CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
10,149 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2008-7171 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.4% | 2009-09-08 |
| CVE-2010-0374 EXP | Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary we… | Patch early | 4.3 medium | 1.4% | 2010-01-21 |
| CVE-2010-1113 EXP | Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web scri… | Patch early | 4.3 medium | 1.4% | 2010-03-25 |
| CVE-2010-1606 EXP | Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1… | Patch early | 4.3 medium | 1.4% | 2010-04-29 |
| CVE-2010-2356 EXP | Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2010-06-21 |
| CVE-2010-2617 EXP | Cross-site scripting (XSS) vulnerability in bible.php in PHP Bible Search allows remote attackers to inject arbitrary web script or HTML via the chapt… | Patch early | 4.3 medium | 1.4% | 2010-07-02 |
| CVE-2010-3202 EXP | Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted book… | Patch early | 4.3 medium | 1.4% | 2010-09-13 |
| CVE-2003-1348 EXP | Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via… | Patch early | 4.3 medium | 1.4% | 2003-12-31 |
| CVE-2012-6434 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authenticatio… | Patch early | 6.8 medium | 1.4% | 2013-01-03 |
| CVE-2008-5971 EXP | Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web… | Patch early | 4.3 medium | 1.4% | 2009-01-27 |
| CVE-2008-3560 EXP | Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.4% | 2008-08-08 |
| CVE-2012-3834 EXP | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authent… | Patch early | 6.5 medium | 1.4% | 2012-07-03 |
| CVE-2017-14219 EXP | XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connect… | Patch early | 6.1 medium | 1.4% | 2017-09-07 |
| CVE-2017-16841 EXP | LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx. | Patch early | 6.1 medium | 1.4% | 2017-11-16 |
| CVE-2013-2713 EXP | Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication… | Patch early | 6.8 medium | 1.4% | 2014-05-23 |
| CVE-2009-3155 EXP | Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inje… | Patch early | 4.3 medium | 1.4% | 2009-09-10 |
| CVE-2009-4446 EXP | Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.4% | 2009-12-29 |
| CVE-2009-4468 EXP | Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page param… | Patch early | 4.3 medium | 1.4% | 2009-12-30 |
| CVE-2009-4469 EXP | Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.4% | 2009-12-30 |
| CVE-2009-4682 EXP | Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parame… | Patch early | 4.3 medium | 1.4% | 2010-03-10 |
| CVE-2008-0723 EXP | Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitr… | Patch early | 4.3 medium | 1.4% | 2008-02-12 |
| CVE-2008-1481 EXP | Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board p… | Patch early | 4.3 medium | 1.4% | 2008-03-24 |
| CVE-2008-1986 EXP | Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 1.4% | 2008-04-27 |
| CVE-2008-2046 EXP | Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.4% | 2008-05-01 |
| CVE-2008-2219 EXP | Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.4% | 2008-05-14 |
| CVE-2008-2508 EXP | Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb"… | Patch early | 4.3 medium | 1.4% | 2008-05-29 |
| CVE-2008-6174 EXP | Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.4% | 2009-02-19 |
| CVE-2008-6205 EXP | Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.4% | 2009-02-20 |
| CVE-2008-6217 EXP | Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.4% | 2009-02-20 |
| CVE-2008-6550 EXP | Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the lett… | Patch early | 4.3 medium | 1.4% | 2009-03-30 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt