CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,025 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2002-2021 EXP | Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2006-1634 EXP | Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the com… | Patch early | 4.3 medium | 1.7% | 2006-04-06 |
| CVE-2005-4675 EXP | Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c… | Patch early | 4.3 medium | 1.7% | 2005-12-31 |
| CVE-2012-2984 EXP | Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 allow remote attackers to injec… | Patch early | 4.3 medium | 1.7% | 2012-08-24 |
| CVE-2012-6556 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.7% | 2013-05-23 |
| CVE-2022-0020 EXP | A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to s… | Patch early | 6.8 medium | 1.7% | 2022-02-10 |
| CVE-2020-29470 EXP | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS pa… | Patch early | 4.8 medium | 1.7% | 2020-12-29 |
| CVE-2006-2269 EXP | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a… | Patch early | 4.3 medium | 1.7% | 2006-05-09 |
| CVE-2006-4634 EXP | Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID paramete… | Patch early | 4.3 medium | 1.7% | 2006-09-08 |
| CVE-2004-2008 EXP | SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter. | Patch early | 4.6 medium | 1.7% | 2004-05-08 |
| CVE-2008-5939 EXP | Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.7% | 2009-01-22 |
| CVE-2008-7089 EXP | Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword param… | Patch early | 4.3 medium | 1.7% | 2009-08-26 |
| CVE-2008-1906 EXP | Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the ye… | Patch early | 4.3 medium | 1.7% | 2008-04-22 |
| CVE-2008-4888 EXP | Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.7% | 2008-11-04 |
| CVE-2006-0871 EXP | Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read a… | Patch early | 6.4 medium | 1.7% | 2006-02-24 |
| CVE-2019-14221 EXP | 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. | Patch early | 5.4 medium | 1.7% | 2019-08-08 |
| CVE-2002-2358 EXP | Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web sc… | Patch early | 4.3 medium | 1.7% | 2002-12-31 |
| CVE-2006-3189 EXP | Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web sc… | Patch early | 5.8 medium | 1.7% | 2006-06-23 |
| CVE-2006-3186 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpat… | Patch early | 4.3 medium | 1.7% | 2006-06-23 |
| CVE-2006-4421 EXP | Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers… | Patch early | 4.3 medium | 1.7% | 2006-08-29 |
| CVE-2006-5512 EXP | Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2006-10-25 |
| CVE-2008-1225 EXP | Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated use… | Patch early | 4.3 medium | 1.7% | 2008-03-10 |
| CVE-2013-6229 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2014-02-12 |
| CVE-2006-2089 EXP | Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.7% | 2006-04-29 |
| CVE-2006-3195 EXP | Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.7% | 2006-06-23 |
| CVE-2006-3948 EXP | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query p… | Patch early | 4.3 medium | 1.7% | 2006-08-01 |
| CVE-2006-4009 EXP | Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.7% | 2006-08-07 |
| CVE-2006-4747 EXP | Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id p… | Patch early | 4.3 medium | 1.7% | 2006-09-13 |
| CVE-2005-2476 EXP | Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2005-08-05 |
| CVE-2005-4063 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script v… | Patch early | 4.3 medium | 1.7% | 2005-12-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt