CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,373 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
12,663 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2005-3408 EXP | SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter. | Patch early | 7.5 high | 1.3% | 2005-11-01 |
| CVE-2014-100011 EXP | SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter. | Patch early | 7.5 high | 1.3% | 2015-01-13 |
| CVE-2013-7189 EXP | Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomai… | Patch early | 7.5 high | 1.3% | 2013-12-20 |
| CVE-2014-4644 EXP | SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via t… | Patch early | 7.5 high | 1.3% | 2014-06-25 |
| CVE-2019-15791 EXP | In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd… | Patch early | 7.1 high | 1.3% | 2020-04-24 |
| CVE-2025-47957 EXP | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Patch early | 8.4 high | 1.3% | 2025-06-10 |
| CVE-2006-0079 EXP | SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field… | Patch early | 7.5 high | 1.3% | 2006-01-04 |
| CVE-2006-0137 EXP | SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL c… | Patch early | 7.5 high | 1.3% | 2006-01-09 |
| CVE-2006-0624 EXP | SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) us… | Patch early | 7.5 high | 1.3% | 2006-02-09 |
| CVE-2006-0626 EXP | SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file p… | Patch early | 7.5 high | 1.3% | 2006-02-09 |
| CVE-2006-5891 EXP | SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID para… | Patch early | 7.5 high | 1.3% | 2006-11-14 |
| CVE-2007-0130 EXP | SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 1.3% | 2007-01-09 |
| CVE-2003-1052 EXP | IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs. | Patch early | 7.2 high | 1.3% | 2004-09-28 |
| CVE-2008-6187 EXP | SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the releas… | Patch early | 7.5 high | 1.3% | 2009-02-19 |
| CVE-2008-6188 EXP | SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the… | Patch early | 7.5 high | 1.3% | 2009-02-19 |
| CVE-2010-3484 EXP | SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to Li… | Patch early | 7.5 high | 1.3% | 2010-09-22 |
| CVE-2014-100020 EXP | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewN… | Patch early | 7.5 high | 1.3% | 2015-01-13 |
| CVE-2010-1499 EXP | SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Patch early | 7.5 high | 1.3% | 2010-04-23 |
| CVE-2008-1650 EXP | SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter… | Patch early | 7.5 high | 1.3% | 2008-04-02 |
| CVE-2008-6213 EXP | SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg para… | Patch early | 7.5 high | 1.3% | 2009-02-20 |
| CVE-2006-5934 EXP | SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via… | Patch early | 7.5 high | 1.3% | 2006-11-16 |
| CVE-2006-5962 EXP | Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Pa… | Patch early | 7.5 high | 1.3% | 2006-11-17 |
| CVE-2006-5221 EXP | Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) matiere_ID paramete… | Patch early | 7.5 high | 1.3% | 2006-10-10 |
| CVE-2013-3050 EXP | SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product. | Patch early | 7.5 high | 1.3% | 2013-04-12 |
| CVE-2019-15627 EXP | Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability… | Patch early | 7.1 high | 1.3% | 2019-10-17 |
| CVE-2006-6039 EXP | SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands vi… | Patch early | 7.5 high | 1.3% | 2006-11-22 |
| CVE-2008-6252 EXP | Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k o… | Patch early | 7.2 high | 1.3% | 2009-02-24 |
| CVE-2019-10038 EXP | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Cal… | Patch early | 7.8 high | 1.3% | 2019-05-31 |
| CVE-2005-2432 EXP | SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2)… | Patch early | 7.5 high | 1.3% | 2005-08-03 |
| CVE-2005-3931 EXP | SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer. | Patch early | 7.5 high | 1.3% | 2005-12-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt