peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,887 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

171,016 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-0872 EXP Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.7% 2008-02-21
CVE-2008-1896 EXP Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.7% 2008-04-18
CVE-2008-2072 EXP Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.7% 2008-05-05
CVE-2008-2861 EXP Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web… Patch early 4.3 medium 1.7% 2008-06-25
CVE-2008-3237 EXP Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.7% 2008-07-21
CVE-2008-7043 EXP Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitra… Patch early 4.3 medium 1.7% 2009-08-24
CVE-2010-1703 EXP Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject a… Patch early 4.3 medium 1.7% 2010-05-04
CVE-2010-1711 EXP Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbi… Patch early 4.3 medium 1.7% 2010-05-04
CVE-2010-1742 EXP Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show para… Patch early 4.3 medium 1.7% 2010-05-06
CVE-2010-2458 EXP Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web scr… Patch early 4.3 medium 1.7% 2010-06-25
CVE-2010-2464 EXP Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inj… Patch early 4.3 medium 1.7% 2010-06-25
CVE-2010-2858 EXP Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2010-07-25
CVE-2010-2917 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2010-07-30
CVE-2010-4792 EXP Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the f… Patch early 4.3 medium 1.7% 2011-04-27
CVE-2010-5007 EXP Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.7% 2011-11-02
CVE-2010-5025 EXP Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.7% 2011-11-02
CVE-2005-0307 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.7% 2005-01-25
CVE-2005-0549 EXP Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2007-6564 EXP Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_… Patch early 4.3 medium 1.7% 2007-12-28
CVE-2010-4794 EXP Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remot… Patch early 4.3 medium 1.7% 2011-04-27
CVE-2010-5042 EXP Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote attackers to inject arbitra… Patch early 4.3 medium 1.7% 2011-11-02
CVE-2008-6631 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.7% 2009-04-07
CVE-2008-6637 EXP Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arb… Patch early 4.3 medium 1.7% 2009-04-07
CVE-2008-6675 EXP Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the clo… Patch early 4.3 medium 1.7% 2009-04-08
CVE-2009-1070 EXP Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote att… Patch early 4.3 medium 1.7% 2009-03-26
CVE-2004-2076 EXP Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.7% 2004-12-31
CVE-2004-2308 EXP Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the d… Patch early 4.3 medium 1.7% 2004-12-31
CVE-2005-1081 EXP Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.7% 2005-05-02
CVE-2002-1803 EXP Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. Patch early 4.3 medium 1.7% 2002-12-31
CVE-2002-1804 EXP Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. Patch early 4.3 medium 1.7% 2002-12-31
← previous page 277 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt