Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 12 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-2796 | The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id. | EXPLOITMEDIUM 5.3EPSS 42.7% | 10 July 2023 |
| CVE-2023-37269 | Prior to version 1.2.3, SVG uploads were not sanitized, which could have allowed a stored cross-site scripting (XSS) attack. | EXPLOITMEDIUM 4.8EPSS 2.70% | 7 July 2023 |
| CVE-2023-3460 | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. | EXPLOITCRITICAL 9.8EPSS 72.3% | 4 July 2023 |
| CVE-2023-34834 | A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint. | EXPLOITMEDIUM 5.3EPSS 3.96% | 29 June 2023 |
| CVE-2023-33592 | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | EXPLOITCRITICAL 9.8EPSS 3.83% | 28 June 2023 |
| CVE-2023-2068 | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. | EXPLOITCRITICAL 9.8EPSS 39.6% | 27 June 2023 |
| CVE-2023-33580 | Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page. | EXPLOIT ✓MEDIUM 4.8EPSS 3.66% | 26 June 2023 |
| CVE-2023-36348 | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter. | EXPLOITHIGH 8.8EPSS 6.37% | 23 June 2023 |
| CVE-2023-36346 | POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php. | EXPLOITMEDIUM 6.1EPSS 5.25% | 23 June 2023 |
| CVE-2023-30258 | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request. | EXPLOITCRITICAL 9.8EPSS 94.3% | 23 June 2023 |
| CVE-2023-36355 | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. | EXPLOITCRITICAL 9.9EPSS 31.7% | 22 June 2023 |
| CVE-2023-34927 | Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. | EXPLOIT ×3MEDIUM 6.5EPSS 3.07% | 22 June 2023 |
| CVE-2023-33584 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. | EXPLOIT ✓CRITICAL 9.8EPSS 14.2% | 21 June 2023 |
| CVE-2020-20969 | File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. | EXPLOITHIGH 7.2EPSS 6.21% | 20 June 2023 |
| CVE-2023-3320 | The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. | EXPLOITHIGH 8.8EPSS 2.30% | 20 June 2023 |
| CVE-2023-2779 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege… | EXPLOIT ✓MEDIUM 6.1EPSS 5.99% | 19 June 2023 |
| CVE-2023-25187 | This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform troubleshooting activities. | EXPLOITHIGH 7.0EPSS 0.96% | 16 June 2023 |
| CVE-2023-33243 | RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. | EXPLOITHIGH 8.1EPSS 4.42% | 15 June 2023 |
| CVE-2023-33145 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | EXPLOITMEDIUM 6.5EPSS 8.62% | 14 June 2023 |
| CVE-2023-33137 | Microsoft Excel Remote Code Execution Vulnerability | EXPLOITHIGH 7.8EPSS 2.75% | 14 June 2023 |
| CVE-2023-33131 | Microsoft Outlook Remote Code Execution Vulnerability | EXPLOITHIGH 8.8EPSS 5.72% | 14 June 2023 |
| CVE-2023-30198 | Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php. | EXPLOITHIGH 7.5EPSS 5.52% | 12 June 2023 |
| CVE-2023-34581 | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | EXPLOIT ✓CRITICAL 9.8EPSS 3.28% | 12 June 2023 |
| CVE-2023-3187 | A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. | EXPLOITMEDIUM 5.4EPSS 2.56% | 9 June 2023 |
| CVE-2023-3184 | A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. | EXPLOIT ✓MEDIUM 4.8EPSS 2.26% | 9 June 2023 |
| CVE-2023-32751 | Pydio Cells through 4.1.2 allows XSS. | EXPLOITMEDIUM 5.4EPSS 2.94% | 8 June 2023 |
| CVE-2023-32750 | Pydio Cells through 4.1.2 allows SSRF. | EXPLOITMEDIUM 6.5EPSS 3.85% | 8 June 2023 |
| CVE-2023-32749 | Pydio Cells allows users by default to create so-called external users in order to share files with them. | EXPLOITHIGH 8.8EPSS 14.1% | 8 June 2023 |
| CVE-2023-34096 | In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. | EXPLOITHIGH 8.8EPSS 62.7% | 8 June 2023 |
| CVE-2023-32707 | In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of… | EXPLOITHIGH 8.8EPSS 79.0% | 1 June 2023 |
| CVE-2023-33177 | A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the… | EXPLOITHIGH 8.8EPSS 7.04% | 30 May 2023 |
| CVE-2023-23956 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | EXPLOITMEDIUM 5.4EPSS 3.08% | 30 May 2023 |
| CVE-2022-24632 | It is directory traversal during file download via the BrowseFiles.php view parameter. | EXPLOITMEDIUM 5.3EPSS 27.4% | 29 May 2023 |
| CVE-2022-24630 | BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed. | EXPLOITHIGH 7.2EPSS 23.9% | 29 May 2023 |
| CVE-2022-24629 | Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. | EXPLOITCRITICAL 9.8EPSS 37.2% | 29 May 2023 |
| CVE-2022-24627 | It is an unauthenticated SQL injection in the p parameter of the process_login.php login form. | EXPLOITCRITICAL 9.8EPSS 26.4% | 29 May 2023 |
| CVE-2021-27825 | A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | EXPLOITHIGH 7.5EPSS 7.80% | 29 May 2023 |
| CVE-2023-31874 | Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process'). | EXPLOITHIGH 8.8EPSS 4.90% | 29 May 2023 |
| CVE-2023-30350 | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | EXPLOITHIGH 8.8EPSS 5.34% | 29 May 2023 |
| CVE-2023-31873 | Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process'). | EXPLOITHIGH 7.8EPSS 1.35% | 28 May 2023 |
| CVE-2023-33440 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | EXPLOIT ✓HIGH 7.2EPSS 14.5% | 26 May 2023 |
| CVE-2023-30145 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 46.1% | 26 May 2023 |
| CVE-2022-46945 | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. | EXPLOITMEDIUM 6.5EPSS 4.13% | 26 May 2023 |
| CVE-2023-25439 | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details. | EXPLOITMEDIUM 6.1EPSS 2.25% | 25 May 2023 |
| CVE-2023-33829 | A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field. | EXPLOITMEDIUM 5.4EPSS 7.26% | 24 May 2023 |
| CVE-2023-31748 | Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file. | EXPLOITHIGH 7.8EPSS 0.83% | 24 May 2023 |
| CVE-2023-31747 | Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. | EXPLOITHIGH 7.8EPSS 1.09% | 23 May 2023 |
| CVE-2023-33362 | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | EXPLOITCRITICAL 9.8EPSS 9.06% | 23 May 2023 |
| CVE-2023-25440 | Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field. | EXPLOITMEDIUM 5.4EPSS 2.54% | 23 May 2023 |
| CVE-2023-30868 | Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions. | EXPLOITMEDIUM 6.1EPSS 4.00% | 18 May 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.