CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1550 EXP | Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id para… | Patch early | 7.5 high | 2% | 2007-03-20 |
| CVE-2009-0707 EXP | SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail paramet… | Patch early | 7.5 high | 2% | 2009-02-23 |
| CVE-2009-1658 EXP | Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitra… | Patch early | 7.5 high | 2% | 2009-05-18 |
| CVE-2009-1664 EXP | myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attacker… | Patch early | 7.5 high | 2% | 2009-05-18 |
| CVE-2016-5809 EXP | An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 seri… | Patch early | 8.8 high | 2% | 2017-02-13 |
| CVE-2010-2133 EXP | SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a differ… | Patch early | 7.5 high | 2% | 2010-06-02 |
| CVE-2010-2141 EXP | SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in… | Patch early | 7.5 high | 2% | 2010-06-02 |
| CVE-2010-5037 EXP | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id… | Patch early | 7.5 high | 2% | 2011-11-02 |
| CVE-2009-0421 EXP | SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 2% | 2009-02-05 |
| CVE-2009-1323 EXP | SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2% | 2009-04-17 |
| CVE-2009-1651 EXP | SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 2% | 2009-05-16 |
| CVE-2009-2102 EXP | SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary… | Patch early | 7.5 high | 2% | 2009-06-17 |
| CVE-2009-2147 EXP | SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 2% | 2009-06-22 |
| CVE-2011-5109 EXP | Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the S… | Patch early | 7.5 high | 2% | 2012-08-23 |
| CVE-2006-5720 EXP | SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to… | Patch early | 7.5 high | 2% | 2006-11-04 |
| CVE-2007-0316 EXP | Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attack… | Patch early | 7.5 high | 2% | 2007-01-18 |
| CVE-2010-4878 EXP | PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in t… | Patch early | 7.5 high | 2% | 2011-10-07 |
| CVE-2010-4939 EXP | PHP remote file inclusion vulnerability in index.php in MailForm 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the theme para… | Patch early | 7.5 high | 2% | 2011-10-09 |
| CVE-2010-4943 EXP | Multiple PHP remote file inclusion vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to execute arbitrary PHP code via a URL in the class_pat… | Patch early | 7.5 high | 2% | 2011-10-09 |
| CVE-2010-4948 EXP | PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP… | Patch early | 7.5 high | 2% | 2011-10-09 |
| CVE-2010-4967 EXP | SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID paramete… | Patch early | 7.5 high | 2% | 2011-10-21 |
| CVE-2010-5019 EXP | SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the al… | Patch early | 7.5 high | 2% | 2011-11-02 |
| CVE-2011-0510 EXP | SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitr… | Patch early | 7.5 high | 2% | 2011-01-20 |
| CVE-2009-5094 EXP | SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter… | Patch early | 7.5 high | 2% | 2011-09-12 |
| CVE-2014-4322 EXP | drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devi… | Patch early | 7.2 high | 2% | 2014-12-24 |
| CVE-2013-5030 EXP | Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain confi… | Patch early | 7.2 high | 2% | 2013-10-16 |
| CVE-2006-4064 EXP | SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 2% | 2006-08-10 |
| CVE-2010-1583 EXP | SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in Task… | Patch early | 7.5 high | 2% | 2010-05-06 |
| CVE-2009-1346 EXP | SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL commands via the id_establecimient… | Patch early | 7.5 high | 2% | 2009-04-20 |
| CVE-2007-6666 EXP | SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr paramet… | Patch early | 7.5 high | 2% | 2008-01-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt