SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 74 of 501

CVESummaryPriorityPublished
CVE-2017-17627Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.EXPLOITCRITICAL 9.8EPSS 2.20%13 December 2017
CVE-2017-17626Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17625Professional Service Script 1.0 has SQL Injection via the service-list city parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17624PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17623Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17622Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.EXPLOITCRITICAL 9.8EPSS 3.62%13 December 2017
CVE-2017-17621Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.EXPLOITCRITICAL 9.8EPSS 3.62%13 December 2017
CVE-2017-17620Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17619Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.EXPLOITCRITICAL 9.8EPSS 3.62%13 December 2017
CVE-2017-17618Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17617Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17616Event Search Script 1.0 has SQL Injection via the /event-list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17615Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.EXPLOITHIGH 8.8EPSS 2.48%13 December 2017
CVE-2017-17614Food Order Script 1.0 has SQL Injection via the /list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17613Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17612Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.EXPLOIT ×2CRITICAL 9.8EPSS 3.66%13 December 2017
CVE-2017-17611Doctor Search Script 1.0 has SQL Injection via the /list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17610E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17609Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17608Child Care Script 1.0 has SQL Injection via the /list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17607CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17606Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17605Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17604Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17603Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17602Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17601Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17600Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17599Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17598Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17597Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17596Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17595Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17594DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17593Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.EXPLOITHIGH 7.5EPSS 6.05%13 December 2017
CVE-2017-17592Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.EXPLOITCRITICAL 9.8EPSS 3.05%13 December 2017
CVE-2017-17591Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.EXPLOITCRITICAL 9.8EPSS 4.37%13 December 2017
CVE-2017-17590FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.EXPLOITCRITICAL 9.8EPSS 3.94%13 December 2017
CVE-2017-17589FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17588FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17587FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17586FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17585FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17584FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17583FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17582FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17581FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17580FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17579FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017
CVE-2017-17578FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.EXPLOITCRITICAL 9.8EPSS 2.98%13 December 2017

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.