peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,516 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,565 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2018-7474 EXP An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. Patch early 9.8 critical 6.2% 2018-03-14
CVE-2015-4594 EXP eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a n… Patch early 9.8 critical 6.2% 2017-01-10
CVE-2019-10866 EXP In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-ma… Patch early 9.8 critical 6.2% 2019-05-23
CVE-2009-2382 EXP admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin co… Patch early 9.8 critical 6.2% 2009-07-08
CVE-2021-43650 EXP WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. Patch early 9.8 critical 6.2% 2022-03-22
CVE-2020-7750 EXP This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can… Patch early 9.6 critical 6.1% 2020-10-21
CVE-2015-4633 EXP Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1)… Patch early 9.8 critical 6.1% 2018-10-18
CVE-2023-26918 EXP Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as… Patch early 9.8 critical 6.1% 2023-04-14
CVE-2017-16716 EXP A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. Patch early 9.8 critical 6% 2018-01-05
CVE-2021-44655 EXP Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can… Patch early 9.8 critical 6% 2021-12-15
CVE-2021-44653 EXP Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due… Patch early 9.8 critical 6% 2021-12-15
CVE-2020-15363 EXP The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. Patch early 9.8 critical 5.9% 2020-06-28
CVE-2023-30330 EXP SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.… Patch early 9.8 critical 5.9% 2023-05-12
CVE-2020-8547 EXP phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin wi… Patch early 9.8 critical 5.9% 2020-02-03
CVE-2018-6411 EXP An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to t… Patch early 9.8 critical 5.8% 2018-05-26
CVE-2023-31714 EXP Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities. Patch early 9.8 critical 5.8% 2023-08-30
CVE-2017-5496 EXP Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash. Patch early 9.8 critical 5.8% 2017-03-15
CVE-2017-16780 EXP The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. Patch early 9.8 critical 5.8% 2017-11-10
CVE-2019-19740 EXP Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. Patch early 9.8 critical 5.8% 2019-12-12
CVE-2025-69985 EXP FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/ap… Patch early 9.8 critical 5.7% 2026-02-24
CVE-2022-2070 EXP In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf i… Patch early 9.8 critical 5.7% 2022-09-23
CVE-2004-2061 EXP RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting… Patch early 9.8 critical 5.7% 2004-07-27
CVE-2017-6095 EXP A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticat… Patch early 9.8 critical 5.6% 2017-02-21
CVE-2021-43481 EXP An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. Patch early 9.8 critical 5.6% 2022-04-20
CVE-2017-16543 EXP Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas… Patch early 9.8 critical 5.6% 2017-11-05
CVE-2018-10757 EXP CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt. Patch early 9.8 critical 5.5% 2018-05-05
CVE-2023-31067 EXP An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… Patch early 9.8 critical 5.5% 2023-09-11
CVE-2023-31068 EXP An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMF… Patch early 9.8 critical 5.4% 2023-09-11
CVE-2017-17970 EXP Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php… Patch early 9.8 critical 5.4% 2018-01-12
CVE-2020-18662 EXP SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. Patch early 9.8 critical 5.4% 2021-06-24
← previous page 52 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt