peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,825 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-0880 EXP The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerabi… Patch early 7.0 high 3.1% 2018-03-14
CVE-2004-1592 EXP PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying… Patch early 7.5 high 3.1% 2004-12-31
CVE-2018-6024 EXP SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. Patch early 9.8 critical 3.1% 2018-02-18
CVE-2018-6364 EXP SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. Patch early 9.8 critical 3.1% 2018-01-29
CVE-2018-6365 EXP SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. Patch early 9.8 critical 3.1% 2018-01-29
CVE-2018-6367 EXP SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php… Patch early 9.8 critical 3.1% 2018-01-29
CVE-2017-15975 EXP Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-15976 EXP ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-17573 EXP FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17592 EXP Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17594 EXP DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17595 EXP Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17596 EXP Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17597 EXP Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17598 EXP Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17599 EXP Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17600 EXP Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17601 EXP Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17602 EXP Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17603 EXP Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17604 EXP Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17605 EXP Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17606 EXP Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17607 EXP CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17608 EXP Child Care Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17609 EXP Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17610 EXP E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid p… Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17611 EXP Doctor Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17613 EXP Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17614 EXP Food Order Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
← previous page 318 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt