CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
400,143 CVEs
1,730 on KEV
17,275 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-30
36,608 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2018-7319 EXP | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | Patch early | 9.8 critical | 2% | 2018-02-22 |
| CVE-2018-6577 EXP | SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions r… | Patch early | 9.8 critical | 2% | 2018-02-02 |
| CVE-2017-15987 EXP | Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. | Patch early | 9.8 critical | 2% | 2017-10-31 |
| CVE-2017-9730 EXP | SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" pa… | Patch early | 9.8 critical | 2% | 2017-06-19 |
| CVE-2018-6373 EXP | SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action. | Patch early | 9.8 critical | 1.9% | 2018-02-17 |
| CVE-2018-5211 EXP | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | Patch early | 9.8 critical | 1.9% | 2018-01-09 |
| CVE-2018-5977 EXP | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request. | Patch early | 9.8 critical | 1.9% | 2018-01-24 |
| CVE-2024-48845 EXP | Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized ad… | Patch early | 9.4 critical | 1.8% | 2024-12-05 |
| CVE-2025-34282 EXP | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker c… | Patch early | 9.1 critical | 1.8% | 2025-10-17 |
| CVE-2024-51550 EXP | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected pr… | Patch early | 10.0 critical | 1.8% | 2024-12-05 |
| CVE-2005-4891 EXP | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL stateme… | Patch early | 9.8 critical | 1.7% | 2020-01-15 |
| CVE-2024-41947 EXP | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with… | Patch early | 9.0 critical | 1.7% | 2024-07-31 |
| CVE-2015-2147 EXP | Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspeci… | Patch early | 9.8 critical | 1.6% | 2017-10-06 |
| CVE-2024-50672 EXP | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator acco… | Patch early | 9.8 critical | 1.6% | 2024-11-25 |
| CVE-2026-15013 EXP | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions… | Patch early | 9.8 critical | 1.5% | 2026-07-16 |
| CVE-2017-15579 EXP | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. | Patch early | 9.8 critical | 1.5% | 2017-10-18 |
| CVE-2017-11471 EXP | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter. | Patch early | 9.8 critical | 1.5% | 2017-07-20 |
| CVE-2017-11470 EXP | IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter. | Patch early | 9.8 critical | 1.5% | 2017-07-20 |
| CVE-2006-5603 EXP | SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter… | Patch early | 9.8 critical | 1.4% | 2006-10-30 |
| CVE-2026-44225 EXP | Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every p… | Patch early | 9.3 critical | 1.4% | 2026-05-12 |
| CVE-2024-24495 EXP | SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET requ… | Patch early | 9.8 critical | 1.3% | 2024-02-08 |
| CVE-2025-50455 EXP | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulne… | Patch early | 9.1 critical | 1.2% | 2026-07-27 |
| CVE-2024-28595 EXP | SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-adm… | Patch early | 9.8 critical | 1.2% | 2024-03-19 |
| CVE-2024-6516 EXP | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products:… | Patch early | 9.0 critical | 1.1% | 2024-12-05 |
| CVE-2024-48573 EXP | A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via… | Patch early | 9.8 critical | 1% | 2024-10-29 |
| CVE-2024-48849 EXP | Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This is… | Patch early | 9.4 critical | 0.9% | 2025-01-29 |
| CVE-2026-25544 EXP | Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly… | Patch early | 9.8 critical | 0.9% | 2026-02-06 |
| CVE-2022-39952 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 thr… | Patch early | 9.8 critical | 99.8% | 2023-02-16 |
| CVE-2023-37679 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | Patch early | 9.8 critical | 99.4% | 2023-08-03 |
| CVE-2023-34960 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a… | Patch early | 9.8 critical | 99.3% | 2023-08-01 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt