peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,932 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

10,149 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-6924 EXP Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.5% 2009-08-10
CVE-2008-7036 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for… Patch early 4.3 medium 1.5% 2009-08-24
CVE-2009-2114 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2009-06-18
CVE-2003-1372 EXP Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbi… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2003-1498 EXP Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject ar… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2008-6502 EXP Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a… Patch early 4.6 medium 1.5% 2009-03-20
CVE-2018-10365 EXP An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a… Patch early 5.4 medium 1.5% 2018-05-01
CVE-2007-2805 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to… Patch early 4.3 medium 1.5% 2007-05-22
CVE-2007-3989 EXP Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attac… Patch early 4.3 medium 1.5% 2007-07-25
CVE-2007-4024 EXP Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2007-07-26
CVE-2007-4264 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier a… Patch early 4.3 medium 1.5% 2007-08-09
CVE-2017-16843 EXP Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic. Patch early 5.4 medium 1.5% 2017-11-16
CVE-2020-8493 EXP A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login… Patch early 4.8 medium 1.5% 2020-01-30
CVE-2011-4809 EXP Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to… Patch early 4.3 medium 1.5% 2011-12-14
CVE-2011-5041 EXP Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d… Patch early 4.3 medium 1.5% 2011-12-30
CVE-2008-5869 EXP Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated users to inject arb… Patch early 4.3 medium 1.5% 2009-01-08
CVE-2009-1281 EXP Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto… Patch early 4.3 medium 1.5% 2009-04-09
CVE-2010-5026 EXP SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands… Patch early 6.8 medium 1.5% 2011-11-02
CVE-2010-1361 EXP Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 1.5% 2010-04-13
CVE-2008-0605 EXP Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.5% 2008-02-06
CVE-2008-2188 EXP Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) boo… Patch early 4.3 medium 1.5% 2008-05-13
CVE-2008-3565 EXP Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.5% 2008-08-10
CVE-2008-6325 EXP Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.5% 2009-02-27
CVE-2011-4275 EXP Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbit… Patch early 4.3 medium 1.5% 2011-11-26
CVE-2017-15084 EXP The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. Patch early 6.5 medium 1.5% 2017-10-06
CVE-2010-2846 EXP Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to injec… Patch early 4.3 medium 1.5% 2010-07-25
CVE-2012-1005 EXP Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.5% 2012-02-07
CVE-2008-2115 EXP Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.5% 2008-05-08
CVE-2008-4372 EXP Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.5% 2008-10-01
CVE-2008-5338 EXP Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 1.5% 2008-12-05
← previous page 289 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt