CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,922 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6162 EXP | Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id para… | Patch early | 4.3 medium | 1.5% | 2007-11-29 |
| CVE-2008-0679 EXP | Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search par… | Patch early | 4.3 medium | 1.5% | 2008-02-12 |
| CVE-2008-1173 EXP | Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.5% | 2008-03-06 |
| CVE-2008-1967 EXP | Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2008-04-27 |
| CVE-2008-2677 EXP | Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2008-06-12 |
| CVE-2008-2973 EXP | Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2008-07-02 |
| CVE-2008-3184 EXP | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers… | Patch early | 4.3 medium | 1.5% | 2008-07-15 |
| CVE-2008-3483 EXP | Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error… | Patch early | 4.3 medium | 1.5% | 2008-08-05 |
| CVE-2008-3917 EXP | Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field… | Patch early | 4.3 medium | 1.5% | 2008-09-04 |
| CVE-2008-4379 EXP | Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 1.5% | 2008-10-01 |
| CVE-2008-4438 EXP | Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.5% | 2008-10-03 |
| CVE-2008-4591 EXP | Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary… | Patch early | 4.3 medium | 1.5% | 2008-10-16 |
| CVE-2008-4756 EXP | Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the dat… | Patch early | 4.3 medium | 1.5% | 2008-10-28 |
| CVE-2008-5264 EXP | Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbit… | Patch early | 4.3 medium | 1.5% | 2008-11-28 |
| CVE-2008-6700 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.5% | 2009-04-10 |
| CVE-2008-6757 EXP | Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 1.5% | 2009-04-28 |
| CVE-2008-6915 EXP | Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.5% | 2009-08-07 |
| CVE-2009-0710 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user… | Patch early | 4.3 medium | 1.5% | 2009-02-23 |
| CVE-2009-1593 EXP | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows rem… | Patch early | 4.3 medium | 1.5% | 2009-05-21 |
| CVE-2009-2391 EXP | Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.5% | 2009-07-09 |
| CVE-2004-2701 EXP | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.5% | 2004-12-31 |
| CVE-2025-51403 EXP | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute… | Patch early | 6.5 medium | 1.5% | 2025-07-21 |
| CVE-2009-4869 EXP | Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the p… | Patch early | 4.3 medium | 1.5% | 2010-05-11 |
| CVE-2019-13977 EXP | index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&… | Patch early | 5.4 medium | 1.5% | 2019-07-19 |
| CVE-2008-2783 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbi… | Patch early | 4.3 medium | 1.5% | 2008-06-19 |
| CVE-2013-1410 EXP | Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities | Patch early | 6.1 medium | 1.5% | 2020-02-12 |
| CVE-2010-4877 EXP | Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the view para… | Patch early | 4.3 medium | 1.5% | 2011-10-07 |
| CVE-2014-4645 EXP | Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a… | Patch early | 4.3 medium | 1.5% | 2014-06-25 |
| CVE-2014-5088 EXP | Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. | Patch early | 4.3 medium | 1.5% | 2014-08-06 |
| CVE-2009-3513 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1… | Patch early | 4.3 medium | 1.5% | 2009-10-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt