peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,646 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,574 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-17624 EXP PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17606 EXP Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17614 EXP Food Order Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17613 EXP Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2018-6024 EXP SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter. Patch early 9.8 critical 3.1% 2018-02-18
CVE-2017-15975 EXP Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-17609 EXP Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17603 EXP Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17620 EXP Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17601 EXP Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17618 EXP Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17605 EXP Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17573 EXP FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17617 EXP Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-15976 EXP ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. Patch early 9.8 critical 3.1% 2017-10-29
CVE-2017-17626 EXP Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17611 EXP Doctor Search Script 1.0 has SQL Injection via the /list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17600 EXP Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17594 EXP DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17604 EXP Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17645 EXP Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. Patch early 9.8 critical 3.1% 2017-12-18
CVE-2017-17592 EXP Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2018-6364 EXP SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. Patch early 9.8 critical 3.1% 2018-01-29
CVE-2018-6365 EXP SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. Patch early 9.8 critical 3.1% 2018-01-29
CVE-2018-6367 EXP SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php… Patch early 9.8 critical 3.1% 2018-01-29
CVE-2017-17597 EXP Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2017-17651 EXP Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitc… Patch early 9.8 critical 3.1% 2017-12-18
CVE-2017-17616 EXP Event Search Script 1.0 has SQL Injection via the /event-list city parameter. Patch early 9.8 critical 3.1% 2017-12-13
CVE-2019-16894 EXP download.php in inoERP 4.15 allows SQL injection through insecure deserialization. Patch early 9.8 critical 3% 2019-09-26
CVE-2017-17870 EXP The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. Patch early 9.8 critical 3% 2017-12-27
← previous page 58 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt