CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,759 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17610 EXP | E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid p… | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17611 EXP | Doctor Search Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17613 EXP | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17614 EXP | Food Order Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17616 EXP | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17617 EXP | Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17618 EXP | Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17620 EXP | Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17623 EXP | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17624 EXP | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17626 EXP | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | Patch early | 9.8 critical | 3.1% | 2017-12-13 |
| CVE-2017-17645 EXP | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | Patch early | 9.8 critical | 3.1% | 2017-12-18 |
| CVE-2017-17651 EXP | Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitc… | Patch early | 9.8 critical | 3.1% | 2017-12-18 |
| CVE-2018-6024 EXP | SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. | Patch early | 9.8 critical | 3.1% | 2018-02-18 |
| CVE-2018-6364 EXP | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. | Patch early | 9.8 critical | 3.1% | 2018-01-29 |
| CVE-2018-6365 EXP | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. | Patch early | 9.8 critical | 3.1% | 2018-01-29 |
| CVE-2018-6367 EXP | SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php… | Patch early | 9.8 critical | 3.1% | 2018-01-29 |
| CVE-2019-16894 EXP | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. | Patch early | 9.8 critical | 3% | 2019-09-26 |
| CVE-2017-17870 EXP | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | Patch early | 9.8 critical | 3% | 2017-12-27 |
| CVE-2013-6792 EXP | Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability | Patch early | 9.8 critical | 3% | 2020-01-23 |
| CVE-2017-17570 EXP | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17571 EXP | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17572 EXP | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17574 EXP | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17575 EXP | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17576 EXP | FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser paramet… | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17577 EXP | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17578 EXP | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17579 EXP | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17580 EXP | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt