CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-4563 EXP | SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and b… | Patch early | 7.5 high | 1.4% | 2005-12-29 |
| CVE-2006-6109 EXP | Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parame… | Patch early | 7.5 high | 1.4% | 2006-11-26 |
| CVE-2000-0460 EXP | Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable. | Patch early | 7.2 high | 1.4% | 2000-05-27 |
| CVE-2006-6095 EXP | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter… | Patch early | 7.5 high | 1.4% | 2006-11-24 |
| CVE-2018-10814 EXP | Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. | Patch early | 7.8 high | 1.4% | 2018-09-14 |
| CVE-2024-10758 EXP | A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects… | Patch early | 7.3 high | 1.4% | 2024-11-04 |
| CVE-2017-3141 EXP | The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system perm… | Patch early | 7.2 high | 1.4% | 2019-01-16 |
| CVE-2004-2131 EXP | Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute a… | Patch early | 7.2 high | 1.4% | 2004-01-27 |
| CVE-2009-3040 EXP | Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL… | Patch early | 7.5 high | 1.4% | 2009-09-01 |
| CVE-2005-0997 EXP | Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the e… | Patch early | 7.5 high | 1.4% | 2005-05-02 |
| CVE-2020-26887 EXP | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. | Patch early | 7.8 high | 1.4% | 2020-10-23 |
| CVE-2007-1339 EXP | SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt pa… | Patch early | 7.5 high | 1.4% | 2007-03-08 |
| CVE-2000-1134 EXP | Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka… | Patch early | 7.2 high | 1.4% | 2001-01-09 |
| CVE-2004-2418 EXP | Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and… | Patch early | 7.2 high | 1.4% | 2004-12-31 |
| CVE-2017-9644 EXP | An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTR… | Patch early | 7.0 high | 1.4% | 2017-08-25 |
| CVE-2007-6106 EXP | SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the se… | Patch early | 7.5 high | 1.4% | 2007-11-23 |
| CVE-2007-4069 EXP | SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id pa… | Patch early | 7.5 high | 1.4% | 2007-07-30 |
| CVE-2008-1465 EXP | SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitr… | Patch early | 9.3 high | 1.4% | 2008-03-24 |
| CVE-2017-5671 EXP | Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/… | Patch early | 8.8 high | 1.4% | 2017-03-29 |
| CVE-1999-1497 EXP | Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail account… | Patch early | 7.2 high | 1.4% | 1999-12-21 |
| CVE-2005-0414 EXP | SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for i… | Patch early | 7.5 high | 1.4% | 2005-04-27 |
| CVE-2005-1594 EXP | SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parame… | Patch early | 7.5 high | 1.4% | 2005-05-16 |
| CVE-2000-0994 EXP | Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via t… | Patch early | 7.2 high | 1.4% | 2000-12-19 |
| CVE-1999-0036 EXP | IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files. | Patch early | 8.4 high | 1.4% | 1997-05-26 |
| CVE-2005-3043 EXP | SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 p… | Patch early | 7.5 high | 1.4% | 2005-09-22 |
| CVE-2001-1076 EXP | Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment v… | Patch early | 7.2 high | 1.4% | 2001-07-05 |
| CVE-2005-3963 EXP | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter… | Patch early | 7.5 high | 1.4% | 2005-12-02 |
| CVE-2005-4143 EXP | SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numer… | Patch early | 7.5 high | 1.4% | 2005-12-10 |
| CVE-2006-1805 EXP | SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter. | Patch early | 7.5 high | 1.4% | 2006-04-18 |
| CVE-2007-4171 EXP | SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 1.4% | 2007-08-07 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt