CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,240 CVEs
1,739 on KEV
17,300 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
187,825 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17576 EXP | FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser paramet… | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17577 EXP | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17578 EXP | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17579 EXP | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17580 EXP | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17581 EXP | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17582 EXP | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17583 EXP | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17584 EXP | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17585 EXP | FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17586 EXP | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17587 EXP | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17588 EXP | FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17589 EXP | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17625 EXP | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | Patch early | 9.8 critical | 3% | 2017-12-13 |
| CVE-2017-17643 EXP | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | Patch early | 9.8 critical | 3% | 2017-12-18 |
| CVE-2024-39304 EXP | ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due… | Patch early | 8.8 high | 3% | 2024-07-26 |
| CVE-2013-0135 EXP | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1)… | Patch early | 7.5 high | 3% | 2013-04-09 |
| CVE-2005-1005 EXP | ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstra… | Patch early | 7.5 high | 3% | 2005-05-02 |
| CVE-2017-7312 EXP | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read exis… | Patch early | 9.8 critical | 3% | 2017-06-07 |
| CVE-2019-6710 EXP | Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. | Patch early | 8.8 high | 3% | 2019-03-07 |
| CVE-2006-2794 EXP | Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter. | Patch early | 7.8 high | 3% | 2006-06-03 |
| CVE-2015-4630 EXP | Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x bef… | Patch early | 8.0 high | 3% | 2018-10-18 |
| CVE-2007-0389 EXP | Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allow… | Patch early | 7.8 high | 3% | 2007-01-19 |
| CVE-2007-5820 EXP | Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files… | Patch early | 9.3 high | 3% | 2007-11-05 |
| CVE-2008-4425 EXP | Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary fil… | Patch early | 8.8 high | 3% | 2008-10-03 |
| CVE-2005-4657 EXP | Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/vie… | Patch early | 7.5 high | 3% | 2005-12-31 |
| CVE-2006-2295 EXP | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter… | Patch early | 7.5 high | 3% | 2006-05-10 |
| CVE-2008-1992 EXP | Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which… | Patch early | 7.5 high | 3% | 2008-04-27 |
| CVE-2008-6844 EXP | The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote att… | Patch early | 7.5 high | 3% | 2009-07-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt