CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,672 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17591 EXP | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | Patch early | 9.8 critical | 4.4% | 2017-12-13 |
| CVE-2019-16693 EXP | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | Patch early | 9.8 critical | 4.3% | 2019-09-22 |
| CVE-2017-9602 EXP | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthen… | Patch early | 9.8 critical | 4.3% | 2017-06-16 |
| CVE-2012-1124 EXP | SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms… | Patch early | 9.8 critical | 4.3% | 2020-02-11 |
| CVE-2012-1259 EXP | Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.… | Patch early | 9.8 critical | 4.2% | 2020-01-09 |
| CVE-2018-7538 EXP | A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arb… | Patch early | 9.8 critical | 4.2% | 2018-03-12 |
| CVE-2019-12279 EXP | Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this… | Patch early | 9.8 critical | 4.2% | 2019-05-22 |
| CVE-2015-4073 EXP | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands vi… | Patch early | 9.8 critical | 4.2% | 2017-09-20 |
| CVE-2024-53584 EXP | OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. | Patch early | 9.8 critical | 4.2% | 2025-01-31 |
| CVE-2018-18619 EXP | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently… | Patch early | 9.8 critical | 4.2% | 2018-11-29 |
| CVE-2014-2023 EXP | Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute… | Patch early | 9.8 critical | 4.1% | 2017-10-26 |
| CVE-2022-46945 EXP | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. | Patch early | 9.1 critical | 4.1% | 2023-05-26 |
| CVE-2017-9834 EXP | SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watup… | Patch early | 9.8 critical | 4.1% | 2017-09-07 |
| CVE-2014-9613 EXP | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login param… | Patch early | 9.8 critical | 4.1% | 2020-02-19 |
| CVE-2015-7568 EXP | SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known us… | Patch early | 9.8 critical | 4.1% | 2017-04-24 |
| CVE-2022-27412 EXP | Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. | Patch early | 9.8 critical | 4.1% | 2022-05-09 |
| CVE-2019-18418 EXP | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session mana… | Patch early | 9.8 critical | 4% | 2019-10-24 |
| CVE-2018-6180 EXP | A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts. | Patch early | 9.8 critical | 4% | 2018-02-08 |
| CVE-2018-9245 EXP | The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the logi… | Patch early | 9.8 critical | 4% | 2018-04-22 |
| CVE-2017-6550 EXP | Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TA… | Patch early | 9.8 critical | 4% | 2017-03-20 |
| CVE-2020-13118 EXP | An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter communi… | Patch early | 9.8 critical | 4% | 2020-05-16 |
| CVE-2017-17590 EXP | FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. | Patch early | 9.8 critical | 3.9% | 2017-12-13 |
| CVE-2019-5722 EXP | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL inject… | Patch early | 9.8 critical | 3.9% | 2019-03-21 |
| CVE-2019-8923 EXP | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | Patch early | 9.8 critical | 3.9% | 2019-05-14 |
| CVE-2018-7178 EXP | SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. | Patch early | 9.8 critical | 3.9% | 2018-02-17 |
| CVE-2026-44262 EXP | Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and vali… | Patch early | 9.4 critical | 3.9% | 2026-05-12 |
| CVE-2011-1939 EXP | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction P… | Patch early | 9.8 critical | 3.9% | 2019-11-26 |
| CVE-2023-33592 EXP | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/con… | Patch early | 9.8 critical | 3.8% | 2023-06-28 |
| CVE-2022-4681 EXP | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action a… | Patch early | 9.8 critical | 3.8% | 2023-02-06 |
| CVE-2024-31777 EXP | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoin… | Patch early | 9.8 critical | 3.8% | 2024-06-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt