peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,891 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,030 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2006-2177 EXP Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat para… Patch early 4.3 medium 1.7% 2006-05-04
CVE-2010-4276 EXP Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla 3.2.0.2 allows remote at… Patch early 4.3 medium 1.7% 2010-12-30
CVE-2010-4949 EXP Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Jo… Patch early 4.3 medium 1.7% 2011-10-09
CVE-2018-11508 EXP The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memo… Patch early 5.5 medium 1.7% 2018-05-28
CVE-2005-0548 EXP Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2005-03-07
CVE-2005-0829 EXP Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2005-2560 EXP Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parame… Patch early 4.3 medium 1.7% 2005-08-16
CVE-2006-0073 EXP Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 1.7% 2006-01-04
CVE-2002-1497 EXP Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found"… Patch early 4.3 medium 1.7% 2003-04-02
CVE-2023-0904 EXP A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown proces… Patch early 6.3 medium 1.7% 2023-02-18
CVE-2003-0165 EXP Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument f… Patch early 4.6 medium 1.7% 2003-04-02
CVE-2006-0198 EXP Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2006-01-13
CVE-2008-5979 EXP Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2009-01-27
CVE-2026-33534 EXP EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SS… Patch early 4.3 medium 1.7% 2026-04-13
CVE-2018-11715 EXP The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject. Patch early 5.4 medium 1.7% 2018-06-04
CVE-2006-1008 EXP Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir… Patch early 5.8 medium 1.7% 2006-03-06
CVE-2013-0125 EXP Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File… Patch early 4.3 medium 1.7% 2013-04-04
CVE-2012-1470 EXP Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2012-10-01
CVE-2011-4403 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators fo… Patch early 5.8 medium 1.7% 2015-04-24
CVE-2009-2641 EXP PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PH… Patch early 6.8 medium 1.7% 2009-07-28
CVE-2006-4988 EXP Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1… Patch early 4.3 medium 1.7% 2006-09-26
CVE-2006-5503 EXP Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2006-10-25
CVE-2006-5652 EXP Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via… Patch early 4.3 medium 1.7% 2006-11-03
CVE-2006-5825 EXP Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.7% 2006-11-10
CVE-2008-5044 EXP Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded applica… Patch early 4.0 medium 1.7% 2008-11-12
CVE-2011-1668 EXP Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers… Patch early 4.3 medium 1.7% 2011-04-10
CVE-2020-5147 EXP SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in th… Patch early 5.3 medium 1.7% 2021-01-09
CVE-2018-20448 EXP Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. Patch early 5.4 medium 1.7% 2018-12-25
CVE-2006-4985 EXP Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary web script or HTML via (1) th… Patch early 4.3 medium 1.7% 2006-09-26
CVE-2006-4742 EXP Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.7% 2006-09-13
← previous page 280 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt