CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6675 EXP | Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the clo… | Patch early | 4.3 medium | 1.7% | 2009-04-08 |
| CVE-2009-1070 EXP | Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote att… | Patch early | 4.3 medium | 1.7% | 2009-03-26 |
| CVE-2006-1634 EXP | Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the com… | Patch early | 4.3 medium | 1.7% | 2006-04-06 |
| CVE-2002-1803 EXP | Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2002-1804 EXP | Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2002-2021 EXP | Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2004-2076 EXP | Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2004-2308 EXP | Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the d… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2005-1081 EXP | Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.7% | 2005-05-02 |
| CVE-2005-4675 EXP | Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2012-2984 EXP | Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 allow remote attackers to injec… | Patch early | 4.3 medium | 1.7% | 2012-08-24 |
| CVE-2012-6556 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.7% | 2013-05-23 |
| CVE-2022-0020 EXP | A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to s… | Patch early | 6.8 medium | 1.7% | 2022-02-10 |
| CVE-2020-29470 EXP | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS pa… | Patch early | 4.8 medium | 1.7% | 2020-12-29 |
| CVE-2006-2269 EXP | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a… | Patch early | 4.3 medium | 1.7% | 2006-05-09 |
| CVE-2006-4634 EXP | Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID paramete… | Patch early | 4.3 medium | 1.7% | 2006-09-08 |
| CVE-2004-2008 EXP | SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter. | Patch early | 4.6 medium | 1.7% | 2004-05-08 |
| CVE-2008-1906 EXP | Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the ye… | Patch early | 4.3 medium | 1.7% | 2008-04-22 |
| CVE-2008-4888 EXP | Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.7% | 2008-11-04 |
| CVE-2008-5939 EXP | Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.7% | 2009-01-22 |
| CVE-2008-7089 EXP | Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword param… | Patch early | 4.3 medium | 1.7% | 2009-08-26 |
| CVE-2006-0871 EXP | Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read a… | Patch early | 6.4 medium | 1.7% | 2006-02-24 |
| CVE-2019-14221 EXP | 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. | Patch early | 5.4 medium | 1.7% | 2019-08-08 |
| CVE-2002-2358 EXP | Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2006-3189 EXP | Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web sc… | Patch early | 5.8 medium | 1.7% | 2006-06-23 |
| CVE-2006-3186 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpat… | Patch early | 4.3 medium | 1.7% | 2006-06-23 |
| CVE-2006-4421 EXP | Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers… | Patch early | 4.3 medium | 1.7% | 2006-08-29 |
| CVE-2006-5512 EXP | Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2006-10-25 |
| CVE-2013-6229 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2014-02-12 |
| CVE-2008-1225 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated use… | Patch early | 4.3 medium | 1.7% | 2008-03-10 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt