CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,692 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2023-34635 EXP | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user… | Patch early | 9.8 critical | 3.5% | 2023-07-31 |
| CVE-2008-3604 EXP | SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Patch early | 9.8 critical | 3.5% | 2008-08-12 |
| CVE-2017-15965 EXP | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | Patch early | 9.8 critical | 3.4% | 2017-10-29 |
| CVE-2017-15966 EXP | The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | Patch early | 9.8 critical | 3.4% | 2017-10-29 |
| CVE-2015-7564 EXP | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramete… | Patch early | 9.8 critical | 3.4% | 2017-04-12 |
| CVE-2025-8730 EXP | A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionali… | Patch early | 9.8 critical | 3.4% | 2025-08-08 |
| CVE-2017-17999 EXP | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to… | Patch early | 9.8 critical | 3.3% | 2018-01-23 |
| CVE-2026-24897 EXP | Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… | Patch early | 10.0 critical | 3.3% | 2026-01-28 |
| CVE-2023-34581 EXP | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | Patch early | 9.8 critical | 3.3% | 2023-06-12 |
| CVE-2018-17375 EXP | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17378 EXP | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17379 EXP | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17380 EXP | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17384 EXP | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2015-2798 EXP | SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id paramet… | Patch early | 9.8 critical | 3.3% | 2017-07-25 |
| CVE-2018-11444 EXP | A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. | Patch early | 9.8 critical | 3.2% | 2018-05-25 |
| CVE-2018-11535 EXP | An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL i… | Patch early | 9.8 critical | 3.2% | 2018-05-29 |
| CVE-2018-12055 EXP | Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_g… | Patch early | 9.8 critical | 3.2% | 2018-06-08 |
| CVE-2018-13045 EXP | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands v… | Patch early | 9.8 critical | 3.2% | 2019-01-02 |
| CVE-2018-17376 EXP | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17377 EXP | SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17382 EXP | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17383 EXP | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17385 EXP | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17391 EXP | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17394 EXP | SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-17397 EXP | SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. | Patch early | 9.8 critical | 3.2% | 2018-09-28 |
| CVE-2018-18763 EXP | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18795 EXP | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18798 EXP | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.ph… | Patch early | 9.8 critical | 3.2% | 2019-03-21 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt