CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,049 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
36,598 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2017-17639 EXP | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17641 EXP | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17636 EXP | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17640 EXP | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17638 EXP | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17630 EXP | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17633 EXP | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detai… | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-15970 EXP | PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | Patch early | 9.8 critical | 2.2% | 2017-10-29 |
| CVE-2017-17627 EXP | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17629 EXP | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17642 EXP | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2017-17635 EXP | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | Patch early | 9.8 critical | 2.2% | 2017-12-13 |
| CVE-2026-24849 EXP | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument(… | Patch early | 9.9 critical | 2.2% | 2026-02-25 |
| CVE-2017-15960 EXP | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15958 EXP | D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15964 EXP | Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15961 EXP | iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2024-42049 EXP | TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection. | Patch early | 9.1 critical | 2.1% | 2024-07-28 |
| CVE-2017-1000474 EXP | Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, l… | Patch early | 9.8 critical | 2.1% | 2018-01-24 |
| CVE-2017-15963 EXP | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15967 EXP | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/templat… | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15959 EXP | Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15969 EXP | PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2017-15968 EXP | MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. | Patch early | 9.8 critical | 2.1% | 2017-10-29 |
| CVE-2026-25994 EXP | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH I… | Patch early | 9.8 critical | 2.1% | 2026-02-11 |
| CVE-2024-48840 EXP | Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATR… | Patch early | 10.0 critical | 2.1% | 2024-12-05 |
| CVE-2017-14703 EXP | SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/. | Patch early | 9.8 critical | 2.1% | 2017-09-26 |
| CVE-2017-15971 EXP | Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin… | Patch early | 9.8 critical | 2% | 2017-10-29 |
| CVE-2024-48445 EXP | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters. | Patch early | 9.8 critical | 2% | 2025-02-04 |
| CVE-2026-58289 EXP | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… | Patch early | 9.0 critical | 2% | 2026-07-03 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt