peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

399,810 CVEs 1,729 on KEV 17,272 EPSS ≥ 10% 25,086 with exploits synced 2026-09-30

36,583 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2017-15972 EXP SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /… Patch early 9.8 critical 2.9% 2017-10-29
CVE-2018-17428 EXP An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter. Patch early 9.8 critical 2.8% 2018-10-03
CVE-2024-35540 EXP A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Patch early 9.0 critical 2.8% 2024-08-20
CVE-2024-48839 EXP Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02;… Patch early 10.0 critical 2.8% 2024-12-05
CVE-2022-45297 EXP EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. Patch early 9.8 critical 2.8% 2023-01-31
CVE-2011-4094 EXP Jara 1.6 has a SQL injection vulnerability. Patch early 9.8 critical 2.7% 2020-01-21
CVE-2018-16659 EXP An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST pa… Patch early 9.8 critical 2.7% 2018-09-28
CVE-2020-15468 EXP Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. Patch early 9.8 critical 2.7% 2020-07-01
CVE-2018-7180 EXP SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-6582 EXP SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHo… Patch early 9.8 critical 2.7% 2018-02-05
CVE-2018-5974 EXP SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5983 EXP SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5970 EXP SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5975 EXP SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5990 EXP SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-6370 EXP SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-6368 EXP SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5991 EXP SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerabili… Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5994 EXP SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resu… Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5987 EXP SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action… Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5992 EXP SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5984 EXP SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI. Patch early 9.8 critical 2.7% 2018-01-24
CVE-2018-6005 EXP SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-6372 EXP SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5978 EXP SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. Patch early 9.8 critical 2.7% 2018-01-24
CVE-2018-6004 EXP SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5971 EXP SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5982 EXP SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5993 EXP SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request. Patch early 9.8 critical 2.7% 2018-02-17
CVE-2018-5981 EXP SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. Patch early 9.8 critical 2.7% 2018-02-17
← previous page 60 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt