CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2806 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 5.8 medium | 1.6% | 2007-05-22 |
| CVE-2007-1479 EXP | Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.6% | 2007-03-16 |
| CVE-2019-11368 EXP | Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter. | Patch early | 5.4 medium | 1.6% | 2019-06-03 |
| CVE-2008-2024 EXP | Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers t… | Patch early | 4.3 medium | 1.5% | 2008-04-30 |
| CVE-2006-2365 EXP | Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parame… | Patch early | 5.8 medium | 1.5% | 2006-05-15 |
| CVE-2007-0590 EXP | Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra para… | Patch early | 5.8 medium | 1.5% | 2007-01-30 |
| CVE-2008-0258 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.5% | 2008-01-15 |
| CVE-2007-3888 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.5% | 2007-07-18 |
| CVE-2007-4178 EXP | Cross-site scripting (XSS) vulnerability in index.php in WebDirector 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.5% | 2007-08-08 |
| CVE-2009-3222 EXP | Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.5% | 2009-09-16 |
| CVE-2009-3858 EXP | Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default U… | Patch early | 4.3 medium | 1.5% | 2009-11-04 |
| CVE-2009-4403 EXP | Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INF… | Patch early | 4.3 medium | 1.5% | 2009-12-23 |
| CVE-2009-4793 EXP | Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute… | Patch early | 6.0 medium | 1.5% | 2010-04-22 |
| CVE-2005-4256 EXP | Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the f… | Patch early | 4.3 medium | 1.5% | 2005-12-15 |
| CVE-2008-2987 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO t… | Patch early | 4.3 medium | 1.5% | 2008-07-02 |
| CVE-2009-3593 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id pa… | Patch early | 4.3 medium | 1.5% | 2009-10-08 |
| CVE-2011-4561 EXP | Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INF… | Patch early | 4.3 medium | 1.5% | 2011-11-28 |
| CVE-2008-6823 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware… | Patch early | 6.8 medium | 1.5% | 2009-06-04 |
| CVE-2006-2178 EXP | Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID… | Patch early | 5.8 medium | 1.5% | 2006-05-04 |
| CVE-2008-2202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ke… | Patch early | 4.3 medium | 1.5% | 2008-05-14 |
| CVE-2011-4335 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH… | Patch early | 4.3 medium | 1.5% | 2011-11-28 |
| CVE-2011-4836 EXP | Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2011-12-15 |
| CVE-2010-4893 EXP | Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the cate… | Patch early | 4.3 medium | 1.5% | 2011-10-08 |
| CVE-2008-1560 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 1.5% | 2008-03-31 |
| CVE-2008-3668 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary w… | Patch early | 4.3 medium | 1.5% | 2008-08-13 |
| CVE-2008-4179 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id par… | Patch early | 4.3 medium | 1.5% | 2008-09-23 |
| CVE-2012-6448 EXP | Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vect… | Patch early | 6.1 medium | 1.5% | 2020-01-27 |
| CVE-2007-2879 EXP | Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.5% | 2007-05-29 |
| CVE-2015-4420 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (… | Patch early | 4.3 medium | 1.5% | 2015-06-18 |
| CVE-2007-3170 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH… | Patch early | 4.3 medium | 1.5% | 2007-06-11 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt