CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,879 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,011 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2014-3247 EXP | Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc param… | Patch early | 4.3 medium | 1.7% | 2014-05-15 |
| CVE-2005-3577 EXP | Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.7% | 2005-11-16 |
| CVE-2005-3730 EXP | Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject ar… | Patch early | 4.3 medium | 1.7% | 2005-11-21 |
| CVE-2005-3834 EXP | Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.7% | 2005-11-26 |
| CVE-2005-4435 EXP | Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the titl… | Patch early | 4.3 medium | 1.7% | 2005-12-21 |
| CVE-2005-4670 EXP | Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2006-0222 EXP | Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.7% | 2006-01-16 |
| CVE-2006-0237 EXP | Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat… | Patch early | 4.3 medium | 1.7% | 2006-01-18 |
| CVE-2006-0317 EXP | Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.7% | 2006-01-19 |
| CVE-2006-0415 EXP | Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.7% | 2006-01-25 |
| CVE-2006-0933 EXP | Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XC… | Patch early | 4.3 medium | 1.7% | 2006-02-28 |
| CVE-2006-1215 EXP | Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2006-03-14 |
| CVE-2002-1493 EXP | Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2… | Patch early | 4.3 medium | 1.7% | 2003-04-02 |
| CVE-2003-1088 EXP | Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the met… | Patch early | 4.3 medium | 1.7% | 2003-08-11 |
| CVE-2006-1682 EXP | Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.7% | 2006-04-11 |
| CVE-2004-1412 EXP | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the se… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2004-1817 EXP | Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Y… | Patch early | 4.3 medium | 1.7% | 2004-03-15 |
| CVE-2004-1930 EXP | Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remot… | Patch early | 4.3 medium | 1.7% | 2004-04-12 |
| CVE-2004-2294 EXP | Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2004-2508 EXP | Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2004-2566 EXP | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFo… | Patch early | 4.3 medium | 1.7% | 2004-12-31 |
| CVE-2005-0945 EXP | Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload ev… | Patch early | 4.3 medium | 1.7% | 2005-05-02 |
| CVE-2005-1130 EXP | Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg param… | Patch early | 4.3 medium | 1.7% | 2005-04-12 |
| CVE-2005-1135 EXP | Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.7% | 2005-05-02 |
| CVE-2005-1494 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2005-05-11 |
| CVE-2005-1587 EXP | Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWor… | Patch early | 4.3 medium | 1.7% | 2005-05-14 |
| CVE-2007-4975 EXP | Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter… | Patch early | 4.3 medium | 1.7% | 2007-09-19 |
| CVE-2008-5761 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.7% | 2008-12-30 |
| CVE-2008-6097 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1)… | Patch early | 4.3 medium | 1.7% | 2009-02-09 |
| CVE-2008-0432 EXP | Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2008-01-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt