peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,164 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2008-4203 EXP SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie… Patch early 7.5 high 2% 2008-09-24
CVE-2008-5864 EXP SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! al… Patch early 7.5 high 2% 2009-01-06
CVE-2009-4599 EXP Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute arbitrary SQL comma… Patch early 7.5 high 2% 2010-01-12
CVE-2008-5208 EXP SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitr… Patch early 7.5 high 2% 2008-11-24
CVE-2008-6371 EXP SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username… Patch early 7.5 high 2% 2009-03-02
CVE-2008-6653 EXP SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote a… Patch early 7.5 high 2% 2009-04-07
CVE-2008-1919 EXP SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 2% 2008-04-23
CVE-2007-1510 EXP SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the post… Patch early 7.5 high 2% 2007-03-20
CVE-2006-1123 EXP SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cook… Patch early 10.0 high 2% 2006-03-09
CVE-2009-3055 EXP PHP remote file inclusion vulnerability in engine/api/api.class.php in DataLife Engine (DLE) 8.2 allows remote attackers to execute arbitrary PHP code… Patch early 7.5 high 2% 2009-09-03
CVE-2009-3333 EXP PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute a… Patch early 7.5 high 2% 2009-09-23
CVE-2009-2777 EXP SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter. Patch early 7.5 high 2% 2009-08-14
CVE-2009-3543 EXP SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via th… Patch early 7.5 high 2% 2009-10-02
CVE-2009-3718 EXP SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands v… Patch early 7.5 high 2% 2009-10-16
CVE-2009-4203 EXP Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via… Patch early 7.5 high 2% 2009-12-04
CVE-2008-5969 EXP SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 2% 2009-01-27
CVE-2008-6182 EXP SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arb… Patch early 7.5 high 2% 2009-02-19
CVE-2008-6892 EXP SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter. NOTE: th… Patch early 7.5 high 2% 2009-08-03
CVE-2010-3479 EXP SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. Patch early 7.5 high 2% 2010-09-22
CVE-2006-5044 EXP Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and a… Patch early 7.5 high 2% 2006-09-27
CVE-2008-0224 EXP SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL co… Patch early 7.5 high 2% 2008-01-10
CVE-2008-0255 EXP SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the se… Patch early 7.5 high 2% 2008-01-15
CVE-2008-1460 EXP SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary… Patch early 7.5 high 2% 2008-03-24
CVE-2008-2453 EXP Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter t… Patch early 7.5 high 2% 2008-05-27
CVE-2009-2340 EXP SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtUserName (aka User Na… Patch early 7.5 high 2% 2009-07-07
CVE-2006-6752 EXP Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unkn… Patch early 7.5 high 2% 2006-12-27
CVE-2010-1874 EXP SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary… Patch early 7.5 high 2% 2010-05-12
CVE-2010-2317 EXP Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr,… Patch early 7.5 high 2% 2010-06-17
CVE-2017-6086 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hi… Patch early 8.8 high 2% 2017-06-27
CVE-2005-1633 EXP Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anz… Patch early 7.5 high 2% 2005-05-17
← previous page 298 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt