CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-6164 EXP | Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2009-02-20 |
| CVE-2008-6306 EXP | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.4% | 2009-02-26 |
| CVE-2008-6385 EXP | Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.4% | 2009-03-02 |
| CVE-2008-6404 EXP | Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.4% | 2009-03-06 |
| CVE-2008-7184 EXP | Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via a public com… | Patch early | 4.3 medium | 1.4% | 2009-09-08 |
| CVE-2008-7222 EXP | Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the ra… | Patch early | 4.3 medium | 1.4% | 2009-09-14 |
| CVE-2009-0283 EXP | Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter. | Patch early | 4.3 medium | 1.4% | 2009-01-27 |
| CVE-2009-0285 EXP | Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.4% | 2009-01-27 |
| CVE-2009-0814 EXP | Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.4% | 2009-03-05 |
| CVE-2009-2289 EXP | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.4% | 2009-07-01 |
| CVE-2002-2348 EXP | Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command p… | Patch early | 4.3 medium | 1.4% | 2002-12-31 |
| CVE-2002-2424 EXP | Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in th… | Patch early | 4.3 medium | 1.4% | 2002-12-31 |
| CVE-2009-4266 EXP | Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers t… | Patch early | 4.3 medium | 1.4% | 2009-12-10 |
| CVE-2009-4694 EXP | Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.4% | 2010-03-10 |
| CVE-2010-1048 EXP | Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2010-03-23 |
| CVE-2007-3190 EXP | Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow… | Patch early | 6.8 medium | 1.4% | 2007-06-12 |
| CVE-2017-10273 EXP | Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1… | Patch early | 4.7 medium | 1.4% | 2018-01-18 |
| CVE-2009-3367 EXP | Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path… | Patch early | 4.3 medium | 1.4% | 2009-09-24 |
| CVE-2008-0474 EXP | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.4% | 2008-01-29 |
| CVE-2008-0684 EXP | Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.4% | 2008-02-12 |
| CVE-2008-2414 EXP | Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.4% | 2008-05-22 |
| CVE-2008-4174 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.4% | 2008-09-23 |
| CVE-2008-4669 EXP | Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.4% | 2008-10-22 |
| CVE-2008-4672 EXP | Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.4% | 2008-10-22 |
| CVE-2008-4896 EXP | Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2008-11-04 |
| CVE-2008-6034 EXP | Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkac… | Patch early | 4.3 medium | 1.4% | 2009-02-03 |
| CVE-2008-6565 EXP | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2009-03-31 |
| CVE-2024-35539 EXP | Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post s… | Patch early | 6.5 medium | 1.4% | 2024-08-19 |
| CVE-2008-0398 EXP | Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2008-01-23 |
| CVE-2008-0541 EXP | Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.4% | 2008-02-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt