CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-11403 EXP | DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter. | Patch early | 5.4 medium | 1.7% | 2018-05-24 |
| CVE-2013-4865 EXP | Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack th… | Patch early | 6.5 medium | 1.7% | 2020-01-28 |
| CVE-2008-7117 EXP | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with t… | Patch early | 5.0 medium | 1.7% | 2009-08-28 |
| CVE-2009-2157 EXP | Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the or… | Patch early | 6.5 medium | 1.7% | 2009-06-22 |
| CVE-2007-4522 EXP | Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands vi… | Patch early | 6.0 medium | 1.7% | 2007-08-25 |
| CVE-2007-5218 EXP | Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2007-10-05 |
| CVE-2007-5429 EXP | Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive p… | Patch early | 4.3 medium | 1.7% | 2007-10-12 |
| CVE-2007-6301 EXP | Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2007-12-10 |
| CVE-2008-0496 EXP | Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit pa… | Patch early | 4.3 medium | 1.7% | 2008-01-30 |
| CVE-2008-2967 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inje… | Patch early | 4.3 medium | 1.7% | 2008-07-02 |
| CVE-2008-3404 EXP | Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2008-07-31 |
| CVE-2008-4727 EXP | Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote att… | Patch early | 4.3 medium | 1.7% | 2008-10-24 |
| CVE-2008-5330 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7… | Patch early | 4.3 medium | 1.7% | 2008-12-05 |
| CVE-2009-2595 EXP | Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2009-07-24 |
| CVE-2010-4901 EXP | Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.7% | 2011-10-08 |
| CVE-2010-4907 EXP | Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the u… | Patch early | 4.3 medium | 1.7% | 2011-10-08 |
| CVE-2010-5002 EXP | Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 1.7% | 2011-11-01 |
| CVE-2021-3441 EXP | A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS). | Patch early | 4.8 medium | 1.7% | 2021-10-29 |
| CVE-2007-6126 EXP | Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2007-11-26 |
| CVE-2005-1023 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) m… | Patch early | 4.3 medium | 1.7% | 2005-05-02 |
| CVE-2005-1955 EXP | Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the galle… | Patch early | 4.3 medium | 1.7% | 2005-06-12 |
| CVE-2023-0915 EXP | A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file… | Patch early | 6.3 medium | 1.7% | 2023-02-19 |
| CVE-2005-2814 EXP | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a v… | Patch early | 4.3 medium | 1.7% | 2005-09-07 |
| CVE-2009-4264 EXP | PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote at… | Patch early | 6.8 medium | 1.7% | 2009-12-10 |
| CVE-2014-3978 EXP | SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Na… | Patch early | 6.5 medium | 1.7% | 2014-10-20 |
| CVE-2014-6030 EXP | Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via… | Patch early | 6.5 medium | 1.7% | 2014-11-06 |
| CVE-2006-5530 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.7% | 2006-10-26 |
| CVE-2008-0092 EXP | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to… | Patch early | 4.3 medium | 1.7% | 2008-01-04 |
| CVE-2008-3448 EXP | Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.7% | 2008-08-04 |
| CVE-2013-1647 EXP | Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attacker… | Patch early | 5.0 medium | 1.7% | 2013-09-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt