peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

404,237 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-11

187,825 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17616 EXP Event Search Script 1.0 has SQL Injection via the /event-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17617 EXP Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17618 EXP Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17620 EXP Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17623 EXP Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17624 EXP PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17626 EXP Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17645 EXP Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. Patch early 9.8 critical 3.1% 2017-12-18
CVE-2017-17651 EXP Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitc… Patch early 9.8 critical 3.1% 2017-12-18
CVE-2007-1075 EXP TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters. Patch early 7.8 high 3.1% 2007-02-22
CVE-2023-1211 EXP SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. Patch early 7.2 high 3.1% 2023-03-07
CVE-2008-1860 EXP Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Confi… Patch early 9.3 high 3% 2008-04-17
CVE-2010-0605 EXP SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute ar… Patch early 7.5 high 3% 2010-02-11
CVE-2010-1873 EXP SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary S… Patch early 7.5 high 3% 2010-05-12
CVE-2009-4747 EXP PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to e… Patch early 7.5 high 3% 2010-03-26
CVE-2008-2282 EXP admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admi… Patch early 7.5 high 3% 2008-05-18
CVE-2008-2081 EXP Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local fil… Patch early 9.0 high 3% 2008-05-05
CVE-2015-7293 EXP Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. Patch early 8.8 high 3% 2017-09-25
CVE-2019-6282 EXP ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlse… Patch early 8.8 high 3% 2019-03-21
CVE-2008-2822 EXP Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arb… Patch early 9.3 high 3% 2008-06-23
CVE-2015-2553 EXP The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,… Patch early 7.2 high 3% 2015-10-14
CVE-2015-2055 EXP Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. Patch early 7.8 high 3% 2015-02-23
CVE-2007-5174 EXP Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (do… Patch early 7.5 high 3% 2007-10-03
CVE-2017-14848 EXP WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. Patch early 8.8 high 3% 2017-10-03
CVE-2009-2395 EXP SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands… Patch early 7.5 high 3% 2009-07-09
CVE-2008-1620 EXP Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote at… Patch early 7.5 high 3% 2008-04-02
CVE-2008-4749 EXP Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, all… Patch early 9.3 high 3% 2008-10-27
CVE-2007-5684 EXP Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an abso… Patch early 7.5 high 3% 2007-10-26
CVE-2006-5102 EXP PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remo… Patch early 7.5 high 3% 2006-10-03
CVE-2015-1862 EXP The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directo… Patch early 7.0 high 3% 2018-02-09
← previous page 319 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt