CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,146 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-1250 EXP | SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 2% | 2007-03-03 |
| CVE-2005-3324 EXP | SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter. | Patch early | 7.5 high | 2% | 2005-10-27 |
| CVE-2010-2319 EXP | SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter. | Patch early | 7.5 high | 2% | 2010-06-17 |
| CVE-2010-2142 EXP | SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2% | 2010-06-02 |
| CVE-2007-6458 EXP | SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded val… | Patch early | 7.5 high | 2% | 2007-12-20 |
| CVE-2007-6665 EXP | SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID par… | Patch early | 7.5 high | 2% | 2008-01-04 |
| CVE-2007-1297 EXP | SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | Patch early | 7.5 high | 2% | 2007-03-07 |
| CVE-2009-0726 EXP | SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 2% | 2009-02-24 |
| CVE-2009-1508 EXP | SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 2% | 2009-05-01 |
| CVE-2006-6066 EXP | Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) us… | Patch early | 7.5 high | 2% | 2006-11-22 |
| CVE-2008-0442 EXP | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL i… | Patch early | 7.5 high | 2% | 2008-01-25 |
| CVE-2011-4026 EXP | SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2% | 2011-10-21 |
| CVE-2015-5736 EXP | The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the cal… | Patch early | 7.2 high | 2% | 2015-09-03 |
| CVE-2008-7075 EXP | Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the… | Patch early | 7.5 high | 2% | 2009-08-25 |
| CVE-2018-13989 EXP | Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by… | Patch early | 8.8 high | 2% | 2018-07-11 |
| CVE-2007-2641 EXP | SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid para… | Patch early | 7.5 high | 2% | 2007-05-13 |
| CVE-2005-1779 EXP | SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 2% | 2005-05-31 |
| CVE-2008-6649 EXP | SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote… | Patch early | 7.5 high | 2% | 2009-04-07 |
| CVE-2009-4571 EXP | Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id pa… | Patch early | 7.5 high | 2% | 2010-01-05 |
| CVE-2005-3968 EXP | SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication… | Patch early | 7.5 high | 2% | 2005-12-03 |
| CVE-2007-0574 EXP | SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execu… | Patch early | 7.5 high | 2% | 2007-01-30 |
| CVE-2013-7043 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote… | Patch early | 8.3 high | 2% | 2013-12-10 |
| CVE-2008-3491 EXP | SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id par… | Patch early | 7.5 high | 2% | 2008-08-06 |
| CVE-2006-6111 EXP | Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid para… | Patch early | 7.5 high | 2% | 2006-11-26 |
| CVE-2008-2510 EXP | SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2% | 2008-05-29 |
| CVE-2008-6509 EXP | SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 2% | 2009-03-23 |
| CVE-2007-3913 EXP | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Patch early | 7.5 high | 2% | 2007-09-06 |
| CVE-2006-2732 EXP | SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) yas… | Patch early | 7.5 high | 2% | 2006-06-01 |
| CVE-2006-3572 EXP | SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid para… | Patch early | 7.5 high | 2% | 2006-07-13 |
| CVE-2008-2688 EXP | SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter… | Patch early | 7.5 high | 2% | 2008-06-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt