SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 11 of 501

CVESummaryPriorityPublished
CVE-2023-4547A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3.EXPLOITMEDIUM 6.1EPSS 61.3%26 August 2023
CVE-2023-34723An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.EXPLOITHIGH 7.5EPSS 5.37%25 August 2023
CVE-2023-39026Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.EXPLOITHIGH 7.5EPSS 17.9%22 August 2023
CVE-2023-38836File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.EXPLOITHIGH 8.8EPSS 76.0%21 August 2023
CVE-2023-4407A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4.EXPLOITCRITICAL 9.8EPSS 1.99%18 August 2023
CVE-2023-4382A vulnerability, which was classified as problematic, has been found in tdevs Hyip Rio 2.1.EXPLOITMEDIUM 5.4EPSS 2.39%16 August 2023
CVE-2023-39115install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.EXPLOITCRITICAL 9.8EPSS 7.88%16 August 2023
CVE-2023-40028Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks.EXPLOITMEDIUM 6.5EPSS 68.7%15 August 2023
CVE-2022-4953This could be used to inject rogue iframes that point to malicious URLs.EXPLOITMEDIUM 6.1EPSS 3.41%14 August 2023
CVE-2023-32560An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.EXPLOITCRITICAL 9.8EPSS 99.4%10 August 2023
CVE-2022-47636A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739.EXPLOITHIGH 7.8EPSS 1.28%10 August 2023
CVE-2023-36306A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php…EXPLOITMEDIUM 6.1EPSS 5.31%8 August 2023
CVE-2023-37569This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component.EXPLOITHIGH 8.8EPSS 33.9%8 August 2023
CVE-2023-4174A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic.EXPLOITMEDIUM 6.1EPSS 9.14%6 August 2023
CVE-2023-4173A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6.EXPLOITMEDIUM 6.1EPSS 5.45%6 August 2023
CVE-2023-4168A vulnerability was found in Templatecookie Adlisting 2.14.0.EXPLOITHIGH 7.5EPSS 46.0%5 August 2023
CVE-2023-29689PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.EXPLOITCRITICAL 9.8EPSS 53.5%4 August 2023
CVE-2023-4119A vulnerability has been found in Academy LMS 6.0 and classified as problematic.EXPLOITMEDIUM 6.1EPSS 3.77%3 August 2023
CVE-2023-4117A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0.EXPLOITMEDIUM 6.1EPSS 3.11%3 August 2023
CVE-2023-4116A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0.EXPLOITMEDIUM 6.1EPSS 8.42%3 August 2023
CVE-2023-4115A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0.EXPLOITMEDIUM 6.1EPSS 8.42%3 August 2023
CVE-2023-4114A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0.EXPLOITMEDIUM 6.1EPSS 8.31%3 August 2023
CVE-2023-4113A vulnerability was found in PHP Jabbers Service Booking Script 1.0.EXPLOITMEDIUM 6.1EPSS 8.42%3 August 2023
CVE-2023-4112A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0.EXPLOITMEDIUM 6.1EPSS 8.42%3 August 2023
CVE-2023-33383Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.EXPLOITMEDIUM 5.3EPSS 4.73%2 August 2023
CVE-2023-39147An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.EXPLOITHIGH 7.8EPSS 1.23%1 August 2023
CVE-2023-38357Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.EXPLOITMEDIUM 5.3EPSS 5.35%1 August 2023
CVE-2023-34634Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.EXPLOITHIGH 7.8EPSS 7.55%1 August 2023
CVE-2023-34635Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection.EXPLOITCRITICAL 9.8EPSS 3.54%31 July 2023
CVE-2023-37979Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.EXPLOITMEDIUM 6.1EPSS 9.71%27 July 2023
CVE-2023-38501Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`.EXPLOITMEDIUM 6.1EPSS 9.25%25 July 2023
CVE-2023-3897Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message.EXPLOITMEDIUM 5.3EPSS 3.06%25 July 2023
CVE-2023-3849A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3848A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3847A vulnerability classified as problematic was found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3846A vulnerability classified as problematic has been found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3845A vulnerability was found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3844A vulnerability was found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-3843A vulnerability was found in mooSocial mooDating 1.2.EXPLOITMEDIUM 6.1EPSS 5.96%23 July 2023
CVE-2023-2636The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriberEXPLOITHIGH 8.8EPSS 6.94%17 July 2023
CVE-2023-36166Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —15 July 2023
CVE-2023-36165Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —15 July 2023
CVE-2023-3643A vulnerability was found in Boss Mini 1.4.0 Build 6221.EXPLOITCRITICAL 9.8EPSS 75.4%12 July 2023
CVE-2023-37629Online Piggery Management System 1.0 is vulnerable to File Upload.EXPLOITCRITICAL 9.8EPSS 23.3%12 July 2023
CVE-2023-36266An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in…EXPLOITMEDIUM 5.5EPSS 0.78%12 July 2023
CVE-2023-33148Microsoft Office Elevation of Privilege VulnerabilityEXPLOITHIGH 7.8EPSS 2.06%11 July 2023
CVE-2023-36167Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —11 July 2023
CVE-2023-36164Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —11 July 2023
CVE-2023-36163Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.EXPLOITMEDIUM 6.1EPSS 4.13%11 July 2023
CVE-2023-3219The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via…EXPLOITMEDIUM 5.3EPSS 7.52%10 July 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.