SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 14 of 501

CVESummaryPriorityPublished
CVE-2023-28285Microsoft Office Remote Code Execution VulnerabilityEXPLOITHIGH 7.8EPSS 3.01%11 April 2023
CVE-2023-27179GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.EXPLOITHIGH 7.5EPSS 60.8%11 April 2023
CVE-2023-24626socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target…EXPLOITMEDIUM 6.5EPSS 0.54%8 April 2023
CVE-2022-47870A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.EXPLOITMEDIUM 6.1EPSS 2.23%4 April 2023
CVE-2023-1671Sophos Web Appliance Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%4 April 2023
CVE-2023-1826A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0.EXPLOITCRITICAL 9.8EPSS 4.35%4 April 2023
CVE-2022-43939Hitachi Vantara Pentaho BA Server Authorization Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 92.3%3 April 2023
CVE-2022-43769Hitachi Vantara Pentaho BA Server Special Element Injection VulnerabilityKEVEXPLOITHIGH 7.2EPSS 97.7%3 April 2023
CVE-2023-1258Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.EXPLOITMEDIUM 5.3EPSS 3.88%31 March 2023
CVE-2023-26692ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Management System (ZBBS) 4.14k is vulnerable to Cross Site Scripting (XSS).EXPLOITMEDIUM 6.1EPSS 2.69%30 March 2023
CVE-2023-27167Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.EXPLOITMEDIUM 6.5EPSS 7.56%29 March 2023
CVE-2022-47529Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or…EXPLOITMEDIUM 6.7EPSS 1.57%28 March 2023
CVE-2023-24787Rejected reason: DO NOT USE THIS CVE RECORD.EXPLOITUnscoredEPSS —23 March 2023
CVE-2023-24788NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.EXPLOITHIGH 8.8EPSS 3.09%23 March 2023
CVE-2023-27100Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.EXPLOITCRITICAL 9.8EPSS 9.84%22 March 2023
CVE-2023-24709An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.EXPLOITHIGH 7.5EPSS 44.2%21 March 2023
CVE-2023-1545SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.EXPLOITHIGH 7.5EPSS 8.35%21 March 2023
CVE-2023-27253A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.EXPLOITHIGH 8.8EPSS 89.5%17 March 2023
CVE-2023-1389TP-Link Archer AX-21 Command Injection VulnerabilityKEVEXPLOITHIGH 8.8EPSS 100.0%15 March 2023
CVE-2023-28343OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.EXPLOITCRITICAL 9.8EPSS 84.8%14 March 2023
CVE-2023-24892Microsoft Edge (Chromium-based) Webview2 Spoofing VulnerabilityEXPLOITHIGH 8.2EPSS 3.52%14 March 2023
CVE-2023-23408Azure Apache Ambari Spoofing VulnerabilityEXPLOITMEDIUM 4.5EPSS 4.05%14 March 2023
CVE-2023-23399Microsoft Excel Remote Code Execution VulnerabilityEXPLOITHIGH 7.8EPSS 2.53%14 March 2023
CVE-2023-27010Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst.EXPLOITHIGH 7.8EPSS 1.02%13 March 2023
CVE-2023-24657phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.EXPLOITMEDIUM 6.1EPSS 3.90%8 March 2023
CVE-2022-41333An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests.EXPLOITHIGH 7.5EPSS 7.23%7 March 2023
CVE-2023-1211SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.EXPLOITHIGH 7.2EPSS 3.05%7 March 2023
CVE-2023-24217AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.EXPLOITHIGH 8.8EPSS 4.54%6 March 2023
CVE-2023-27290Due to this, an attacker within the network could access the datastores with read/write access.EXPLOITCRITICAL 9.1EPSS 8.57%3 March 2023
CVE-2023-0084The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping.EXPLOITMEDIUM 6.1EPSS 28.6%2 March 2023
CVE-2022-47076An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.EXPLOITHIGH 7.5EPSS 6.18%28 February 2023
CVE-2022-47075An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.EXPLOITHIGH 7.5EPSS 59.4%28 February 2023
CVE-2023-27372SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.EXPLOITCRITICAL 9.8EPSS 99.7%28 February 2023
CVE-2023-23156Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.EXPLOITCRITICAL 9.8EPSS 3.68%27 February 2023
CVE-2023-26609ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.EXPLOITHIGH 7.2EPSS 38.7%27 February 2023
CVE-2023-26602ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.EXPLOITCRITICAL 9.8EPSS 17.4%26 February 2023
CVE-2023-0963A vulnerability was found in SourceCodester Music Gallery Site 1.0.EXPLOITCRITICAL 9.8EPSS 4.67%22 February 2023
CVE-2023-0962A vulnerability was found in SourceCodester Music Gallery Site 1.0.EXPLOITHIGH 8.8EPSS 1.74%22 February 2023
CVE-2023-0961A vulnerability was found in SourceCodester Music Gallery Site 1.0.EXPLOITCRITICAL 9.8EPSS 1.88%22 February 2023
CVE-2023-0943A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0.EXPLOITHIGH 8.8EPSS 2.27%21 February 2023
CVE-2023-0938A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0.EXPLOITCRITICAL 9.8EPSS 1.79%21 February 2023
CVE-2023-0916A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0.EXPLOITHIGH 8.8EPSS 3.07%19 February 2023
CVE-2023-0915A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0.EXPLOITHIGH 8.8EPSS 1.73%19 February 2023
CVE-2023-0913A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0.EXPLOITHIGH 8.8EPSS 1.64%18 February 2023
CVE-2023-0912A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0.EXPLOITHIGH 8.8EPSS 1.64%18 February 2023
CVE-2023-0905A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0.EXPLOITHIGH 7.5EPSS 3.19%18 February 2023
CVE-2023-0904A vulnerability was found in SourceCodester Employee Task Management System 1.0.EXPLOITHIGH 8.8EPSS 1.68%18 February 2023
CVE-2023-0902A vulnerability was found in SourceCodester Simple Food Ordering System 1.0.EXPLOIT ×2MEDIUM 5.4EPSS 2.69%18 February 2023
CVE-2023-22232Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.EXPLOIT ×2MEDIUM 5.3EPSS 81.9%17 February 2023
CVE-2022-47986IBM Aspera Faspex Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%17 February 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.