CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2007-2824 EXP | SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the p… | Patch early | 10.0 high | 1.8% | 2007-05-22 |
| CVE-2017-8422 EXP | KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper a… | Patch early | 7.8 high | 1.8% | 2017-05-17 |
| CVE-2011-5140 EXP | Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start p… | Patch early | 7.5 high | 1.8% | 2012-08-31 |
| CVE-2010-4738 EXP | Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 1.8% | 2011-02-16 |
| CVE-2020-2944 EXP | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and… | Patch early | 8.8 high | 1.8% | 2020-04-15 |
| CVE-2007-1725 EXP | SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an u… | Patch early | 9.3 high | 1.8% | 2007-03-28 |
| CVE-2006-1710 EXP | SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email… | Patch early | 7.6 high | 1.8% | 2006-04-11 |
| CVE-2007-0970 EXP | Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID p… | Patch early | 7.5 high | 1.8% | 2007-02-16 |
| CVE-2011-3394 EXP | SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page param… | Patch early | 7.5 high | 1.8% | 2011-09-15 |
| CVE-2007-1026 EXP | SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter… | Patch early | 7.5 high | 1.8% | 2007-02-21 |
| CVE-2006-4978 EXP | Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) th… | Patch early | 7.5 high | 1.8% | 2006-09-25 |
| CVE-2009-3417 EXP | SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands… | Patch early | 7.5 high | 1.8% | 2009-09-25 |
| CVE-2010-2691 EXP | Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sb… | Patch early | 7.5 high | 1.8% | 2010-07-12 |
| CVE-2025-47987 EXP | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | Patch early | 7.8 high | 1.8% | 2025-07-08 |
| CVE-2007-1548 EXP | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain charact… | Patch early | 7.5 high | 1.8% | 2007-03-20 |
| CVE-2006-5881 EXP | SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 1.8% | 2006-11-14 |
| CVE-2006-5887 EXP | SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via th… | Patch early | 7.5 high | 1.8% | 2006-11-14 |
| CVE-2008-5649 EXP | SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 10.0 high | 1.8% | 2008-12-17 |
| CVE-2024-21111 EXP | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.1… | Patch early | 7.8 high | 1.8% | 2024-04-16 |
| CVE-2005-4034 EXP | Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2… | Patch early | 7.5 high | 1.8% | 2005-12-06 |
| CVE-2024-25004 EXP | KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and in… | Patch early | 7.8 high | 1.8% | 2024-02-09 |
| CVE-2007-3562 EXP | SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 1.8% | 2007-07-04 |
| CVE-2007-3609 EXP | Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id para… | Patch early | 7.5 high | 1.8% | 2007-07-06 |
| CVE-2017-9413 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authenticatio… | Patch early | 8.8 high | 1.8% | 2017-07-25 |
| CVE-2006-4010 EXP | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page… | Patch early | 7.5 high | 1.8% | 2006-08-07 |
| CVE-2003-1216 EXP | SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the sea… | Patch early | 7.5 high | 1.8% | 2003-11-27 |
| CVE-2005-1263 EXP | The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to e… | Patch early | 7.2 high | 1.8% | 2005-05-11 |
| CVE-2008-3369 EXP | SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the catego… | Patch early | 7.5 high | 1.8% | 2008-07-30 |
| CVE-2008-3845 EXP | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands v… | Patch early | 7.5 high | 1.8% | 2008-08-27 |
| CVE-2018-2892 EXP | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are af… | Patch early | 7.8 high | 1.8% | 2018-07-18 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt