peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,025 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2005-4229 EXP Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction 1.53 and earlier allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.7% 2005-12-14
CVE-2005-4298 EXP Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.7% 2005-12-16
CVE-2005-4299 EXP Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.7% 2005-12-16
CVE-2005-4311 EXP Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.7% 2005-12-17
CVE-2005-4375 EXP Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change paramet… Patch early 4.3 medium 1.7% 2005-12-20
CVE-2005-4399 EXP Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary we… Patch early 4.3 medium 1.7% 2005-12-20
CVE-2005-4497 EXP Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2005-12-22
CVE-2006-0699 EXP Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbi… Patch early 4.3 medium 1.7% 2006-02-15
CVE-2004-1410 EXP Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is… Patch early 4.3 medium 1.7% 2004-12-31
CVE-2004-1975 EXP Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.7% 2004-04-27
CVE-2005-0863 EXP Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parame… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2005-1027 EXP Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2005-1171 EXP Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2017-6547 EXP Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC8… Patch early 6.1 medium 1.7% 2017-03-09
CVE-2002-1958 EXP Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascri… Patch early 4.3 medium 1.7% 2002-12-31
CVE-2014-0793 EXP Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers… Patch early 4.3 medium 1.7% 2014-01-30
CVE-2012-2452 EXP Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 6.1 medium 1.7% 2020-02-11
CVE-2006-2873 EXP Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber 4.2 allows remote attackers to inject arbitrary web script or HTML via the il par… Patch early 4.3 medium 1.7% 2006-06-06
CVE-2006-4454 EXP Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web script or HTML via the q param… Patch early 4.3 medium 1.7% 2006-08-30
CVE-2015-2198 EXP Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2015-03-03
CVE-2010-4612 EXP Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary… Patch early 6.8 medium 1.7% 2010-12-29
CVE-2005-4247 EXP Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.7% 2005-12-14
CVE-2020-29240 EXP Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an… Patch early 4.8 medium 1.7% 2020-12-02
CVE-2006-2037 EXP Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2006-04-26
CVE-2009-1735 EXP Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt… Patch early 4.3 medium 1.7% 2009-05-20
CVE-2009-2399 EXP PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attac… Patch early 6.8 medium 1.7% 2009-07-09
CVE-2009-2769 EXP PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers… Patch early 6.8 medium 1.7% 2009-08-14
CVE-2008-2981 EXP PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows… Patch early 6.8 medium 1.7% 2008-07-02
CVE-2007-6700 EXP Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject ar… Patch early 4.3 medium 1.7% 2008-02-05
CVE-2006-7112 EXP Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via… Patch early 6.0 medium 1.7% 2007-03-06
← previous page 279 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt