peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,063 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-5263 EXP The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS. Patch early 5.4 medium 1.6% 2018-01-08
CVE-2017-16781 EXP The installer in MyBB before 1.8.13 has XSS. Patch early 5.4 medium 1.6% 2017-11-10
CVE-2008-1726 EXP Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL comma… Patch early 6.8 medium 1.6% 2008-04-11
CVE-2008-6985 EXP Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allo… Patch early 6.8 medium 1.6% 2009-08-19
CVE-2021-22557 EXP SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generat… Patch early 5.3 medium 1.6% 2021-10-04
CVE-2018-6190 EXP Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. Patch early 5.4 medium 1.6% 2018-01-24
CVE-2016-8769 EXP Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service que… Patch early 6.7 medium 1.6% 2017-04-02
CVE-2004-2134 EXP Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords. Patch early 4.6 medium 1.6% 2004-01-28
CVE-2007-0982 EXP Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMe… Patch early 4.3 medium 1.6% 2007-02-16
CVE-2007-1433 EXP Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.6% 2007-03-13
CVE-2009-2218 EXP Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute a… Patch early 6.8 medium 1.6% 2009-06-25
CVE-2021-28935 EXP CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. Patch early 5.4 medium 1.6% 2021-03-30
CVE-2022-25630 EXP An authenticated user can embed malicious content with XSS into the admin group policy page. Patch early 5.4 medium 1.6% 2022-12-09
CVE-2018-6226 EXP Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to in… Patch early 5.4 medium 1.6% 2018-03-15
CVE-2018-6227 EXP A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts in… Patch early 5.4 medium 1.6% 2018-03-15
CVE-2009-3359 EXP Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 1.6% 2009-09-24
CVE-2007-1482 EXP Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter… Patch early 4.3 medium 1.6% 2007-03-16
CVE-2007-3291 EXP Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name… Patch early 4.3 medium 1.6% 2007-06-20
CVE-2007-6479 EXP Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows… Patch early 4.9 medium 1.6% 2007-12-20
CVE-2008-2048 EXP Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.6% 2008-05-01
CVE-2008-2181 EXP Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.6% 2008-05-13
CVE-2008-2644 EXP Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1)… Patch early 4.3 medium 1.6% 2008-06-10
CVE-2008-3180 EXP Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrar… Patch early 4.3 medium 1.6% 2008-07-15
CVE-2008-3581 EXP Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_me… Patch early 4.3 medium 1.6% 2008-08-10
CVE-2008-3923 EXP Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arb… Patch early 4.3 medium 1.6% 2008-09-04
CVE-2008-5193 EXP Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.6% 2008-11-21
CVE-2008-5487 EXP Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.6% 2008-12-12
CVE-2008-5591 EXP Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.6% 2008-12-16
CVE-2008-5854 EXP Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.6% 2009-01-06
CVE-2022-47529 EXP Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify… Patch early 6.7 medium 1.6% 2023-03-28
← previous page 286 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt