SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 13 of 501

CVESummaryPriorityPublished
CVE-2023-31703Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.EXPLOITCRITICAL 9.0EPSS 4.47%17 May 2023
CVE-2023-31702SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.EXPLOITHIGH 7.2EPSS 4.31%17 May 2023
CVE-2023-31699ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.EXPLOITMEDIUM 4.8EPSS 1.51%17 May 2023
CVE-2023-31698Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.EXPLOITMEDIUM 5.4EPSS 2.59%17 May 2023
CVE-2023-2745WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter.EXPLOITMEDIUM 5.4EPSS 79.5%17 May 2023
CVE-2023-27823An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.EXPLOITCRITICAL 9.8EPSS 53.6%12 May 2023
CVE-2023-1934The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability.EXPLOITHIGH 7.5EPSS 8.08%12 May 2023
CVE-2022-47880An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.EXPLOITMEDIUM 5.3EPSS 2.93%12 May 2023
CVE-2022-47879A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods.EXPLOITHIGH 7.5EPSS 6.30%12 May 2023
CVE-2023-29983Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.EXPLOITMEDIUM 5.4EPSS 5.10%12 May 2023
CVE-2023-30330SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.EXPLOITCRITICAL 9.8EPSS 5.88%12 May 2023
CVE-2023-29809SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.EXPLOITCRITICAL 9.8EPSS 10.5%12 May 2023
CVE-2023-30256Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.EXPLOITMEDIUM 6.1EPSS 9.05%11 May 2023
CVE-2023-29336Microsoft Win32K Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 40.9%9 May 2023
CVE-2023-32235Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal.EXPLOITHIGH 7.5EPSS 39.1%5 May 2023
CVE-2023-25289Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.EXPLOITHIGH 7.5EPSS 7.69%4 May 2023
CVE-2023-25438An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.EXPLOITHIGH 7.8EPSS 2.09%4 May 2023
CVE-2017-11197In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.EXPLOITHIGH 7.8EPSS 0.98%3 May 2023
CVE-2022-47878Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory.EXPLOITHIGH 8.8EPSS 35.7%2 May 2023
CVE-2022-47877A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.EXPLOITMEDIUM 5.4EPSS 2.63%2 May 2023
CVE-2022-47876The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.EXPLOITHIGH 8.8EPSS 7.05%2 May 2023
CVE-2022-47875A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.EXPLOITHIGH 8.8EPSS 10.2%2 May 2023
CVE-2022-47874Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.EXPLOITMEDIUM 6.5EPSS 21.1%2 May 2023
CVE-2023-29918RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.EXPLOITMEDIUM 5.4EPSS 2.17%2 May 2023
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 97.4%24 April 2023
CVE-2023-29849Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.EXPLOITHIGH 8.8EPSS 3.16%24 April 2023
CVE-2023-29848Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function.EXPLOITMEDIUM 4.8EPSS 1.93%24 April 2023
CVE-2023-2246A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical.EXPLOITCRITICAL 9.8EPSS 3.62%23 April 2023
CVE-2022-4944A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49.EXPLOITHIGH 8.8EPSS 2.67%22 April 2023
CVE-2023-1998The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp.EXPLOITMEDIUM 5.6EPSS 1.38%21 April 2023
CVE-2023-27350PaperCut MF/NG Improper Access Control VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0%20 April 2023
CVE-2021-36520A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.EXPLOITHIGH 7.5EPSS 2.70%16 April 2023
CVE-2021-33990Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.EXPLOITCRITICAL 9.8EPSS 11.9%16 April 2023
CVE-2022-34128The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.EXPLOITCRITICAL 9.8EPSS 7.81%16 April 2023
CVE-2022-34127The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.EXPLOITHIGH 7.5EPSS 6.77%16 April 2023
CVE-2022-34125front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.EXPLOITMEDIUM 6.5EPSS 4.61%16 April 2023
CVE-2022-30076ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000.EXPLOITMEDIUM 5.3EPSS 3.57%16 April 2023
CVE-2022-43128Rejected reason: DO NOT USE THIS CVE RECORD.EXPLOITUnscoredEPSS —16 April 2023
CVE-2022-40946On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.EXPLOITHIGH 7.5EPSS 7.52%16 April 2023
CVE-2022-38841Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.EXPLOITHIGH 8.8EPSS 10.7%16 April 2023
CVE-2022-38840cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.EXPLOITHIGH 7.5EPSS 9.80%16 April 2023
CVE-2022-37255TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.EXPLOITHIGH 7.5EPSS 4.98%16 April 2023
CVE-2022-45030A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).EXPLOITHIGH 8.8EPSS 2.69%15 April 2023
CVE-2022-48178X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.EXPLOITMEDIUM 5.4EPSS 1.83%15 April 2023
CVE-2022-48177X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter).EXPLOITMEDIUM 5.4EPSS 1.83%15 April 2023
CVE-2023-26918Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem.EXPLOITCRITICAL 9.8EPSS 6.05%14 April 2023
CVE-2023-27826SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.EXPLOITHIGH 8.8EPSS 11.8%12 April 2023
CVE-2023-28311Microsoft Word Remote Code Execution VulnerabilityEXPLOITHIGH 7.8EPSS 2.72%11 April 2023
CVE-2023-28293Windows Kernel Elevation of Privilege VulnerabilityEXPLOITHIGH 7.8EPSS 2.87%11 April 2023
CVE-2023-28288Microsoft SharePoint Server Spoofing VulnerabilityEXPLOITHIGH 8.1EPSS 6.23%11 April 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.