peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,759 CVEs 1,728 on KEV 17,267 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17581 EXP FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17582 EXP FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17583 EXP FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17584 EXP FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17585 EXP FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17586 EXP FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17587 EXP FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17588 EXP FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17589 EXP FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17625 EXP Professional Service Script 1.0 has SQL Injection via the service-list city parameter. Patch early 9.8 critical 3% 2017-12-13
CVE-2017-17643 EXP FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. Patch early 9.8 critical 3% 2017-12-18
CVE-2018-6363 EXP SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. Patch early 9.8 critical 3% 2018-01-29
CVE-2017-7312 EXP An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read exis… Patch early 9.8 critical 3% 2017-06-07
CVE-2023-48974 EXP Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the se… Patch early 9.6 critical 3% 2024-02-08
CVE-2017-6089 EXP SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id paramet… Patch early 9.8 critical 3% 2017-10-03
CVE-2026-7567 EXP The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input v… Patch early 9.8 critical 2.9% 2026-05-01
CVE-2017-14396 EXP In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrat… Patch early 9.8 critical 2.9% 2017-09-12
CVE-2008-1511 EXP Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComme… Patch early 9.8 critical 2.9% 2008-03-25
CVE-2017-15972 EXP SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /… Patch early 9.8 critical 2.9% 2017-10-29
CVE-2017-15973 EXP Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php. Patch early 9.8 critical 2.9% 2017-10-29
CVE-2018-17428 EXP An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter. Patch early 9.8 critical 2.8% 2018-10-03
CVE-2024-35540 EXP A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Patch early 9.0 critical 2.8% 2024-08-20
CVE-2024-48839 EXP Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02;… Patch early 10.0 critical 2.8% 2024-12-05
CVE-2022-45297 EXP EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. Patch early 9.8 critical 2.8% 2023-01-31
CVE-2011-4094 EXP Jara 1.6 has a SQL injection vulnerability. Patch early 9.8 critical 2.7% 2020-01-21
CVE-2018-16659 EXP An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST pa… Patch early 9.8 critical 2.7% 2018-09-28
CVE-2020-15468 EXP Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. Patch early 9.8 critical 2.7% 2020-07-01
CVE-2018-6582 EXP SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHo… Patch early 9.8 critical 2.7% 2018-02-05
CVE-2018-7180 EXP SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5970 EXP SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. Patch early 9.8 critical 2.7% 2018-02-17
← previous page 45 of 50 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt