CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,887 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
171,016 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-6301 EXP | Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2007-12-10 |
| CVE-2009-2595 EXP | Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.7% | 2009-07-24 |
| CVE-2010-4901 EXP | Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.7% | 2011-10-08 |
| CVE-2010-4907 EXP | Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the u… | Patch early | 4.3 medium | 1.7% | 2011-10-08 |
| CVE-2010-5002 EXP | Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrar… | Patch early | 4.3 medium | 1.7% | 2011-11-01 |
| CVE-2008-5330 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7… | Patch early | 4.3 medium | 1.7% | 2008-12-05 |
| CVE-2008-0496 EXP | Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit pa… | Patch early | 4.3 medium | 1.7% | 2008-01-30 |
| CVE-2008-2967 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inje… | Patch early | 4.3 medium | 1.7% | 2008-07-02 |
| CVE-2008-3404 EXP | Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.7% | 2008-07-31 |
| CVE-2008-4727 EXP | Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote att… | Patch early | 4.3 medium | 1.7% | 2008-10-24 |
| CVE-2021-3441 EXP | A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS). | Patch early | 4.8 medium | 1.7% | 2021-10-29 |
| CVE-2007-6126 EXP | Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.7% | 2007-11-26 |
| CVE-2005-1023 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) m… | Patch early | 4.3 medium | 1.7% | 2005-05-02 |
| CVE-2005-1955 EXP | Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the galle… | Patch early | 4.3 medium | 1.7% | 2005-06-12 |
| CVE-2023-0915 EXP | A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file… | Patch early | 6.3 medium | 1.7% | 2023-02-19 |
| CVE-2005-2814 EXP | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a v… | Patch early | 4.3 medium | 1.7% | 2005-09-07 |
| CVE-2009-4264 EXP | PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote at… | Patch early | 6.8 medium | 1.7% | 2009-12-10 |
| CVE-2014-3978 EXP | SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Na… | Patch early | 6.5 medium | 1.7% | 2014-10-20 |
| CVE-2014-6030 EXP | Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via… | Patch early | 6.5 medium | 1.7% | 2014-11-06 |
| CVE-2006-5530 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.7% | 2006-10-26 |
| CVE-2008-0092 EXP | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to… | Patch early | 4.3 medium | 1.7% | 2008-01-04 |
| CVE-2008-3448 EXP | Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or H… | Patch early | 4.3 medium | 1.7% | 2008-08-04 |
| CVE-2004-1521 EXP | Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which ma… | Patch early | 5.0 medium | 1.7% | 2004-12-31 |
| CVE-2013-1647 EXP | Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attacker… | Patch early | 5.0 medium | 1.7% | 2013-09-05 |
| CVE-2006-3624 EXP | Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url paramet… | Patch early | 4.3 medium | 1.7% | 2006-07-18 |
| CVE-2003-1307 EXP | The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and us… | Patch early | 4.3 medium | 1.7% | 2003-12-31 |
| CVE-2009-2182 EXP | Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS… | Patch early | 6.8 medium | 1.7% | 2009-06-23 |
| CVE-2007-1793 EXP | SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT fun… | Patch early | 4.9 medium | 1.7% | 2007-04-02 |
| CVE-2016-8018 EXP | Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote at… | Patch early | 4.3 medium | 1.7% | 2017-03-14 |
| CVE-2010-0700 EXP | Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang p… | Patch early | 4.3 medium | 1.7% | 2010-02-23 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt