CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,164 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2011-3340 EXP | SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. | Patch early | 7.5 high | 2% | 2011-10-21 |
| CVE-2022-0088 EXP | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. | Patch early | 7.4 high | 2% | 2022-04-03 |
| CVE-2010-2847 EXP | Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute… | Patch early | 7.5 high | 2% | 2010-07-25 |
| CVE-2008-3291 EXP | SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 2% | 2008-07-24 |
| CVE-2006-0417 EXP | SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitra… | Patch early | 7.5 high | 2% | 2006-01-25 |
| CVE-2011-1546 EXP | Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2% | 2011-04-04 |
| CVE-2015-3222 EXP | syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root. | Patch early | 7.0 high | 2% | 2017-09-07 |
| CVE-2010-1713 EXP | SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News… | Patch early | 7.5 high | 2% | 2010-05-04 |
| CVE-2010-1740 EXP | SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter. | Patch early | 7.5 high | 2% | 2010-05-06 |
| CVE-2010-2124 EXP | SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 2% | 2010-06-01 |
| CVE-2010-2135 EXP | Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2% | 2010-06-02 |
| CVE-2010-2907 EXP | SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 2% | 2010-07-28 |
| CVE-2008-2084 EXP | SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 2% | 2008-05-05 |
| CVE-2008-3245 EXP | SQL injection vulnerability in phpHoo3.php in phpHoo3 4.3.9, 4.3.10, 4.4.8, and 5.2.6 allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 7.5 high | 2% | 2008-07-21 |
| CVE-2008-3256 EXP | SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to exe… | Patch early | 7.5 high | 2% | 2008-07-22 |
| CVE-2008-4332 EXP | SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL comma… | Patch early | 7.5 high | 2% | 2008-09-30 |
| CVE-2008-5637 EXP | SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter. | Patch early | 7.5 high | 2% | 2008-12-17 |
| CVE-2008-5766 EXP | SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2% | 2008-12-30 |
| CVE-2008-5815 EXP | SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 2% | 2009-01-02 |
| CVE-2008-5851 EXP | SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID p… | Patch early | 7.5 high | 2% | 2009-01-06 |
| CVE-2008-6525 EXP | SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL command… | Patch early | 7.5 high | 2% | 2009-03-25 |
| CVE-2008-7085 EXP | Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL comm… | Patch early | 7.5 high | 2% | 2009-08-26 |
| CVE-2000-0170 EXP | Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable. | Patch early | 7.2 high | 2% | 2000-02-26 |
| CVE-2017-12653 EXP | 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demons… | Patch early | 7.8 high | 2% | 2017-08-07 |
| CVE-2006-1426 EXP | Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in ind… | Patch early | 7.5 high | 2% | 2006-03-28 |
| CVE-2005-1196 EXP | SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL c… | Patch early | 7.5 high | 2% | 2005-05-02 |
| CVE-2007-2971 EXP | SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid par… | Patch early | 7.5 high | 2% | 2007-06-01 |
| CVE-2010-1343 EXP | SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter. | Patch early | 7.5 high | 2% | 2010-04-09 |
| CVE-2017-16244 EXP | Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an a… | Patch early | 8.8 high | 2% | 2017-11-01 |
| CVE-2007-2146 EXP | The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via… | Patch early | 7.5 high | 2% | 2007-04-19 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt