peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,534 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,566 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2012-5190 EXP Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability Patch early 9.8 critical 4.7% 2020-01-21
CVE-2018-12052 EXP SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php. Patch early 9.8 critical 4.6% 2018-06-08
CVE-2021-26830 EXP SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the… Patch early 9.1 critical 4.6% 2021-04-16
CVE-2002-1798 EXP MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access… Patch early 9.1 critical 4.6% 2002-12-31
CVE-2015-4523 EXP Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanis… Patch early 9.3 critical 4.5% 2017-09-11
CVE-2023-31703 EXP Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject a… Patch early 9.0 critical 4.5% 2023-05-17
CVE-2026-80428 EXP ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to ex… Patch early 9.8 critical 4.5% 2026-08-26
CVE-2006-4428 EXP PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the templ… Patch early 9.8 critical 4.4% 2006-08-29
CVE-2024-48841 EXP Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older. Patch early 10.0 critical 4.4% 2025-01-27
CVE-2023-23162 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. Patch early 9.8 critical 4.4% 2023-02-10
CVE-2023-23163 EXP Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. Patch early 9.8 critical 4.4% 2023-02-10
CVE-2017-17591 EXP Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. Patch early 9.8 critical 4.4% 2017-12-13
CVE-2019-16693 EXP phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. Patch early 9.8 critical 4.3% 2019-09-22
CVE-2017-9602 EXP KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthen… Patch early 9.8 critical 4.3% 2017-06-16
CVE-2012-1124 EXP SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms… Patch early 9.8 critical 4.3% 2020-02-11
CVE-2012-1259 EXP Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.… Patch early 9.8 critical 4.2% 2020-01-09
CVE-2018-7538 EXP A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arb… Patch early 9.8 critical 4.2% 2018-03-12
CVE-2019-12279 EXP Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this… Patch early 9.8 critical 4.2% 2019-05-22
CVE-2015-4073 EXP Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands vi… Patch early 9.8 critical 4.2% 2017-09-20
CVE-2024-53584 EXP OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. Patch early 9.8 critical 4.2% 2025-01-31
CVE-2018-18619 EXP internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently… Patch early 9.8 critical 4.2% 2018-11-29
CVE-2014-2023 EXP Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute… Patch early 9.8 critical 4.1% 2017-10-26
CVE-2022-46945 EXP Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. Patch early 9.1 critical 4.1% 2023-05-26
CVE-2017-9834 EXP SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watup… Patch early 9.8 critical 4.1% 2017-09-07
CVE-2014-9613 EXP Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login param… Patch early 9.8 critical 4.1% 2020-02-19
CVE-2015-7568 EXP SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known us… Patch early 9.8 critical 4.1% 2017-04-24
CVE-2022-27412 EXP Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. Patch early 9.8 critical 4.1% 2022-05-09
CVE-2019-18418 EXP clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session mana… Patch early 9.8 critical 4% 2019-10-24
CVE-2018-6180 EXP A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts. Patch early 9.8 critical 4% 2018-02-08
CVE-2018-9245 EXP The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the logi… Patch early 9.8 critical 4% 2018-04-22
← previous page 54 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt