peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,169 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

171,154 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4424 EXP Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2008-10-03
CVE-2008-4435 EXP Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject… Patch early 4.3 medium 1.5% 2008-10-03
CVE-2008-4648 EXP Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.5% 2008-10-22
CVE-2008-4931 EXP Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attac… Patch early 4.3 medium 1.5% 2008-11-05
CVE-2007-6141 EXP Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the searc… Patch early 4.3 medium 1.5% 2007-11-27
CVE-2018-5705 EXP Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there i… Patch early 6.1 medium 1.5% 2018-01-24
CVE-2006-2552 EXP Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathna… Patch early 5.0 medium 1.5% 2006-05-24
CVE-2007-4966 EXP SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via th… Patch early 6.8 medium 1.5% 2007-09-18
CVE-2007-4917 EXP Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the i… Patch early 4.3 medium 1.5% 2007-09-17
CVE-2008-1283 EXP Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which i… Patch early 4.3 medium 1.5% 2008-03-11
CVE-2008-1413 EXP Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.5% 2008-03-20
CVE-2008-3587 EXP Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.5% 2008-08-11
CVE-2008-3941 EXP Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page… Patch early 4.3 medium 1.5% 2008-09-05
CVE-2008-5039 EXP Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2008-11-12
CVE-2008-6297 EXP Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and… Patch early 4.3 medium 1.5% 2009-02-26
CVE-2008-6386 EXP Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id pa… Patch early 4.3 medium 1.5% 2009-03-02
CVE-2008-6515 EXP Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows remote attackers to inject ar… Patch early 4.3 medium 1.5% 2009-03-24
CVE-2008-6609 EXP Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.5% 2009-04-06
CVE-2011-5150 EXP Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07 and possibly earlier allow remote attackers or authenticated users to inject arb… Patch early 4.3 medium 1.5% 2012-08-31
CVE-2007-6160 EXP Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.5% 2007-11-29
CVE-2003-1453 EXP Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attack… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2026-58058 EXP Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the p… Patch early 6.5 medium 1.5% 2026-06-28
CVE-2015-5595 EXP Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin us… Patch early 6.5 medium 1.5% 2019-12-31
CVE-2008-2127 EXP Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.5% 2008-05-09
CVE-2008-2445 EXP Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attacker… Patch early 4.3 medium 1.5% 2008-05-27
CVE-2008-2496 EXP Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO… Patch early 4.3 medium 1.5% 2008-05-28
CVE-2008-5879 EXP Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arb… Patch early 4.3 medium 1.5% 2009-01-08
CVE-2008-6248 EXP Cross-site scripting (XSS) vulnerability in all.php in Galatolo WebManager 1.3a and earlier allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.5% 2009-02-23
CVE-2008-6278 EXP Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers… Patch early 4.3 medium 1.5% 2009-02-25
CVE-2008-6351 EXP Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or H… Patch early 4.3 medium 1.5% 2009-03-02
← previous page 301 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt