peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,905 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,030 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-4771 EXP Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte… Patch early 4.3 medium 1.7% 2006-09-14
CVE-2017-15291 EXP Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject ar… Patch early 6.1 medium 1.7% 2017-10-20
CVE-2009-2882 EXP Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show param… Patch early 4.3 medium 1.7% 2009-08-20
CVE-2012-2996 EXP Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow… Patch early 6.8 medium 1.7% 2012-09-17
CVE-2007-5027 EXP Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94… Patch early 4.3 medium 1.7% 2007-09-21
CVE-2007-2090 EXP Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 1.7% 2007-04-18
CVE-2006-6536 EXP Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via th… Patch early 6.8 medium 1.7% 2006-12-14
CVE-2021-31327 EXP Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. Patch early 5.4 medium 1.7% 2021-04-21
CVE-2021-31329 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php Patch early 5.4 medium 1.7% 2021-04-21
CVE-2001-0941 EXP Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. Patch early 4.6 medium 1.7% 2001-11-30
CVE-2004-0678 EXP Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other… Patch early 4.3 medium 1.7% 2004-08-06
CVE-2012-2570 EXP Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2012-08-15
CVE-2012-5322 EXP Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName pa… Patch early 4.3 medium 1.7% 2012-10-08
CVE-2006-5564 EXP Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op… Patch early 4.3 medium 1.7% 2006-10-27
CVE-2012-4998 EXP Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter. Patch early 4.3 medium 1.7% 2012-09-19
CVE-2025-47171 EXP Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. Patch early 6.7 medium 1.7% 2025-06-10
CVE-2004-2718 EXP PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database p… Patch early 4.3 medium 1.7% 2004-12-31
CVE-2010-3489 EXP Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remo… Patch early 4.3 medium 1.7% 2010-09-22
CVE-2009-4467 EXP misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre… Patch early 4.0 medium 1.7% 2009-12-30
CVE-2009-2440 EXP Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page… Patch early 4.3 medium 1.7% 2009-07-13
CVE-2006-5712 EXP Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Styl… Patch early 4.3 medium 1.7% 2006-11-04
CVE-2008-6427 EXP SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex… Patch early 6.8 medium 1.7% 2009-03-06
CVE-2009-1616 EXP Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitra… Patch early 4.3 medium 1.7% 2009-05-11
CVE-2018-8732 EXP Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parame… Patch early 5.4 medium 1.7% 2018-03-19
CVE-2012-2910 EXP Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.7% 2012-05-21
CVE-2009-4319 EXP PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remote… Patch early 6.8 medium 1.7% 2009-12-14
CVE-2018-18416 EXP LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/u… Patch early 4.8 medium 1.7% 2018-10-19
CVE-2018-10763 EXP Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Pa… Patch early 4.8 medium 1.7% 2018-09-14
CVE-2006-3358 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via… Patch early 6.8 medium 1.6% 2006-07-06
CVE-2009-4174 EXP The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with… Patch early 6.0 medium 1.6% 2009-12-02
← previous page 281 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt