CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
403,932 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-10
208,037 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-5978 EXP | SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. | Patch early | 9.8 critical | 2.7% | 2018-01-24 |
| CVE-2018-5981 EXP | SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5982 EXP | SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5983 EXP | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5984 EXP | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI. | Patch early | 9.8 critical | 2.7% | 2018-01-24 |
| CVE-2018-5987 EXP | SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action… | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5990 EXP | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5991 EXP | SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerabili… | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5992 EXP | SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5993 EXP | SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-5994 EXP | SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resu… | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6004 EXP | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6005 EXP | SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6368 EXP | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6370 EXP | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6372 EXP | SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6394 EXP | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6395 EXP | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | Patch early | 9.8 critical | 2.7% | 2018-01-30 |
| CVE-2018-6398 EXP | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | Patch early | 9.8 critical | 2.7% | 2018-01-30 |
| CVE-2018-6575 EXP | SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6576 EXP | SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6581 EXP | SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-02 |
| CVE-2018-6585 EXP | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6604 EXP | SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request. | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2018-6609 EXP | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a s… | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2017-17871 EXP | The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | Patch early | 9.8 critical | 2.7% | 2017-12-27 |
| CVE-2017-17872 EXP | The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | Patch early | 9.8 critical | 2.7% | 2017-12-27 |
| CVE-2017-17873 EXP | Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI. | Patch early | 9.8 critical | 2.7% | 2017-12-27 |
| CVE-2017-17875 EXP | The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action. | Patch early | 9.8 critical | 2.7% | 2017-12-27 |
| CVE-2017-15977 EXP | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | Patch early | 9.8 critical | 2.7% | 2017-10-31 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt