CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,733 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-18800 EXP | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.… | Patch early | 9.8 critical | 3.2% | 2019-05-14 |
| CVE-2018-18801 EXP | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18803 EXP | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18804 EXP | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | Patch early | 9.8 critical | 3.2% | 2018-11-16 |
| CVE-2018-18923 EXP | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproje… | Patch early | 9.8 critical | 3.2% | 2018-12-13 |
| CVE-2006-5021 EXP | Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the roo… | Patch early | 9.8 critical | 3.1% | 2006-09-27 |
| CVE-2018-14592 EXP | The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection… | Patch early | 9.8 critical | 3.1% | 2018-09-20 |
| CVE-2017-12930 EXP | SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface a… | Patch early | 9.8 critical | 3.1% | 2017-09-21 |
| CVE-2018-18755 EXP | K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter. | Patch early | 9.8 critical | 3.1% | 2018-11-16 |
| CVE-2015-3934 EXP | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps… | Patch early | 9.8 critical | 3.1% | 2017-11-21 |
| CVE-2017-15975 EXP | Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. | Patch early | 9.8 critical | 3.1% | 2017-10-29 |
| CVE-2017-15976 EXP | ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. | Patch early | 9.8 critical | 3.1% | 2017-10-29 |
| CVE-2017-17573 EXP | FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17592 EXP | Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17594 EXP | DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17595 EXP | Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17596 EXP | Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17597 EXP | Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17598 EXP | Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17599 EXP | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17600 EXP | Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17601 EXP | Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17602 EXP | Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17603 EXP | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17604 EXP | Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17605 EXP | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17606 EXP | Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2018-6024 EXP | SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. | Patch early | 9.8 critical | 3.1% | 2018-02-18 |
| CVE-2018-6364 EXP | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. | Patch early | 9.8 critical | 3.1% | 2018-01-29 |
| CVE-2018-6365 EXP | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. | Patch early | 9.8 critical | 3.1% | 2018-01-29 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt