CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
36,598 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-5974 EXP | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. | Patch early | 9.8 critical | 2.7% | 2018-02-17 |
| CVE-2018-6609 EXP | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a s… | Patch early | 9.8 critical | 2.7% | 2018-02-05 |
| CVE-2025-1550 EXP | The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archi… | Patch early | 9.8 critical | 2.6% | 2025-03-11 |
| CVE-2017-14738 EXP | FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter… | Patch early | 9.8 critical | 2.6% | 2017-09-30 |
| CVE-2026-26335 EXP | Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Pro… | Patch early | 9.8 critical | 2.6% | 2026-02-13 |
| CVE-2018-5989 EXP | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011… | Patch early | 9.8 critical | 2.6% | 2018-02-17 |
| CVE-2017-15981 EXP | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2017-15982 EXP | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | Patch early | 9.8 critical | 2.6% | 2017-10-31 |
| CVE-2018-5986 EXP | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. | Patch early | 9.8 critical | 2.6% | 2018-01-24 |
| CVE-2024-44541 EXP | evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin." | Patch early | 9.8 critical | 2.6% | 2024-09-11 |
| CVE-2016-1000124 EXP | Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | Patch early | 9.8 critical | 2.6% | 2016-10-06 |
| CVE-2016-1000125 EXP | Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla | Patch early | 9.8 critical | 2.5% | 2016-10-06 |
| CVE-2026-61447 EXP | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without… | Patch early | 10.0 critical | 2.5% | 2026-07-11 |
| CVE-2026-65008 EXP | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), wh… | Patch early | 9.8 critical | 2.5% | 2026-07-21 |
| CVE-2024-48852 EXP | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.… | Patch early | 9.4 critical | 2.5% | 2025-01-29 |
| CVE-2026-32746 EXP | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does n… | Patch early | 9.8 critical | 2.4% | 2026-03-13 |
| CVE-2017-15081 EXP | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | Patch early | 9.8 critical | 2.4% | 2017-10-24 |
| CVE-2026-2624 EXP | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows… | Patch early | 9.8 critical | 2.4% | 2026-02-25 |
| CVE-2024-38944 EXP | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?for… | Patch early | 9.8 critical | 2.4% | 2024-07-22 |
| CVE-2024-53537 EXP | An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager. | Patch early | 9.1 critical | 2.4% | 2025-01-31 |
| CVE-2026-61459 EXP | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) th… | Patch early | 9.8 critical | 2.4% | 2026-07-10 |
| CVE-2026-38526 EXP | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arb… | Patch early | 9.9 critical | 2.4% | 2026-04-14 |
| CVE-2016-4337 EXP | SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands… | Patch early | 9.8 critical | 2.3% | 2017-04-12 |
| CVE-2026-42607 EXP | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE)… | Patch early | 9.1 critical | 2.3% | 2026-05-11 |
| CVE-2025-57174 EXP | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous version… | Patch early | 9.8 critical | 2.2% | 2025-09-15 |
| CVE-2017-15970 EXP | PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | Patch early | 9.8 critical | 2.2% | 2017-10-29 |
| CVE-2017-17627 EXP | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17628 EXP | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17629 EXP | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17630 EXP | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt