peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,226 CVEs 1,739 on KEV 17,298 EPSS ≥ 10% 25,091 with exploits synced 2026-10-08

207,671 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2004-2121 EXP Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files… Patch early 5.0 medium 3.1% 2004-12-31
CVE-2005-3947 EXP Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filenam… Patch early 5.0 medium 3.1% 2005-12-01
CVE-2017-15975 EXP Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-15976 EXP ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-17573 EXP FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17592 EXP Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17594 EXP DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17595 EXP Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17596 EXP Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17597 EXP Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17598 EXP Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17599 EXP Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17600 EXP Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17601 EXP Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17602 EXP Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17603 EXP Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17604 EXP Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17605 EXP Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17606 EXP Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17607 EXP CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17608 EXP Child Care Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17609 EXP Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17610 EXP E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid p… Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17611 EXP Doctor Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17613 EXP Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17614 EXP Food Order Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17616 EXP Event Search Script 1.0 has SQL Injection via the /event-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17617 EXP Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17618 EXP Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17620 EXP Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
← previous page 239 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt