CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-61447 EXP | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without… | Patch early | 10.0 critical | 2.5% | 2026-07-11 |
| CVE-2026-65008 EXP | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), wh… | Patch early | 9.8 critical | 2.5% | 2026-07-21 |
| CVE-2024-48852 EXP | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.… | Patch early | 9.4 critical | 2.5% | 2025-01-29 |
| CVE-2026-32746 EXP | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does n… | Patch early | 9.8 critical | 2.4% | 2026-03-13 |
| CVE-2017-15081 EXP | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | Patch early | 9.8 critical | 2.4% | 2017-10-24 |
| CVE-2026-2624 EXP | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows… | Patch early | 9.8 critical | 2.4% | 2026-02-25 |
| CVE-2024-38944 EXP | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?for… | Patch early | 9.8 critical | 2.4% | 2024-07-22 |
| CVE-2024-53537 EXP | An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager. | Patch early | 9.1 critical | 2.4% | 2025-01-31 |
| CVE-2026-61459 EXP | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) th… | Patch early | 9.8 critical | 2.4% | 2026-07-10 |
| CVE-2026-38526 EXP | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arb… | Patch early | 9.9 critical | 2.4% | 2026-04-14 |
| CVE-2016-4337 EXP | SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands… | Patch early | 9.8 critical | 2.3% | 2017-04-12 |
| CVE-2026-42607 EXP | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE)… | Patch early | 9.1 critical | 2.3% | 2026-05-11 |
| CVE-2025-57174 EXP | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous version… | Patch early | 9.8 critical | 2.2% | 2025-09-15 |
| CVE-2017-15970 EXP | PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | Patch early | 9.8 critical | 2.2% | 2017-10-29 |
| CVE-2017-17627 EXP | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17628 EXP | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17629 EXP | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17630 EXP | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17631 EXP | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17632 EXP | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17633 EXP | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detai… | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17634 EXP | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17635 EXP | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17636 EXP | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17637 EXP | Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17638 EXP | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17639 EXP | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17640 EXP | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17641 EXP | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17642 EXP | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt