peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,145 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-2306 EXP The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers… Patch early 7.5 high 2.1% 2009-07-02
CVE-2009-3180 EXP Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php. Patch early 7.5 high 2.1% 2009-09-11
CVE-2013-6364 EXP Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book Patch early 8.8 high 2.1% 2019-11-05
CVE-1999-0972 EXP Buffer overflow in Xshipwars xsw program. Patch early 7.5 high 2.1% 1999-12-09
CVE-2005-1788 EXP SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.1% 2005-06-01
CVE-2005-2046 EXP Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat pa… Patch early 7.5 high 2.1% 2005-06-22
CVE-2008-5605 EXP Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifi… Patch early 7.5 high 2.1% 2008-12-16
CVE-2008-5739 EXP SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url paramet… Patch early 7.5 high 2.1% 2008-12-26
CVE-2008-7097 EXP Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in ad… Patch early 7.5 high 2.1% 2009-08-27
CVE-2009-3665 EXP Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) i parame… Patch early 7.5 high 2.1% 2009-10-11
CVE-2008-1863 EXP SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands vi… Patch early 7.5 high 2.1% 2008-04-17
CVE-2008-3241 EXP SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL command… Patch early 7.5 high 2.1% 2008-07-21
CVE-2008-3267 EXP SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter. Patch early 7.5 high 2.1% 2008-07-24
CVE-2008-3591 EXP SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL c… Patch early 7.5 high 2.1% 2008-08-11
CVE-2014-2081 EXP Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before… Patch early 7.5 high 2.1% 2014-10-20
CVE-2014-3935 EXP SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via t… Patch early 7.5 high 2.1% 2014-06-02
CVE-2014-4741 EXP SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQL commands via the catid param… Patch early 7.5 high 2.1% 2014-07-09
CVE-2014-9242 EXP SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id… Patch early 7.5 high 2.1% 2014-12-03
CVE-2014-9464 EXP SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the c… Patch early 7.5 high 2.1% 2015-01-03
CVE-2009-0297 EXP SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2)… Patch early 7.5 high 2.1% 2009-01-27
CVE-2005-2580 EXP Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 2.1% 2005-08-16
CVE-2008-0802 EXP SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.1% 2008-02-15
CVE-2008-1427 EXP SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL… Patch early 7.5 high 2.1% 2008-03-20
CVE-2026-34474 EXP Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can e… Patch early 7.5 high 2.1% 2026-05-06
CVE-2006-5236 EXP SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user par… Patch early 7.5 high 2.1% 2006-10-11
CVE-2000-0049 EXP Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file. Patch early 7.2 high 2.1% 2000-01-04
CVE-2020-17382 EXP The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054). Patch early 7.8 high 2.1% 2020-10-02
CVE-2007-6556 EXP Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to defa… Patch early 7.5 high 2.1% 2007-12-28
CVE-2002-0539 EXP Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_ke… Patch early 10.0 high 2.1% 2002-07-03
CVE-2014-9145 EXP Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edi… Patch early 7.5 high 2.1% 2015-04-14
← previous page 294 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt