CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,648 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2020-15363 EXP | The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. | Patch early | 9.8 critical | 5.9% | 2020-06-28 |
| CVE-2023-30330 EXP | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.… | Patch early | 9.8 critical | 5.9% | 2023-05-12 |
| CVE-2020-8547 EXP | phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin wi… | Patch early | 9.8 critical | 5.9% | 2020-02-03 |
| CVE-2018-6411 EXP | An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to t… | Patch early | 9.8 critical | 5.8% | 2018-05-26 |
| CVE-2023-31714 EXP | Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities. | Patch early | 9.8 critical | 5.8% | 2023-08-30 |
| CVE-2017-5496 EXP | Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. | Patch early | 9.8 critical | 5.8% | 2017-03-15 |
| CVE-2017-16780 EXP | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | Patch early | 9.8 critical | 5.8% | 2017-11-10 |
| CVE-2019-19740 EXP | Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. | Patch early | 9.8 critical | 5.8% | 2019-12-12 |
| CVE-2025-69985 EXP | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/ap… | Patch early | 9.8 critical | 5.7% | 2026-02-24 |
| CVE-2022-2070 EXP | In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf i… | Patch early | 9.8 critical | 5.7% | 2022-09-23 |
| CVE-2004-2061 EXP | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting… | Patch early | 9.8 critical | 5.7% | 2004-07-27 |
| CVE-2017-6095 EXP | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticat… | Patch early | 9.8 critical | 5.6% | 2017-02-21 |
| CVE-2021-43481 EXP | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | Patch early | 9.8 critical | 5.6% | 2022-04-20 |
| CVE-2017-16543 EXP | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas… | Patch early | 9.8 critical | 5.6% | 2017-11-05 |
| CVE-2018-10757 EXP | CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt. | Patch early | 9.8 critical | 5.5% | 2018-05-05 |
| CVE-2023-31067 EXP | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… | Patch early | 9.8 critical | 5.5% | 2023-09-11 |
| CVE-2023-31068 EXP | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… | Patch early | 9.8 critical | 5.4% | 2023-09-11 |
| CVE-2017-17970 EXP | Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php… | Patch early | 9.8 critical | 5.4% | 2018-01-12 |
| CVE-2020-18662 EXP | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | Patch early | 9.8 critical | 5.4% | 2021-06-24 |
| CVE-2024-30896 EXP | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access… | Patch early | 9.1 critical | 5.4% | 2024-11-21 |
| CVE-2022-40347 EXP | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allow… | Patch early | 9.8 critical | 5.3% | 2023-02-17 |
| CVE-2015-6970 EXP | The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML… | Patch early | 9.8 critical | 5.3% | 2020-02-18 |
| CVE-2022-2025 EXP | an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param len… | Patch early | 9.8 critical | 5.3% | 2022-09-23 |
| CVE-2016-2417 EXP | media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initial… | Patch early | 9.8 critical | 5.3% | 2016-04-18 |
| CVE-2017-14507 EXP | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via… | Patch early | 9.8 critical | 5.3% | 2017-09-29 |
| CVE-2018-10969 EXP | SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the i… | Patch early | 9.8 critical | 5.3% | 2018-06-17 |
| CVE-2009-4581 EXP | Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers… | Patch early | 9.8 critical | 5.2% | 2010-01-06 |
| CVE-2021-40617 EXP | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | Patch early | 9.8 critical | 5.2% | 2021-10-11 |
| CVE-2018-18805 EXP | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | Patch early | 9.8 critical | 5.2% | 2018-11-16 |
| CVE-2007-0681 EXP | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, a… | Patch early | 9.8 critical | 5.2% | 2007-02-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt