CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,806 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-5994 EXP | SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resu… | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6004 EXP | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6005 EXP | SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6368 EXP | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6370 EXP | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6372 EXP | SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6394 EXP | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6395 EXP | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | Patch early | 9.8 critical | 2.7% | 2018-01-30 |
| CVE-2018-6398 EXP | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | Patch early | 9.8 critical | 2.7% | 2018-01-30 |
| CVE-2018-6575 EXP | SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6576 EXP | SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6581 EXP | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6585 EXP | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6604 EXP | SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request. | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2018-6609 EXP | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a s… | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2018-7177 EXP | SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-7179 EXP | SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-7312 EXP | SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-22 |
| CVE-2018-7315 EXP | SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-22 |
| CVE-2018-7477 EXP | SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php… | Patch early | 9.8 critical | 2.7% | 2018-02-28 |
| CVE-2025-1550 EXP | The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archi… | Patch early | 9.8 critical | 2.6% | 2025-03-11 |
| CVE-2017-14738 EXP | FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter… | Patch early | 9.8 critical | 2.6% | 2017-09-30 |
| CVE-2026-26335 EXP | Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Pro… | Patch early | 9.8 critical | 2.6% | 2026-02-13 |
| CVE-2017-15981 EXP | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2017-15982 EXP | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2018-5986 EXP | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. | Patch early | 9.8 critical | 2.6% | 2018-01-24 |
| CVE-2018-5989 EXP | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011… | Patch early | 9.8 critical | 2.6% | 2018-02-17 |
| CVE-2024-44541 EXP | evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin." | Patch early | 9.8 critical | 2.6% | 2024-09-11 |
| CVE-2016-1000124 EXP | Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | Patch early | 9.8 critical | 2.6% | 2016-10-06 |
| CVE-2016-1000125 EXP | Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla | Patch early | 9.8 critical | 2.5% | 2016-10-06 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt