peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,879 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-5810 EXP Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTM… Patch early 6.8 medium 1.6% 2006-11-08
CVE-2010-0725 EXP Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary web script or HTML via the id… Patch early 4.3 medium 1.6% 2010-02-26
CVE-2010-1872 EXP Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.6% 2010-05-12
CVE-2008-6259 EXP Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 1.6% 2009-02-24
CVE-2012-1990 EXP Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject… Patch early 4.3 medium 1.6% 2012-05-22
CVE-2011-0546 EXP Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, wh… Patch early 6.5 medium 1.6% 2011-05-31
CVE-2012-2909 EXP Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text… Patch early 4.3 medium 1.6% 2012-05-21
CVE-2012-2911 EXP Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.6% 2012-05-21
CVE-2012-2918 EXP Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.6% 2012-05-21
CVE-2003-20001 EXP An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external ca… Patch early 5.6 medium 1.6% 2025-04-01
CVE-2018-14869 EXP PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile. Patch early 5.4 medium 1.6% 2018-08-06
CVE-2011-5026 EXP Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inje… Patch early 4.3 medium 1.6% 2011-12-29
CVE-2007-1142 EXP Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_paramete… Patch early 4.3 medium 1.6% 2007-03-02
CVE-2002-2341 EXP Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.6% 2002-12-31
CVE-2002-2362 EXP Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the no… Patch early 4.3 medium 1.6% 2002-12-31
CVE-2008-4426 EXP Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitr… Patch early 4.3 medium 1.6% 2008-10-03
CVE-2010-1950 EXP SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows rem… Patch early 6.8 medium 1.6% 2010-05-19
CVE-2010-2613 EXP Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitra… Patch early 4.3 medium 1.6% 2010-07-02
CVE-2008-6087 EXP Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the na… Patch early 4.3 medium 1.6% 2009-02-06
CVE-2008-6529 EXP Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.6% 2009-03-26
CVE-2006-1912 EXP MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to i… Patch early 5.8 medium 1.6% 2006-04-20
CVE-2012-1782 EXP Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.6% 2012-03-19
CVE-2015-3214 EXP The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, wh… Patch early 6.9 medium 1.6% 2015-08-31
CVE-2005-3555 EXP Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arb… Patch early 6.5 medium 1.6% 2005-11-16
CVE-2024-1234 EXP The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and inc… Patch early 6.4 medium 1.6% 2024-03-13
CVE-2024-41358 EXP phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. Patch early 6.1 medium 1.6% 2024-08-29
CVE-1999-0672 EXP Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics. Patch early 5.1 medium 1.6% 1999-08-01
CVE-1999-0673 EXP Buffer overflow in ALMail32 POP3 client via From: or To: headers. Patch early 5.1 medium 1.6% 1999-08-08
CVE-1999-0685 EXP Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option. Patch early 5.1 medium 1.6% 1999-09-02
CVE-2007-0023 EXP The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows loca… Patch early 6.9 medium 1.6% 2007-01-24
← previous page 279 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt