CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
171,150 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-3989 EXP | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attac… | Patch early | 4.3 medium | 1.5% | 2007-07-25 |
| CVE-2007-4024 EXP | Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HT… | Patch early | 4.3 medium | 1.5% | 2007-07-26 |
| CVE-2007-4264 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier a… | Patch early | 4.3 medium | 1.5% | 2007-08-09 |
| CVE-2007-2805 EXP | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to… | Patch early | 4.3 medium | 1.5% | 2007-05-22 |
| CVE-2017-16843 EXP | Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic. | Patch early | 5.4 medium | 1.5% | 2017-11-16 |
| CVE-2020-8493 EXP | A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login… | Patch early | 4.8 medium | 1.5% | 2020-01-30 |
| CVE-2008-5869 EXP | Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated users to inject arb… | Patch early | 4.3 medium | 1.5% | 2009-01-08 |
| CVE-2011-4809 EXP | Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to… | Patch early | 4.3 medium | 1.5% | 2011-12-14 |
| CVE-2011-5041 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d… | Patch early | 4.3 medium | 1.5% | 2011-12-30 |
| CVE-2009-1281 EXP | Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto… | Patch early | 4.3 medium | 1.5% | 2009-04-09 |
| CVE-2010-5026 EXP | SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands… | Patch early | 6.8 medium | 1.5% | 2011-11-02 |
| CVE-2010-1361 EXP | Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.5% | 2010-04-13 |
| CVE-2008-6325 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.5% | 2009-02-27 |
| CVE-2008-0605 EXP | Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.5% | 2008-02-06 |
| CVE-2008-2188 EXP | Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) boo… | Patch early | 4.3 medium | 1.5% | 2008-05-13 |
| CVE-2008-3565 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script… | Patch early | 4.3 medium | 1.5% | 2008-08-10 |
| CVE-2011-4275 EXP | Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbit… | Patch early | 4.3 medium | 1.5% | 2011-11-26 |
| CVE-2017-15084 EXP | The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22. | Patch early | 6.5 medium | 1.5% | 2017-10-06 |
| CVE-2008-2115 EXP | Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web scr… | Patch early | 4.3 medium | 1.5% | 2008-05-08 |
| CVE-2008-4372 EXP | Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2008-10-01 |
| CVE-2012-1005 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web scrip… | Patch early | 4.3 medium | 1.5% | 2012-02-07 |
| CVE-2008-5338 EXP | Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web s… | Patch early | 4.3 medium | 1.5% | 2008-12-05 |
| CVE-2010-2846 EXP | Cross-site scripting (XSS) vulnerability in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to injec… | Patch early | 4.3 medium | 1.5% | 2010-07-25 |
| CVE-2003-0449 EXP | Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH… | Patch early | 4.6 medium | 1.5% | 2003-08-07 |
| CVE-2007-4899 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML v… | Patch early | 4.3 medium | 1.5% | 2007-09-14 |
| CVE-2007-6673 EXP | Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the… | Patch early | 4.3 medium | 1.5% | 2008-01-08 |
| CVE-2010-4412 EXP | Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id p… | Patch early | 4.3 medium | 1.5% | 2010-12-07 |
| CVE-2008-0877 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2008-02-21 |
| CVE-2008-3559 EXP | Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filena… | Patch early | 4.3 medium | 1.5% | 2008-08-08 |
| CVE-2008-3664 EXP | Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field,… | Patch early | 4.3 medium | 1.5% | 2008-09-05 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt