peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,367 CVEs 1,739 on KEV 17,299 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

208,322 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15970 EXP PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. Patch early 9.8 critical 2.2% 2017-10-29
CVE-2017-17627 EXP Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17628 EXP Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17629 EXP Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17630 EXP Yoga Class Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17631 EXP Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17632 EXP Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17633 EXP Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detai… Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17634 EXP Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17635 EXP MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17636 EXP MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17637 EXP Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17638 EXP Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17639 EXP Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17640 EXP Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17641 EXP Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2017-17642 EXP Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. Patch early 9.8 critical 2.2% 2017-12-13
CVE-2005-3412 EXP Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a t… Patch early 4.3 medium 2.2% 2005-11-01
CVE-2010-4347 EXP The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain priv… Patch early 6.9 medium 2.2% 2010-12-22
CVE-2026-24849 EXP OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument(… Patch early 9.9 critical 2.2% 2026-02-25
CVE-2006-4751 EXP Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitr… Patch early 6.8 medium 2.2% 2006-09-13
CVE-2008-6336 EXP Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to rea… Patch early 4.3 medium 2.2% 2009-02-27
CVE-2006-1645 EXP Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitr… Patch early 6.8 medium 2.2% 2006-04-06
CVE-2006-5219 EXP SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a doubl… Patch early 5.1 medium 2.2% 2006-10-10
CVE-2014-7176 EXP SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt pa… Patch early 6.5 medium 2.2% 2014-11-04
CVE-2013-4881 EXP Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to h… Patch early 6.8 medium 2.2% 2013-08-19
CVE-2006-3909 EXP Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week par… Patch early 6.8 medium 2.2% 2006-07-27
CVE-2006-4540 EXP Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML vi… Patch early 6.8 medium 2.2% 2006-09-05
CVE-2008-6736 EXP Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, a… Patch early 6.4 medium 2.2% 2009-04-21
CVE-2008-6065 EXP Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTOR… Patch early 5.1 medium 2.2% 2009-02-05
← previous page 294 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt