004-08-06 |
| CVE-2012-2570 EXP | Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2012-08-15 |
| CVE-2012-5322 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName pa… | Patch early | 4.3 medium | 1.7% | 2012-10-08 |
| CVE-2006-5564 EXP | Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op… | Patch early | 4.3 medium | 1.7% | 2006-10-27 |
| CVE-2012-4998 EXP | Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Patch early | 4.3 medium | 1.7% | 2012-09-19 |
| CVE-2025-47171 EXP | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | Patch early | 6.7 medium | 1.7% | 2025-06-10 |
| CVE-2010-3489 EXP | Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remo… | Patch early | 4.3 medium | 1.7% | 2010-09-22 |
| CVE-2004-2718 EXP | PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database p… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2009-4467 EXP | misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre… | Patch early | 4.0 medium | 1.7% | 2009-12-30 |
| CVE-2009-2440 EXP | Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page… | Patch early | 4.3 medium | 1.7% | 2009-07-13 |
| CVE-2006-5712 EXP | Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Styl… | Patch early | 4.3 medium | 1.7% | 2006-11-04 |
| CVE-2008-6427 EXP | SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex… | Patch early | 6.8 medium | 1.7% | 2009-03-06 |
| CVE-2009-1616 EXP | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 1.7% | 2009-05-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt