CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,734 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
207,912 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2006-6086 EXP | PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pea… | Patch early | 5.1 medium | 3% | 2006-11-24 |
| CVE-2017-17570 EXP | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17571 EXP | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17572 EXP | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17574 EXP | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17575 EXP | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17576 EXP | FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser paramet… | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17577 EXP | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17578 EXP | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17579 EXP | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17580 EXP | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17581 EXP | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17582 EXP | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17583 EXP | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17584 EXP | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17585 EXP | FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17586 EXP | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17587 EXP | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17588 EXP | FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17589 EXP | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17625 EXP | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17643 EXP | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | Patch early | 9.8 critical | 3% | 2017-12-18 |
| CVE-2018-6363 EXP | SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. | Patch early | 9.8 critical | 3% | 2018-01-29 |
| CVE-2007-5113 EXP | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified q… | Patch early | 5.0 medium | 3% | 2007-09-26 |
| CVE-2002-1488 EXP | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a mis… | Patch early | 5.0 medium | 3% | 2003-04-02 |
| CVE-2018-5754 EXP | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allow… | Patch early | 5.4 medium | 3% | 2018-06-16 |
| CVE-2006-4464 EXP | The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that con… | Patch early | 5.0 medium | 3% | 2006-08-31 |
| CVE-2017-7312 EXP | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read exis… | Patch early | 9.8 critical | 3% | 2017-06-07 |
| CVE-2005-1202 EXP | Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via t… | Patch early | 6.8 medium | 3% | 2005-05-02 |
| CVE-2017-0282 EXP | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1… | Patch early | 5.0 medium | 3% | 2017-06-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt