peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,734 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

170,949 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2011-0005 EXP Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.8% 2011-01-11
CVE-2006-2390 EXP Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in t… Patch early 5.8 medium 1.8% 2006-05-16
CVE-2021-30030 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. Patch early 5.4 medium 1.8% 2021-04-13
CVE-2021-30034 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. Patch early 5.4 medium 1.8% 2021-04-13
CVE-2021-30039 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php. Patch early 5.4 medium 1.8% 2021-04-13
CVE-2021-30042 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register… Patch early 5.4 medium 1.8% 2021-04-13
CVE-2021-30044 EXP Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. Patch early 5.4 medium 1.8% 2021-04-13
CVE-2006-3974 EXP Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject… Patch early 4.3 medium 1.8% 2007-06-11
CVE-2007-4334 EXP Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP p… Patch early 4.3 medium 1.8% 2007-08-14
CVE-2005-0857 EXP Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.8% 2005-05-02
CVE-2003-1271 EXP Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL con… Patch early 4.3 medium 1.8% 2003-12-31
CVE-2006-5983 EXP Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users to inject arbitrary web scrip… Patch early 6.0 medium 1.8% 2006-11-20
CVE-2007-2908 EXP Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.8% 2007-05-30
CVE-2026-24421 EXP phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoint… Patch early 6.5 medium 1.8% 2026-01-24
CVE-2005-2588 EXP Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1)… Patch early 4.3 medium 1.8% 2005-08-17
CVE-2007-2013 EXP Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.8% 2007-04-12
CVE-2007-3212 EXP Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.8% 2007-06-14
CVE-2008-7208 EXP Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) usern… Patch early 6.8 medium 1.8% 2009-09-11
CVE-2009-3512 EXP Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date par… Patch early 4.3 medium 1.8% 2009-10-01
CVE-2006-3191 EXP Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid para… Patch early 4.3 medium 1.8% 2006-06-23
CVE-2006-4295 EXP Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.8% 2006-08-23
CVE-2004-1844 EXP Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the er… Patch early 4.3 medium 1.8% 2004-12-31
CVE-2005-2488 EXP Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1)… Patch early 4.3 medium 1.8% 2005-08-07
CVE-2005-2674 EXP Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to i… Patch early 4.3 medium 1.8% 2005-08-23
CVE-2006-2725 EXP SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 6.4 medium 1.8% 2006-06-01
CVE-2007-1508 EXP Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESUL… Patch early 4.3 medium 1.8% 2007-03-20
CVE-2006-3143 EXP Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attacker… Patch early 4.0 medium 1.8% 2006-06-22
CVE-2019-25046 EXP The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. Patch early 6.1 medium 1.8% 2021-06-10
CVE-2008-2668 EXP Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q param… Patch early 4.3 medium 1.8% 2008-06-12
CVE-2010-4850 EXP Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_co… Patch early 4.3 medium 1.8% 2011-09-27
← previous page 269 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt