CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,813 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2012-6510 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.6% | 2013-01-24 |
| CVE-2007-1382 EXP | The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demon… | Patch early | 6.8 medium | 1.6% | 2007-03-10 |
| CVE-2006-2127 EXP | SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter. | Patch early | 6.4 medium | 1.6% | 2006-05-01 |
| CVE-2006-6300 EXP | Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | Patch early | 4.3 medium | 1.6% | 2006-12-05 |
| CVE-2009-4926 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.6% | 2010-07-12 |
| CVE-2002-1168 EXP | Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execut… | Patch early | 6.8 medium | 1.6% | 2002-11-04 |
| CVE-2003-0295 EXP | Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via… | Patch early | 6.8 medium | 1.6% | 2003-06-16 |
| CVE-2008-0278 EXP | SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day p… | Patch early | 6.0 medium | 1.6% | 2008-01-15 |
| CVE-2021-40577 EXP | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0… | Patch early | 5.4 medium | 1.6% | 2021-11-08 |
| CVE-2023-0912 EXP | A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /a… | Patch early | 4.7 medium | 1.6% | 2023-02-18 |
| CVE-2023-0913 EXP | A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the f… | Patch early | 4.7 medium | 1.6% | 2023-02-18 |
| CVE-2012-3836 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 1.6% | 2012-07-03 |
| CVE-2012-3837 EXP | Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to… | Patch early | 4.3 medium | 1.6% | 2012-07-03 |
| CVE-2012-3840 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 1.6% | 2012-07-03 |
| CVE-2012-4236 EXP | Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Sour… | Patch early | 4.3 medium | 1.6% | 2012-08-20 |
| CVE-2012-4871 EXP | Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers t… | Patch early | 4.3 medium | 1.6% | 2012-09-06 |
| CVE-2012-5899 EXP | Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.6% | 2012-11-17 |
| CVE-2007-1241 EXP | Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PAT… | Patch early | 5.8 medium | 1.6% | 2007-03-03 |
| CVE-2012-0989 EXP | Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbi… | Patch early | 4.3 medium | 1.6% | 2012-10-01 |
| CVE-2012-4336 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.6% | 2012-09-15 |
| CVE-2012-4873 EXP | Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.6% | 2012-09-06 |
| CVE-2012-5295 EXP | Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.6% | 2012-10-04 |
| CVE-2012-5330 EXP | Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_IN… | Patch early | 4.3 medium | 1.6% | 2012-10-08 |
| CVE-2012-6557 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.6% | 2013-05-23 |
| CVE-2012-6559 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment,… | Patch early | 4.3 medium | 1.6% | 2013-05-23 |
| CVE-2014-3434 EXP | Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition bef… | Patch early | 6.9 medium | 1.6% | 2014-08-06 |
| CVE-2007-3983 EXP | Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveRepo… | Patch early | 5.0 medium | 1.6% | 2007-07-25 |
| CVE-2012-2172 EXP | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10… | Patch early | 4.3 medium | 1.6% | 2012-06-22 |
| CVE-2012-6043 EXP | Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.6% | 2012-11-26 |
| CVE-2002-1016 EXP | Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operat… | Patch early | 4.6 medium | 1.6% | 2002-10-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt