peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,164 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

171,150 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-4464 EXP Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.5% 2009-12-30
CVE-2009-4684 EXP Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter… Patch early 4.3 medium 1.5% 2010-03-10
CVE-2009-4685 EXP Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTM… Patch early 4.3 medium 1.5% 2010-03-10
CVE-2009-4686 EXP Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.5% 2010-03-10
CVE-2009-4714 EXP Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the P… Patch early 4.3 medium 1.5% 2010-03-15
CVE-2009-4782 EXP Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.5% 2010-04-21
CVE-2009-4856 EXP Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.5% 2010-05-11
CVE-2014-9439 EXP Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the us… Patch early 4.3 medium 1.5% 2015-01-02
CVE-2007-1919 EXP Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.5% 2007-04-10
CVE-2003-1372 EXP Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbi… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2003-1498 EXP Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject ar… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2007-6669 EXP Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the str… Patch early 4.3 medium 1.5% 2008-01-08
CVE-2009-2114 EXP Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2009-06-18
CVE-2009-3719 EXP Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.5% 2009-10-16
CVE-2009-4575 EXP Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary… Patch early 4.3 medium 1.5% 2010-01-06
CVE-2009-4692 EXP Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.5% 2010-03-10
CVE-2009-4697 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via t… Patch early 4.3 medium 1.5% 2010-03-10
CVE-2009-4713 EXP Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web scri… Patch early 4.3 medium 1.5% 2010-03-15
CVE-2009-4814 EXP Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI… Patch early 4.3 medium 1.5% 2010-04-27
CVE-2008-1956 EXP Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.5% 2008-04-25
CVE-2008-2126 EXP Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q paramet… Patch early 4.3 medium 1.5% 2008-05-09
CVE-2008-4737 EXP Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the dom… Patch early 4.3 medium 1.5% 2008-10-24
CVE-2008-5891 EXP Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 1.5% 2009-01-12
CVE-2008-6620 EXP Multiple cross-site scripting (XSS) vulnerabilities in javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php in GraFX miniCW… Patch early 4.3 medium 1.5% 2009-04-06
CVE-2008-6764 EXP Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.5% 2009-04-28
CVE-2008-6924 EXP Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script o… Patch early 4.3 medium 1.5% 2009-08-10
CVE-2008-7036 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for… Patch early 4.3 medium 1.5% 2009-08-24
CVE-2010-4514 EXP Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary w… Patch early 4.3 medium 1.5% 2010-12-09
CVE-2008-6502 EXP Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a… Patch early 4.6 medium 1.5% 2009-03-20
CVE-2018-10365 EXP An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a… Patch early 5.4 medium 1.5% 2018-05-01
← previous page 294 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt