peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,696 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-09

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-7457 EXP XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure. Patch early 5.0 medium 1.8% 2017-04-14
CVE-2003-1164 EXP Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inject… Patch early 4.3 medium 1.8% 2003-12-31
CVE-2004-1657 EXP Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 1.8% 2004-09-01
CVE-2004-1692 EXP Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 1.8% 2004-09-18
CVE-2005-4205 EXP Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.8% 2005-12-13
CVE-2005-4774 EXP Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the e… Patch early 4.3 medium 1.8% 2005-12-31
CVE-2012-2938 EXP Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the ho… Patch early 4.3 medium 1.8% 2012-05-27
CVE-2008-6949 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators f… Patch early 6.8 medium 1.8% 2009-08-12
CVE-2009-1230 EXP Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary P… Patch early 6.5 medium 1.8% 2009-04-02
CVE-2006-2051 EXP Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web scrip… Patch early 5.8 medium 1.8% 2006-04-26
CVE-2006-2176 EXP Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML v… Patch early 5.8 medium 1.8% 2006-05-04
CVE-2006-3405 EXP Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 5.8 medium 1.8% 2006-07-07
CVE-2016-3139 EXP The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial o… Patch early 4.6 medium 1.8% 2016-04-27
CVE-2016-3140 EXP The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a… Patch early 4.6 medium 1.8% 2016-05-02
CVE-2007-5426 EXP Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page pa… Patch early 4.3 medium 1.8% 2007-10-12
CVE-2007-5562 EXP Cross-site scripting (XSS) vulnerability in cgi-bin/welcome (aka the login page) in Netgear SSL312 PROSAFE SSL VPN-Concentrator 25 allows remote attac… Patch early 4.3 medium 1.8% 2007-10-18
CVE-2010-4836 EXP Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.8% 2011-09-14
CVE-2004-1418 EXP Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail a… Patch early 4.3 medium 1.8% 2004-12-31
CVE-2008-1180 EXP Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attac… Patch early 4.3 medium 1.8% 2008-03-06
CVE-2008-2187 EXP Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.8% 2008-05-13
CVE-2008-4393 EXP Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitr… Patch early 4.3 medium 1.8% 2008-10-07
CVE-2008-4742 EXP Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.8% 2008-10-27
CVE-2009-1458 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.8% 2009-04-28
CVE-2006-6936 EXP Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catnam… Patch early 6.8 medium 1.8% 2007-01-17
CVE-2018-1186 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2018-1187 EXP Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in th… Patch early 4.8 medium 1.8% 2018-03-26
CVE-2009-2772 EXP Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.8% 2009-08-14
CVE-2018-8772 EXP Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. Patch early 6.1 medium 1.8% 2018-04-10
CVE-2010-5046 EXP Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter. Patch early 4.3 medium 1.8% 2011-11-23
CVE-2007-5944 EXP Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows r… Patch early 4.3 medium 1.8% 2007-11-14
← previous page 261 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt