CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,069 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-5045 EXP | Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.5% | 2011-12-30 |
| CVE-2008-0980 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.5% | 2008-02-25 |
| CVE-2008-6211 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2009-02-20 |
| CVE-2008-6655 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom… | Patch early | 4.3 medium | 1.5% | 2009-04-07 |
| CVE-2008-7140 EXP | Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2009-09-01 |
| CVE-2007-6212 EXP | Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer param… | Patch early | 5.0 medium | 1.5% | 2007-12-04 |
| CVE-2008-1037 EXP | Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2… | Patch early | 4.3 medium | 1.5% | 2008-02-27 |
| CVE-2008-1273 EXP | Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path paramet… | Patch early | 4.3 medium | 1.5% | 2008-03-10 |
| CVE-2008-1621 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to… | Patch early | 4.3 medium | 1.5% | 2008-04-02 |
| CVE-2008-2449 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.5% | 2008-05-27 |
| CVE-2008-6435 EXP | Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) la… | Patch early | 4.3 medium | 1.5% | 2009-03-06 |
| CVE-2009-0573 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (… | Patch early | 4.3 medium | 1.5% | 2009-02-13 |
| CVE-2008-6267 EXP | Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.5% | 2009-02-25 |
| CVE-2008-6888 EXP | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.5% | 2009-08-03 |
| CVE-2009-0105 EXP | Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd para… | Patch early | 4.3 medium | 1.5% | 2009-01-09 |
| CVE-2009-0248 EXP | Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the s… | Patch early | 4.3 medium | 1.5% | 2009-01-22 |
| CVE-2009-0378 EXP | Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers… | Patch early | 4.3 medium | 1.5% | 2009-02-02 |
| CVE-2009-1321 EXP | Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2009-04-17 |
| CVE-2009-1607 EXP | Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.5% | 2009-05-11 |
| CVE-2009-2033 EXP | Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg paramet… | Patch early | 4.3 medium | 1.5% | 2009-06-12 |
| CVE-2009-2401 EXP | Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post. | Patch early | 4.3 medium | 1.5% | 2009-07-09 |
| CVE-2009-3592 EXP | Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2009-10-08 |
| CVE-2009-4578 EXP | Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 1.5% | 2010-01-06 |
| CVE-2009-4596 EXP | Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_… | Patch early | 4.3 medium | 1.5% | 2010-01-12 |
| CVE-2012-0285 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.5% | 2012-01-24 |
| CVE-2014-9582 EXP | Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.5% | 2015-01-08 |
| CVE-2011-0748 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administra… | Patch early | 6.8 medium | 1.5% | 2011-04-13 |
| CVE-2010-4868 EXP | Cross-site scripting (XSS) vulnerability in search.php3 (aka search.php) in W-Agora 4.2.1 and earlier allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.5% | 2011-10-05 |
| CVE-2010-4928 EXP | Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject a… | Patch early | 4.3 medium | 1.5% | 2011-10-09 |
| CVE-2010-4978 EXP | Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id p… | Patch early | 4.3 medium | 1.5% | 2011-11-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt