peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,554 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,568 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-6550 EXP Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TA… Patch early 9.8 critical 4% 2017-03-20
CVE-2020-13118 EXP An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter communi… Patch early 9.8 critical 4% 2020-05-16
CVE-2017-17590 EXP FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. Patch early 9.8 critical 3.9% 2017-12-13
CVE-2019-5722 EXP An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL inject… Patch early 9.8 critical 3.9% 2019-03-21
CVE-2019-8923 EXP XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. Patch early 9.8 critical 3.9% 2019-05-14
CVE-2018-7178 EXP SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. Patch early 9.8 critical 3.9% 2018-02-17
CVE-2026-44262 EXP Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and vali… Patch early 9.4 critical 3.9% 2026-05-12
CVE-2011-1939 EXP SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction P… Patch early 9.8 critical 3.9% 2019-11-26
CVE-2023-33592 EXP Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/con… Patch early 9.8 critical 3.8% 2023-06-28
CVE-2022-4681 EXP The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action a… Patch early 9.8 critical 3.8% 2023-02-06
CVE-2024-31777 EXP File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoin… Patch early 9.8 critical 3.8% 2024-06-13
CVE-2024-23346 EXP Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFa… Patch early 9.3 critical 3.8% 2024-02-21
CVE-2026-25643 EXP Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (R… Patch early 9.1 critical 3.8% 2026-02-06
CVE-2018-6579 EXP SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-6584 EXP SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2018-6578 EXP SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions req… Patch early 9.8 critical 3.8% 2018-02-02
CVE-2018-5980 EXP SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. Patch early 9.8 critical 3.8% 2018-02-17
CVE-2017-17648 EXP Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. Patch early 9.8 critical 3.8% 2017-12-13
CVE-2014-5093 EXP Status2k does not remove the install directory allowing credential reset. Patch early 9.8 critical 3.8% 2020-01-10
CVE-2026-59827 EXP Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances wi… Patch early 9.9 critical 3.8% 2026-07-09
CVE-2015-3933 EXP Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary… Patch early 9.8 critical 3.8% 2017-11-08
CVE-2017-11494 EXP SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user p… Patch early 9.8 critical 3.7% 2017-08-02
CVE-2016-3694 EXP Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remo… Patch early 9.8 critical 3.7% 2017-02-15
CVE-2014-9558 EXP Multiple SQL injection vulnerabilities in SmartCMS v.2. Patch early 9.8 critical 3.7% 2017-08-28
CVE-2015-7346 EXP SQL injection vulnerability in ZCMS 1.1. Patch early 9.8 critical 3.7% 2017-06-07
CVE-2017-15974 EXP tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. Patch early 9.8 critical 3.7% 2017-10-29
CVE-2023-31069 EXP An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page. Patch early 9.8 critical 3.7% 2023-09-11
CVE-2023-23156 EXP Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product p… Patch early 9.8 critical 3.7% 2023-02-27
CVE-2015-7567 EXP SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter. Patch early 9.8 critical 3.7% 2020-02-18
CVE-2017-17612 EXP Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. Patch early 9.8 critical 3.7% 2017-12-13
← previous page 55 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt