peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,166 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

12,663 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-0343 EXP Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in Mo… Patch early 10.0 high 1.8% 2004-11-23
CVE-2007-6583 EXP SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip… Patch early 7.5 high 1.8% 2007-12-28
CVE-2009-3349 EXP SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to th… Patch early 7.5 high 1.8% 2009-09-24
CVE-2010-0723 EXP SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. Patch early 7.5 high 1.8% 2010-02-26
CVE-2000-0955 EXP Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows t… Patch early 7.5 high 1.8% 2000-12-19
CVE-2009-0431 EXP SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirecti… Patch early 7.5 high 1.8% 2009-02-05
CVE-2009-1499 EXP SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the arti… Patch early 7.5 high 1.8% 2009-05-01
CVE-2017-14344 EXP This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to e… Patch early 7.8 high 1.8% 2017-09-12
CVE-2007-0554 EXP SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id… Patch early 7.5 high 1.8% 2007-01-29
CVE-2010-1949 EXP SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary S… Patch early 7.5 high 1.8% 2010-05-19
CVE-2010-4507 EXP Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.… Patch early 9.3 high 1.8% 2010-12-30
CVE-2006-0160 EXP SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) roo… Patch early 7.5 high 1.8% 2006-01-10
CVE-2017-1000379 EXP The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing a… Patch early 7.8 high 1.8% 2017-06-19
CVE-2009-4936 EXP Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter… Patch early 7.5 high 1.8% 2010-07-22
CVE-2006-4279 EXP SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topi… Patch early 7.5 high 1.8% 2006-08-21
CVE-2006-6355 EXP SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. N… Patch early 10.0 high 1.8% 2006-12-07
CVE-2006-2650 EXP SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max param… Patch early 7.5 high 1.8% 2006-05-30
CVE-2006-2858 EXP SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid par… Patch early 7.5 high 1.8% 2006-06-06
CVE-2007-0132 EXP SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parame… Patch early 7.5 high 1.8% 2007-01-09
CVE-2007-3515 EXP SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id… Patch early 10.0 high 1.8% 2007-07-03
CVE-2007-3824 EXP SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter. Patch early 10.0 high 1.8% 2007-07-17
CVE-2017-14075 EXP This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to e… Patch early 7.8 high 1.8% 2017-09-11
CVE-2017-14153 EXP This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to e… Patch early 7.8 high 1.8% 2017-09-11
CVE-2006-4478 EXP SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the… Patch early 7.5 high 1.8% 2006-08-31
CVE-2024-25003 EXP KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and in… Patch early 7.8 high 1.8% 2024-02-09
CVE-2007-0093 EXP SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id p… Patch early 7.5 high 1.8% 2007-01-05
CVE-2023-45131 EXP Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus.… Patch early 7.5 high 1.8% 2023-10-16
CVE-2024-56901 EXP A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrar… Patch early 8.8 high 1.8% 2025-02-03
CVE-2007-0623 EXP SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. Patch early 7.5 high 1.8% 2007-01-31
CVE-2015-2143 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authenticat… Patch early 8.8 high 1.8% 2017-10-06
← previous page 302 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt