peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,922 CVEs 1,739 on KEV 17,301 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,041 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0278 EXP SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day p… Patch early 6.0 medium 1.6% 2008-01-15
CVE-2021-40577 EXP A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0… Patch early 5.4 medium 1.6% 2021-11-08
CVE-2023-0912 EXP A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /a… Patch early 4.7 medium 1.6% 2023-02-18
CVE-2023-0913 EXP A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the f… Patch early 4.7 medium 1.6% 2023-02-18
CVE-2012-3836 EXP Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (… Patch early 4.3 medium 1.6% 2012-07-03
CVE-2012-3837 EXP Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to… Patch early 4.3 medium 1.6% 2012-07-03
CVE-2012-3840 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary we… Patch early 4.3 medium 1.6% 2012-07-03
CVE-2012-4236 EXP Cross-site scripting (XSS) vulnerability in the refresh_page function in application/modules/_main/views/_top.php in Total Shop UK eCommerce Open Sour… Patch early 4.3 medium 1.6% 2012-08-20
CVE-2012-4871 EXP Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers t… Patch early 4.3 medium 1.6% 2012-09-06
CVE-2012-5899 EXP Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.6% 2012-11-17
CVE-2007-1241 EXP Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PAT… Patch early 5.8 medium 1.6% 2007-03-03
CVE-2012-4336 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.6% 2012-09-15
CVE-2012-4873 EXP Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.6% 2012-09-06
CVE-2012-5295 EXP Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.6% 2012-10-04
CVE-2012-5330 EXP Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_IN… Patch early 4.3 medium 1.6% 2012-10-08
CVE-2012-6557 EXP Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.6% 2013-05-23
CVE-2012-6559 EXP Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment,… Patch early 4.3 medium 1.6% 2013-05-23
CVE-2012-0989 EXP Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbi… Patch early 4.3 medium 1.6% 2012-10-01
CVE-2014-3434 EXP Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition bef… Patch early 6.9 medium 1.6% 2014-08-06
CVE-2007-3983 EXP Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveRepo… Patch early 5.0 medium 1.6% 2007-07-25
CVE-2012-2172 EXP Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10… Patch early 4.3 medium 1.6% 2012-06-22
CVE-2012-6043 EXP Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.6% 2012-11-26
CVE-2002-1016 EXP Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operat… Patch early 4.6 medium 1.6% 2002-10-04
CVE-2006-6544 EXP Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: T… Patch early 6.8 medium 1.6% 2006-12-14
CVE-2012-4928 EXP Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.6% 2012-09-15
CVE-2012-5341 EXP Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.6% 2012-10-09
CVE-2012-5903 EXP Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the s… Patch early 4.3 medium 1.6% 2012-11-17
CVE-2012-6045 EXP Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.6% 2012-11-27
CVE-2012-1898 EXP Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary… Patch early 4.3 medium 1.6% 2012-10-01
CVE-2006-5529 EXP Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary… Patch early 5.1 medium 1.6% 2006-10-26
← previous page 283 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt