Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 13 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-31703 | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter. | EXPLOITCRITICAL 9.0EPSS 4.47% | 17 May 2023 |
| CVE-2023-31702 | SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1. | EXPLOITHIGH 7.2EPSS 4.31% | 17 May 2023 |
| CVE-2023-31699 | ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file. | EXPLOITMEDIUM 4.8EPSS 1.51% | 17 May 2023 |
| CVE-2023-31698 | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. | EXPLOIT ✓MEDIUM 5.4EPSS 2.59% | 17 May 2023 |
| CVE-2023-2745 | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. | EXPLOITMEDIUM 5.4EPSS 79.5% | 17 May 2023 |
| CVE-2023-27823 | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | EXPLOITCRITICAL 9.8EPSS 53.6% | 12 May 2023 |
| CVE-2023-1934 | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. | EXPLOITHIGH 7.5EPSS 8.08% | 12 May 2023 |
| CVE-2022-47880 | An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function. | EXPLOITMEDIUM 5.3EPSS 2.93% | 12 May 2023 |
| CVE-2022-47879 | A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. | EXPLOITHIGH 7.5EPSS 6.30% | 12 May 2023 |
| CVE-2023-29983 | Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel. | EXPLOITMEDIUM 5.4EPSS 5.10% | 12 May 2023 |
| CVE-2023-30330 | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php. | EXPLOITCRITICAL 9.8EPSS 5.88% | 12 May 2023 |
| CVE-2023-29809 | SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request. | EXPLOIT ✓CRITICAL 9.8EPSS 10.5% | 12 May 2023 |
| CVE-2023-30256 | Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file. | EXPLOITMEDIUM 6.1EPSS 9.05% | 11 May 2023 |
| CVE-2023-29336 | Microsoft Win32K Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 40.9% | 9 May 2023 |
| CVE-2023-32235 | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. | EXPLOITHIGH 7.5EPSS 39.1% | 5 May 2023 |
| CVE-2023-25289 | Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request. | EXPLOITHIGH 7.5EPSS 7.69% | 4 May 2023 |
| CVE-2023-25438 | An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files. | EXPLOITHIGH 7.8EPSS 2.09% | 4 May 2023 |
| CVE-2017-11197 | In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option. | EXPLOITHIGH 7.8EPSS 0.98% | 3 May 2023 |
| CVE-2022-47878 | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. | EXPLOITHIGH 8.8EPSS 35.7% | 2 May 2023 |
| CVE-2022-47877 | A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'. | EXPLOITMEDIUM 5.4EPSS 2.63% | 2 May 2023 |
| CVE-2022-47876 | The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts. | EXPLOITHIGH 8.8EPSS 7.05% | 2 May 2023 |
| CVE-2022-47875 | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. | EXPLOITHIGH 8.8EPSS 10.2% | 2 May 2023 |
| CVE-2022-47874 | Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'. | EXPLOITMEDIUM 6.5EPSS 21.1% | 2 May 2023 |
| CVE-2023-29918 | RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module. | EXPLOIT ✓MEDIUM 5.4EPSS 2.17% | 2 May 2023 |
| CVE-2023-27524 | Apache Superset Insecure Default Initialization of Resource Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 97.4% | 24 April 2023 |
| CVE-2023-29849 | Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter. | EXPLOIT ✓HIGH 8.8EPSS 3.16% | 24 April 2023 |
| CVE-2023-29848 | Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function. | EXPLOIT ✓MEDIUM 4.8EPSS 1.93% | 24 April 2023 |
| CVE-2023-2246 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. | EXPLOIT ✓CRITICAL 9.8EPSS 3.62% | 23 April 2023 |
| CVE-2022-4944 | A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. | EXPLOITHIGH 8.8EPSS 2.67% | 22 April 2023 |
| CVE-2023-1998 | The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. | EXPLOITMEDIUM 5.6EPSS 1.38% | 21 April 2023 |
| CVE-2023-27350 | PaperCut MF/NG Improper Access Control Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0% | 20 April 2023 |
| CVE-2021-36520 | A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI. | EXPLOITHIGH 7.5EPSS 2.70% | 16 April 2023 |
| CVE-2021-33990 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. | EXPLOITCRITICAL 9.8EPSS 11.9% | 16 April 2023 |
| CVE-2022-34128 | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. | EXPLOITCRITICAL 9.8EPSS 7.81% | 16 April 2023 |
| CVE-2022-34127 | The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter. | EXPLOITHIGH 7.5EPSS 6.77% | 16 April 2023 |
| CVE-2022-34125 | front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter. | EXPLOITMEDIUM 6.5EPSS 4.61% | 16 April 2023 |
| CVE-2022-30076 | ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. | EXPLOITMEDIUM 5.3EPSS 3.57% | 16 April 2023 |
| CVE-2022-43128 | Rejected reason: DO NOT USE THIS CVE RECORD. | EXPLOITUnscoredEPSS — | 16 April 2023 |
| CVE-2022-40946 | On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request. | EXPLOITHIGH 7.5EPSS 7.52% | 16 April 2023 |
| CVE-2022-38841 | Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. | EXPLOITHIGH 8.8EPSS 10.7% | 16 April 2023 |
| CVE-2022-38840 | cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure. | EXPLOITHIGH 7.5EPSS 9.80% | 16 April 2023 |
| CVE-2022-37255 | TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603. | EXPLOITHIGH 7.5EPSS 4.98% | 16 April 2023 |
| CVE-2022-45030 | A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv). | EXPLOITHIGH 8.8EPSS 2.69% | 15 April 2023 |
| CVE-2022-48178 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI. | EXPLOITMEDIUM 5.4EPSS 1.83% | 15 April 2023 |
| CVE-2022-48177 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). | EXPLOITMEDIUM 5.4EPSS 1.83% | 15 April 2023 |
| CVE-2023-26918 | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. | EXPLOITCRITICAL 9.8EPSS 6.05% | 14 April 2023 |
| CVE-2023-27826 | SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function. | EXPLOITHIGH 8.8EPSS 11.8% | 12 April 2023 |
| CVE-2023-28311 | Microsoft Word Remote Code Execution Vulnerability | EXPLOITHIGH 7.8EPSS 2.72% | 11 April 2023 |
| CVE-2023-28293 | Windows Kernel Elevation of Privilege Vulnerability | EXPLOITHIGH 7.8EPSS 2.87% | 11 April 2023 |
| CVE-2023-28288 | Microsoft SharePoint Server Spoofing Vulnerability | EXPLOITHIGH 8.1EPSS 6.23% | 11 April 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.