Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 11 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-4547 | A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. | EXPLOITMEDIUM 6.1EPSS 61.3% | 26 August 2023 |
| CVE-2023-34723 | An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. | EXPLOITHIGH 7.5EPSS 5.37% | 25 August 2023 |
| CVE-2023-39026 | Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component. | EXPLOITHIGH 7.5EPSS 17.9% | 22 August 2023 |
| CVE-2023-38836 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | EXPLOITHIGH 8.8EPSS 76.0% | 21 August 2023 |
| CVE-2023-4407 | A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. | EXPLOITCRITICAL 9.8EPSS 1.99% | 18 August 2023 |
| CVE-2023-4382 | A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1. | EXPLOITMEDIUM 5.4EPSS 2.39% | 16 August 2023 |
| CVE-2023-39115 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | EXPLOITCRITICAL 9.8EPSS 7.88% | 16 August 2023 |
| CVE-2023-40028 | Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. | EXPLOITMEDIUM 6.5EPSS 68.7% | 15 August 2023 |
| CVE-2022-4953 | This could be used to inject rogue iframes that point to malicious URLs. | EXPLOITMEDIUM 6.1EPSS 3.41% | 14 August 2023 |
| CVE-2023-32560 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. | EXPLOITCRITICAL 9.8EPSS 99.4% | 10 August 2023 |
| CVE-2022-47636 | A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. | EXPLOITHIGH 7.8EPSS 1.28% | 10 August 2023 |
| CVE-2023-36306 | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php… | EXPLOITMEDIUM 6.1EPSS 5.31% | 8 August 2023 |
| CVE-2023-37569 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. | EXPLOITHIGH 8.8EPSS 33.9% | 8 August 2023 |
| CVE-2023-4174 | A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. | EXPLOIT ✓MEDIUM 6.1EPSS 9.14% | 6 August 2023 |
| CVE-2023-4173 | A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. | EXPLOIT ✓MEDIUM 6.1EPSS 5.45% | 6 August 2023 |
| CVE-2023-4168 | A vulnerability was found in Templatecookie Adlisting 2.14.0. | EXPLOITHIGH 7.5EPSS 46.0% | 5 August 2023 |
| CVE-2023-29689 | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. | EXPLOITCRITICAL 9.8EPSS 53.5% | 4 August 2023 |
| CVE-2023-4119 | A vulnerability has been found in Academy LMS 6.0 and classified as problematic. | EXPLOITMEDIUM 6.1EPSS 3.77% | 3 August 2023 |
| CVE-2023-4117 | A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. | EXPLOITMEDIUM 6.1EPSS 3.11% | 3 August 2023 |
| CVE-2023-4116 | A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. | EXPLOITMEDIUM 6.1EPSS 8.42% | 3 August 2023 |
| CVE-2023-4115 | A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. | EXPLOITMEDIUM 6.1EPSS 8.42% | 3 August 2023 |
| CVE-2023-4114 | A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. | EXPLOITMEDIUM 6.1EPSS 8.31% | 3 August 2023 |
| CVE-2023-4113 | A vulnerability was found in PHP Jabbers Service Booking Script 1.0. | EXPLOITMEDIUM 6.1EPSS 8.42% | 3 August 2023 |
| CVE-2023-4112 | A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. | EXPLOITMEDIUM 6.1EPSS 8.42% | 3 August 2023 |
| CVE-2023-33383 | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload. | EXPLOITMEDIUM 5.3EPSS 4.73% | 2 August 2023 |
| CVE-2023-39147 | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file. | EXPLOIT ✓HIGH 7.8EPSS 1.23% | 1 August 2023 |
| CVE-2023-38357 | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions. | EXPLOITMEDIUM 5.3EPSS 5.35% | 1 August 2023 |
| CVE-2023-34634 | Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened. | EXPLOITHIGH 7.8EPSS 7.55% | 1 August 2023 |
| CVE-2023-34635 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. | EXPLOITCRITICAL 9.8EPSS 3.54% | 31 July 2023 |
| CVE-2023-37979 | Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions. | EXPLOITMEDIUM 6.1EPSS 9.71% | 27 July 2023 |
| CVE-2023-38501 | Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. | EXPLOIT ✓MEDIUM 6.1EPSS 9.25% | 25 July 2023 |
| CVE-2023-3897 | Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. | EXPLOITMEDIUM 5.3EPSS 3.06% | 25 July 2023 |
| CVE-2023-3849 | A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3848 | A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3847 | A vulnerability classified as problematic was found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3846 | A vulnerability classified as problematic has been found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3845 | A vulnerability was found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3844 | A vulnerability was found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-3843 | A vulnerability was found in mooSocial mooDating 1.2. | EXPLOITMEDIUM 6.1EPSS 5.96% | 23 July 2023 |
| CVE-2023-2636 | The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber | EXPLOIT ✓HIGH 8.8EPSS 6.94% | 17 July 2023 |
| CVE-2023-36166 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 15 July 2023 |
| CVE-2023-36165 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 15 July 2023 |
| CVE-2023-3643 | A vulnerability was found in Boss Mini 1.4.0 Build 6221. | EXPLOITCRITICAL 9.8EPSS 75.4% | 12 July 2023 |
| CVE-2023-37629 | Online Piggery Management System 1.0 is vulnerable to File Upload. | EXPLOIT ✓CRITICAL 9.8EPSS 23.3% | 12 July 2023 |
| CVE-2023-36266 | An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in… | EXPLOITMEDIUM 5.5EPSS 0.78% | 12 July 2023 |
| CVE-2023-33148 | Microsoft Office Elevation of Privilege Vulnerability | EXPLOITHIGH 7.8EPSS 2.06% | 11 July 2023 |
| CVE-2023-36167 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 11 July 2023 |
| CVE-2023-36164 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 11 July 2023 |
| CVE-2023-36163 | Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL. | EXPLOITMEDIUM 6.1EPSS 4.13% | 11 July 2023 |
| CVE-2023-3219 | The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via… | EXPLOITMEDIUM 5.3EPSS 7.52% | 10 July 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.