CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,831 CVEs
1,728 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-24849 EXP | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument(… | Patch early | 9.9 critical | 2.2% | 2026-02-25 |
| CVE-2017-15958 EXP | D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15960 EXP | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15961 EXP | iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15964 EXP | Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2024-42049 EXP | TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection. | Patch early | 9.1 critical | 2.1% | 2024-07-28 |
| CVE-2017-1000474 EXP | Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, l… | Patch early | 9.8 critical | 2.1% | 2018-01-24 |
| CVE-2017-15959 EXP | Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15963 EXP | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15967 EXP | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/templat… | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15968 EXP | MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15969 EXP | PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2024-48840 EXP | Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATR… | Patch early | 10.0 critical | 2.1% | 2024-12-05 |
| CVE-2017-14703 EXP | SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/. | Patch early | 9.8 critical | 2.1% | 2017-09-26 |
| CVE-2017-15971 EXP | Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin… | Patch early | 9.8 critical | 2% | 2017-10-29 |
| CVE-2026-25994 EXP | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH I… | Patch early | 9.8 critical | 2% | 2026-02-11 |
| CVE-2024-48445 EXP | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters. | Patch early | 9.8 critical | 2% | 2025-02-04 |
| CVE-2026-58289 EXP | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… | Patch early | 9.0 critical | 2% | 2026-07-03 |
| CVE-2017-15987 EXP | Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. | Patch early | 9.8 critical | 2% | 2017-10-31 |
| CVE-2018-6577 EXP | SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions r… | Patch early | 9.8 critical | 2% | 2018-02-02 |
| CVE-2018-7319 EXP | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | Patch early | 9.8 critical | 2% | 2018-02-22 |
| CVE-2017-9730 EXP | SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" pa… | Patch early | 9.8 critical | 2% | 2017-06-19 |
| CVE-2018-6373 EXP | SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action. | Patch early | 9.8 critical | 1.9% | 2018-02-17 |
| CVE-2018-5211 EXP | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | Patch early | 9.8 critical | 1.9% | 2018-01-09 |
| CVE-2018-5977 EXP | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request. | Patch early | 9.8 critical | 1.9% | 2018-01-24 |
| CVE-2024-48845 EXP | Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized ad… | Patch early | 9.4 critical | 1.8% | 2024-12-05 |
| CVE-2025-34282 EXP | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker c… | Patch early | 9.1 critical | 1.8% | 2025-10-17 |
| CVE-2024-51550 EXP | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected pr… | Patch early | 10.0 critical | 1.8% | 2024-12-05 |
| CVE-2005-4891 EXP | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL stateme… | Patch early | 9.8 critical | 1.7% | 2020-01-15 |
| CVE-2024-41947 EXP | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with… | Patch early | 9.0 critical | 1.7% | 2024-07-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt