peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,413 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-0983 EXP Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page par… Patch early 4.3 medium 2% 2006-03-03
CVE-2006-0984 EXP Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 2% 2006-03-03
CVE-2007-1291 EXP Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script… Patch early 5.8 medium 2% 2007-03-07
CVE-2006-0675 EXP Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q par… Patch early 4.3 medium 2% 2006-02-13
CVE-2006-0885 EXP Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the sho… Patch early 4.3 medium 2% 2006-02-25
CVE-2006-1344 EXP Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 2% 2006-03-22
CVE-2004-1978 EXP Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text… Patch early 4.3 medium 2% 2004-04-30
CVE-2005-0925 EXP Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 2% 2005-05-02
CVE-2005-3515 EXP Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 2% 2005-11-06
CVE-2005-3516 EXP Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 2% 2005-11-06
CVE-2005-4293 EXP Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2% 2005-12-16
CVE-2006-0210 EXP Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 2% 2006-01-14
CVE-2008-0300 EXP mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are… Patch early 6.8 medium 2% 2008-03-11
CVE-2008-0681 EXP SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as d… Patch early 6.8 medium 2% 2008-02-12
CVE-2007-2148 EXP Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated a… Patch early 6.5 medium 2% 2007-04-19
CVE-2012-2906 EXP Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to in… Patch early 4.3 medium 2% 2012-05-21
CVE-2004-0251 EXP Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter. Patch early 6.8 medium 2% 2004-11-23
CVE-2004-0254 EXP Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img ta… Patch early 6.8 medium 2% 2004-11-23
CVE-2004-0305 EXP Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other use… Patch early 6.8 medium 2% 2004-11-23
CVE-2004-0319 EXP Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demons… Patch early 6.8 medium 2% 2004-11-23
CVE-2004-1210 EXP Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web s… Patch early 6.8 medium 2% 2005-01-10
CVE-2007-2233 EXP cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (… Patch early 6.5 medium 2% 2007-04-25
CVE-2005-4432 EXP Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the err parame… Patch early 4.3 medium 2% 2005-12-21
CVE-2006-2689 EXP Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the… Patch early 6.8 medium 2% 2006-05-31
CVE-2017-16836 EXP Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_manage… Patch early 6.1 medium 2% 2017-11-16
CVE-2007-5190 EXP Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 2% 2007-10-22
CVE-2015-3141 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote attackers to hija… Patch early 6.8 medium 2% 2015-05-20
CVE-2008-3405 EXP Directory traversal vulnerability in index.php in Ricardo Amaral nzFotolog 0.4.1 allows remote attackers to include and execute arbitrary local files… Patch early 6.8 medium 2% 2008-07-31
CVE-2008-3446 EXP Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitrary local files via a .. (dot… Patch early 6.8 medium 2% 2008-08-04
CVE-2014-5462 EXP Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execute arbitrary SQL commands via t… Patch early 6.5 medium 2% 2014-12-08
← previous page 240 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt