CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,905 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,030 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-4771 EXP | Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte… | Patch early | 4.3 medium | 1.7% | 2006-09-14 |
| CVE-2017-15291 EXP | Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject ar… | Patch early | 6.1 medium | 1.7% | 2017-10-20 |
| CVE-2009-2882 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show param… | Patch early | 4.3 medium | 1.7% | 2009-08-20 |
| CVE-2012-2996 EXP | Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow… | Patch early | 6.8 medium | 1.7% | 2012-09-17 |
| CVE-2007-5027 EXP | Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94… | Patch early | 4.3 medium | 1.7% | 2007-09-21 |
| CVE-2007-2090 EXP | Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 6.8 medium | 1.7% | 2007-04-18 |
| CVE-2006-6536 EXP | Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 6.8 medium | 1.7% | 2006-12-14 |
| CVE-2021-31327 EXP | Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. | Patch early | 5.4 medium | 1.7% | 2021-04-21 |
| CVE-2021-31329 EXP | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php | Patch early | 5.4 medium | 1.7% | 2021-04-21 |
| CVE-2001-0941 EXP | Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. | Patch early | 4.6 medium | 1.7% | 2001-11-30 |
| CVE-2004-0678 EXP | Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other… | Patch early | 4.3 medium | 1.7% | 2004-08-06 |
| CVE-2012-2570 EXP | Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2012-08-15 |
| CVE-2012-5322 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName pa… | Patch early | 4.3 medium | 1.7% | 2012-10-08 |
| CVE-2006-5564 EXP | Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op… | Patch early | 4.3 medium | 1.7% | 2006-10-27 |
| CVE-2012-4998 EXP | Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Patch early | 4.3 medium | 1.7% | 2012-09-19 |
| CVE-2025-47171 EXP | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | Patch early | 6.7 medium | 1.7% | 2025-06-10 |
| CVE-2004-2718 EXP | PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database p… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2010-3489 EXP | Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remo… | Patch early | 4.3 medium | 1.7% | 2010-09-22 |
| CVE-2009-4467 EXP | misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre… | Patch early | 4.0 medium | 1.7% | 2009-12-30 |
| CVE-2009-2440 EXP | Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page… | Patch early | 4.3 medium | 1.7% | 2009-07-13 |
| CVE-2006-5712 EXP | Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Styl… | Patch early | 4.3 medium | 1.7% | 2006-11-04 |
| CVE-2008-6427 EXP | SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex… | Patch early | 6.8 medium | 1.7% | 2009-03-06 |
| CVE-2009-1616 EXP | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitra… | Patch early | 4.3 medium | 1.7% | 2009-05-11 |
| CVE-2018-8732 EXP | Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parame… | Patch early | 5.4 medium | 1.7% | 2018-03-19 |
| CVE-2012-2910 EXP | Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.7% | 2012-05-21 |
| CVE-2009-4319 EXP | PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remote… | Patch early | 6.8 medium | 1.7% | 2009-12-14 |
| CVE-2018-18416 EXP | LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/u… | Patch early | 4.8 medium | 1.7% | 2018-10-19 |
| CVE-2018-10763 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Pa… | Patch early | 4.8 medium | 1.7% | 2018-09-14 |
| CVE-2006-3358 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via… | Patch early | 6.8 medium | 1.6% | 2006-07-06 |
| CVE-2009-4174 EXP | The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with… | Patch early | 6.0 medium | 1.6% | 2009-12-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt