peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

171,158 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4056 EXP Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.5% 2008-09-11
CVE-2008-4349 EXP Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.5% 2008-09-30
CVE-2009-2107 EXP Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrar… Patch early 4.3 medium 1.5% 2009-06-17
CVE-2009-2241 EXP Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.5% 2009-06-27
CVE-2009-2594 EXP Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the item… Patch early 4.3 medium 1.5% 2009-07-24
CVE-2009-3440 EXP Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitra… Patch early 4.3 medium 1.5% 2009-09-28
CVE-2009-3485 EXP Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web… Patch early 4.3 medium 1.5% 2009-09-30
CVE-2009-3496 EXP Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.5% 2009-09-30
CVE-2009-3751 EXP Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent… Patch early 4.3 medium 1.5% 2009-10-22
CVE-2009-4253 EXP Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the… Patch early 4.3 medium 1.5% 2009-12-10
CVE-2009-4813 EXP Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HT… Patch early 4.3 medium 1.5% 2010-04-27
CVE-2002-2318 EXP Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or… Patch early 4.3 medium 1.5% 2002-12-31
CVE-2003-1400 EXP Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web scrip… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2003-1513 EXP Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject a… Patch early 4.3 medium 1.5% 2003-12-31
CVE-2007-5648 EXP Multiple cross-site scripting (XSS) vulnerabilities in rnote.php in rNote 0.9.7.5 allow remote attackers to inject arbitrary web script or HTML via th… Patch early 4.3 medium 1.5% 2007-10-23
CVE-2017-15687 EXP DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. Patch early 6.1 medium 1.5% 2017-10-23
CVE-2007-6157 EXP Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the al… Patch early 4.3 medium 1.4% 2007-11-29
CVE-2002-2348 EXP Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command p… Patch early 4.3 medium 1.4% 2002-12-31
CVE-2002-2424 EXP Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in th… Patch early 4.3 medium 1.4% 2002-12-31
CVE-2009-2289 EXP Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.4% 2009-07-01
CVE-2009-4266 EXP Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers t… Patch early 4.3 medium 1.4% 2009-12-10
CVE-2009-4694 EXP Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML v… Patch early 4.3 medium 1.4% 2010-03-10
CVE-2010-1048 EXP Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.4% 2010-03-23
CVE-2008-1355 EXP Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web s… Patch early 4.3 medium 1.4% 2008-03-17
CVE-2008-1955 EXP Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML vi… Patch early 4.3 medium 1.4% 2008-04-25
CVE-2008-2413 EXP Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id… Patch early 4.3 medium 1.4% 2008-05-22
CVE-2008-2493 EXP Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML… Patch early 4.3 medium 1.4% 2008-05-28
CVE-2008-4670 EXP Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.4% 2008-10-22
CVE-2008-5067 EXP Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q… Patch early 4.3 medium 1.4% 2008-11-13
CVE-2008-6164 EXP Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via… Patch early 4.3 medium 1.4% 2009-02-20
← previous page 303 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt