peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,692 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2024-23346 EXP Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFa… Patch early 9.3 critical 3.8% 2024-02-21
CVE-2026-25643 EXP Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (R… Patch early 9.1 critical 3.8% 2026-02-06
CVE-2017-17648 EXP Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. Patch early 9.8 critical 3.8% 2017-12-13
CVE-2018-5980 EXP SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2018-6578 EXP SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions req… Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-6579 EXP SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-6584 EXP SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2014-5093 EXP Status2k does not remove the install directory allowing credential reset. Patch early 9.8 critical 3.8% 2020-01-10
CVE-2026-59827 EXP Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances wi… Patch early 9.9 critical 3.8% 2026-07-09
CVE-2015-3933 EXP Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary… Patch early 9.8 critical 3.8% 2017-11-08
CVE-2017-11494 EXP SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user p… Patch early 9.8 critical 3.7% 2017-08-02
CVE-2016-3694 EXP Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remo… Patch early 9.8 critical 3.7% 2017-02-15
CVE-2014-9558 EXP Multiple SQL injection vulnerabilities in SmartCMS v.2. Patch early 9.8 critical 3.7% 2017-08-28
CVE-2015-7346 EXP SQL injection vulnerability in ZCMS 1.1. Patch early 9.8 critical 3.7% 2017-06-07
CVE-2017-15974 EXP tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. Patch early 9.8 critical 3.7% 2017-10-29
CVE-2023-31069 EXP An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. Patch early 9.8 critical 3.7% 2023-09-11
CVE-2023-23156 EXP Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product p… Patch early 9.8 critical 3.7% 2023-02-27
CVE-2015-7567 EXP SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter. Patch early 9.8 critical 3.7% 2020-02-18
CVE-2017-17612 EXP Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. Patch early 9.8 critical 3.7% 2017-12-13
CVE-2026-49952 EXP Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain u… Patch early 9.1 critical 3.7% 2026-06-15
CVE-2016-1000123 EXP Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla Patch early 9.8 critical 3.6% 2016-10-06
CVE-2017-17619 EXP Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.6% 2017-12-13
CVE-2017-17621 EXP Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. Patch early 9.8 critical 3.6% 2017-12-13
CVE-2017-17622 EXP Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. Patch early 9.8 critical 3.6% 2017-12-13
CVE-2017-17721 EXP CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobty… Patch early 9.8 critical 3.6% 2017-12-18
CVE-2022-4297 EXP The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX avai… Patch early 9.8 critical 3.6% 2023-01-02
CVE-2026-58480 EXP Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to uplo… Patch early 9.8 critical 3.6% 2026-07-08
CVE-2026-36356 EXP The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via t… Patch early 9.1 critical 3.6% 2026-05-05
CVE-2024-33559 EXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue af… Patch early 9.3 critical 3.6% 2024-04-29
CVE-2015-8261 EXP The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows rem… Patch early 9.8 critical 3.6% 2016-01-08
← previous page 41 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt