CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,166 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
171,151 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2009-3747 EXP | Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the content… | Patch early | 4.3 medium | 1.5% | 2009-10-22 |
| CVE-2009-3911 EXP | Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sam… | Patch early | 4.3 medium | 1.5% | 2009-11-09 |
| CVE-2009-4384 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.5% | 2009-12-22 |
| CVE-2009-4523 EXP | Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchSongKe… | Patch early | 4.3 medium | 1.5% | 2009-12-31 |
| CVE-2009-4601 EXP | Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.5% | 2010-01-12 |
| CVE-2009-4681 EXP | Cross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.5% | 2010-03-10 |
| CVE-2009-4857 EXP | Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the pa… | Patch early | 4.3 medium | 1.5% | 2010-05-11 |
| CVE-2009-4989 EXP | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.5% | 2010-08-25 |
| CVE-2001-1559 EXP | The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease fun… | Patch early | 5.5 medium | 1.5% | 2001-12-31 |
| CVE-2010-4610 EXP | Cross-site scripting (XSS) vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to inject arbitrary web script or HTML via the er… | Patch early | 4.3 medium | 1.5% | 2010-12-29 |
| CVE-2010-5018 EXP | Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject… | Patch early | 4.3 medium | 1.5% | 2011-11-02 |
| CVE-2012-0932 EXP | Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2012-01-29 |
| CVE-2010-4165 EXP | The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which a… | Patch early | 4.9 medium | 1.5% | 2010-11-22 |
| CVE-2010-5045 EXP | Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via th… | Patch early | 4.3 medium | 1.5% | 2011-11-02 |
| CVE-2011-1106 EXP | Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.5% | 2011-03-01 |
| CVE-2011-4564 EXP | Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the… | Patch early | 4.3 medium | 1.5% | 2011-11-28 |
| CVE-2011-5073 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web… | Patch early | 4.3 medium | 1.5% | 2012-01-29 |
| CVE-2012-1028 EXP | Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject a… | Patch early | 4.3 medium | 1.5% | 2012-02-08 |
| CVE-2012-1048 EXP | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions,… | Patch early | 4.3 medium | 1.5% | 2012-02-12 |
| CVE-2007-4052 EXP | Cross-site scripting (XSS) vulnerability in utilities/login.asp in nukedit 4.9.7 and earlier allows remote attackers to inject arbitrary web script or… | Patch early | 4.3 medium | 1.5% | 2007-07-30 |
| CVE-2011-4541 EXP | Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML vi… | Patch early | 4.3 medium | 1.5% | 2011-11-29 |
| CVE-2011-4567 EXP | Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote… | Patch early | 4.3 medium | 1.5% | 2011-11-29 |
| CVE-2011-5023 EXP | Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the se… | Patch early | 4.3 medium | 1.5% | 2011-12-29 |
| CVE-2011-5045 EXP | Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTM… | Patch early | 4.3 medium | 1.5% | 2011-12-30 |
| CVE-2008-6211 EXP | Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 4.3 medium | 1.5% | 2009-02-20 |
| CVE-2008-6655 EXP | Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom… | Patch early | 4.3 medium | 1.5% | 2009-04-07 |
| CVE-2008-7140 EXP | Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML… | Patch early | 4.3 medium | 1.5% | 2009-09-01 |
| CVE-2008-0980 EXP | Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script o… | Patch early | 4.3 medium | 1.5% | 2008-02-25 |
| CVE-2007-6212 EXP | Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer param… | Patch early | 5.0 medium | 1.5% | 2007-12-04 |
| CVE-2008-1037 EXP | Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2… | Patch early | 4.3 medium | 1.5% | 2008-02-27 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt