peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,882 CVEs 1,728 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-28

1,485 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2015-2147 EXP Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspeci… Patch early 9.8 critical 1.6% 2017-10-06
CVE-2024-50672 EXP A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator acco… Patch early 9.8 critical 1.6% 2024-11-25
CVE-2026-15013 EXP The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions… Patch early 9.8 critical 1.5% 2026-07-16
CVE-2017-15579 EXP In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. Patch early 9.8 critical 1.5% 2017-10-18
CVE-2017-11470 EXP IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter. Patch early 9.8 critical 1.5% 2017-07-20
CVE-2017-11471 EXP IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter. Patch early 9.8 critical 1.5% 2017-07-20
CVE-2006-5603 EXP SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter… Patch early 9.8 critical 1.4% 2006-10-30
CVE-2026-44225 EXP Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every p… Patch early 9.3 critical 1.4% 2026-05-12
CVE-2024-24495 EXP SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET requ… Patch early 9.8 critical 1.3% 2024-02-08
CVE-2025-50455 EXP SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulne… Patch early 9.1 critical 1.2% 2026-07-27
CVE-2024-28595 EXP SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-adm… Patch early 9.8 critical 1.2% 2024-03-19
CVE-2024-6516 EXP Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products:… Patch early 9.0 critical 1.1% 2024-12-05
CVE-2024-48573 EXP A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via… Patch early 9.8 critical 1% 2024-10-29
CVE-2024-48849 EXP Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This is… Patch early 9.4 critical 0.9% 2025-01-29
CVE-2026-25544 EXP Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly… Patch early 9.8 critical 0.9% 2026-02-06
← previous page 50 of 50

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt