CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
399,554 CVEs
1,729 on KEV
17,272 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
36,568 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2026-49952 EXP | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain u… | Patch early | 9.1 critical | 3.7% | 2026-06-15 |
| CVE-2016-1000123 EXP | Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla | Patch early | 9.8 critical | 3.6% | 2016-10-06 |
| CVE-2017-17619 EXP | Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 3.6% | 2017-12-13 |
| CVE-2017-17622 EXP | Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. | Patch early | 9.8 critical | 3.6% | 2017-12-13 |
| CVE-2017-17621 EXP | Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. | Patch early | 9.8 critical | 3.6% | 2017-12-13 |
| CVE-2017-17721 EXP | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobty… | Patch early | 9.8 critical | 3.6% | 2017-12-18 |
| CVE-2022-4297 EXP | The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX avai… | Patch early | 9.8 critical | 3.6% | 2023-01-02 |
| CVE-2026-58480 EXP | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to uplo… | Patch early | 9.8 critical | 3.6% | 2026-07-08 |
| CVE-2026-36356 EXP | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via t… | Patch early | 9.1 critical | 3.6% | 2026-05-05 |
| CVE-2024-33559 EXP | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue af… | Patch early | 9.3 critical | 3.6% | 2024-04-29 |
| CVE-2015-8261 EXP | The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows rem… | Patch early | 9.8 critical | 3.6% | 2016-01-08 |
| CVE-2023-34635 EXP | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user… | Patch early | 9.8 critical | 3.5% | 2023-07-31 |
| CVE-2008-3604 EXP | SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Patch early | 9.8 critical | 3.5% | 2008-08-12 |
| CVE-2017-15965 EXP | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | Patch early | 9.8 critical | 3.4% | 2017-10-29 |
| CVE-2017-15966 EXP | The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | Patch early | 9.8 critical | 3.4% | 2017-10-29 |
| CVE-2015-7564 EXP | Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramete… | Patch early | 9.8 critical | 3.4% | 2017-04-12 |
| CVE-2025-8730 EXP | A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionali… | Patch early | 9.8 critical | 3.4% | 2025-08-08 |
| CVE-2017-17999 EXP | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to… | Patch early | 9.8 critical | 3.3% | 2018-01-23 |
| CVE-2026-24897 EXP | Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… | Patch early | 10.0 critical | 3.3% | 2026-01-28 |
| CVE-2023-34581 EXP | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | Patch early | 9.8 critical | 3.3% | 2023-06-12 |
| CVE-2018-17379 EXP | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17378 EXP | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17384 EXP | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17380 EXP | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2018-17375 EXP | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. | Patch early | 9.8 critical | 3.3% | 2018-09-28 |
| CVE-2015-2798 EXP | SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id paramet… | Patch early | 9.8 critical | 3.3% | 2017-07-25 |
| CVE-2018-11444 EXP | A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. | Patch early | 9.8 critical | 3.2% | 2018-05-25 |
| CVE-2018-12055 EXP | Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_g… | Patch early | 9.8 critical | 3.2% | 2018-06-08 |
| CVE-2018-11535 EXP | An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL i… | Patch early | 9.8 critical | 3.2% | 2018-05-29 |
| CVE-2018-13045 EXP | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands v… | Patch early | 9.8 critical | 3.2% | 2019-01-02 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt