CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,169 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-7766 EXP | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthentic… | Patch early | 8.0 high | 1.8% | 2025-07-22 |
| CVE-2005-4139 EXP | Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parame… | Patch early | 7.5 high | 1.8% | 2005-12-09 |
| CVE-2004-1225 EXP | SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via th… | Patch early | 10.0 high | 1.8% | 2005-01-10 |
| CVE-2007-2675 EXP | SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category p… | Patch early | 7.5 high | 1.8% | 2007-05-14 |
| CVE-2016-4808 EXP | Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user t… | Patch early | 8.8 high | 1.8% | 2017-01-11 |
| CVE-2012-5698 EXP | BabyGekko before 1.2.4 has SQL injection. | Patch early | 8.8 high | 1.8% | 2020-01-23 |
| CVE-2007-3889 EXP | Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the curren… | Patch early | 7.5 high | 1.8% | 2007-07-18 |
| CVE-2008-6802 EXP | Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary SQL commands via the (1) Userna… | Patch early | 7.5 high | 1.8% | 2009-05-07 |
| CVE-2005-1134 EXP | SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id o… | Patch early | 7.5 high | 1.8% | 2005-04-13 |
| CVE-2005-3201 EXP | SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows rem… | Patch early | 7.5 high | 1.8% | 2005-10-14 |
| CVE-2004-2143 EXP | SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitra… | Patch early | 7.5 high | 1.7% | 2004-12-31 |
| CVE-2005-2954 EXP | SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the emai… | Patch early | 7.5 high | 1.7% | 2005-09-16 |
| CVE-2005-3545 EXP | SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL comman… | Patch early | 7.5 high | 1.7% | 2005-11-16 |
| CVE-2006-0721 EXP | SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter… | Patch early | 7.5 high | 1.7% | 2006-02-16 |
| CVE-2006-1754 EXP | SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the S… | Patch early | 7.5 high | 1.7% | 2006-04-13 |
| CVE-2004-1914 EXP | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 1.7% | 2004-12-31 |
| CVE-2008-5958 EXP | Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) que… | Patch early | 7.5 high | 1.7% | 2009-01-23 |
| CVE-2007-3313 EXP | Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username paramete… | Patch early | 7.5 high | 1.7% | 2007-06-21 |
| CVE-2006-2300 EXP | Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.as… | Patch early | 7.5 high | 1.7% | 2006-05-11 |
| CVE-2006-3926 EXP | Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parame… | Patch early | 7.5 high | 1.7% | 2006-07-31 |
| CVE-2019-10529 EXP | Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Au… | Patch early | 8.1 high | 1.7% | 2019-11-06 |
| CVE-2026-51134 EXP | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml. | Patch early | 7.5 high | 1.7% | 2026-09-15 |
| CVE-2003-1375 EXP | Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument… | Patch early | 7.2 high | 1.7% | 2003-12-31 |
| CVE-2015-6811 EXP | SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to e… | Patch early | 7.5 high | 1.7% | 2015-09-04 |
| CVE-2024-50858 EXP | Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by… | Patch early | 8.8 high | 1.7% | 2025-01-14 |
| CVE-2009-5068 EXP | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is… | Patch early | 7.2 high | 1.7% | 2020-01-15 |
| CVE-2014-3119 EXP | Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) s… | Patch early | 8.8 high | 1.7% | 2020-01-31 |
| CVE-2003-1435 EXP | SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search mod… | Patch early | 7.5 high | 1.7% | 2003-12-31 |
| CVE-2004-0806 EXP | cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in th… | Patch early | 7.2 high | 1.7% | 2004-12-31 |
| CVE-2007-6217 EXP | Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 1.7% | 2007-12-04 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt