Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 15 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-45701 | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. | EXPLOITHIGH 8.8EPSS 42.6% | 17 February 2023 |
| CVE-2022-40032 | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information. | EXPLOIT ✓CRITICAL 9.8EPSS 20.7% | 17 February 2023 |
| CVE-2022-40347 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information. | EXPLOIT ✓CRITICAL 9.8EPSS 5.35% | 17 February 2023 |
| CVE-2023-24078 | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | EXPLOITHIGH 8.8EPSS 53.0% | 17 February 2023 |
| CVE-2023-23752 | Joomla! Improper Access Control Vulnerability | KEVEXPLOIT ✓MEDIUM 5.3EPSS 99.8% | 16 February 2023 |
| CVE-2023-22855 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. | EXPLOITCRITICAL 9.8EPSS 14.8% | 15 February 2023 |
| CVE-2023-22629 | The move-file function has a path traversal vulnerability in the newPath parameter. | EXPLOITHIGH 8.8EPSS 12.3% | 14 February 2023 |
| CVE-2023-0830 | A vulnerability classified as critical has been found in EasyNAS 1.1.0. | EXPLOITMEDIUM 5.3EPSS 20.9% | 14 February 2023 |
| CVE-2022-48110 | CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. | EXPLOITMEDIUM 6.1EPSS 2.10% | 13 February 2023 |
| CVE-2023-0159 | The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary… | EXPLOITHIGH 7.5EPSS 55.5% | 13 February 2023 |
| CVE-2023-23163 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 4.38% | 10 February 2023 |
| CVE-2023-23162 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. | EXPLOIT ✓CRITICAL 9.8EPSS 4.38% | 10 February 2023 |
| CVE-2023-23161 | A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the… | EXPLOIT ✓MEDIUM 6.1EPSS 5.91% | 10 February 2023 |
| CVE-2023-0777 | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | EXPLOITCRITICAL 9.8EPSS 15.2% | 10 February 2023 |
| CVE-2023-23286 | Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the server-log via username field from the login form. | EXPLOITMEDIUM 6.1EPSS 2.63% | 10 February 2023 |
| CVE-2023-0744 | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | EXPLOIT ✓CRITICAL 9.8EPSS 6.37% | 8 February 2023 |
| CVE-2023-23333 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | EXPLOITCRITICAL 9.8EPSS 99.3% | 6 February 2023 |
| CVE-2022-44268 | ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. | EXPLOITMEDIUM 6.5EPSS 89.9% | 6 February 2023 |
| CVE-2022-44267 | ImageMagick 7.1.0-49 is vulnerable to Denial of Service. | EXPLOITMEDIUM 6.5EPSS 76.6% | 6 February 2023 |
| CVE-2023-0669 | Fortra GoAnywhere MFT Remote Code Execution Vulnerability | KEVEXPLOITHIGH 7.2EPSS 100.0% | 6 February 2023 |
| CVE-2022-4681 | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | EXPLOITCRITICAL 9.8EPSS 3.82% | 6 February 2023 |
| CVE-2018-25080 | A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. | EXPLOITMEDIUM 6.1EPSS 2.66% | 4 February 2023 |
| CVE-2022-46604 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. | EXPLOIT ✓HIGH 8.8EPSS 8.63% | 2 February 2023 |
| CVE-2022-46552 | D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. | EXPLOITHIGH 8.8EPSS 10.5% | 2 February 2023 |
| CVE-2022-45297 | EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. | EXPLOITCRITICAL 9.8EPSS 2.80% | 31 January 2023 |
| CVE-2022-4395 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. | EXPLOITCRITICAL 9.8EPSS 17.6% | 30 January 2023 |
| CVE-2023-0527 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. | EXPLOIT ✓MEDIUM 6.1EPSS 6.12% | 27 January 2023 |
| CVE-2023-0493 | Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. | EXPLOIT ✓HIGH 8.8EPSS 7.90% | 26 January 2023 |
| CVE-2023-0455 | Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. | EXPLOITHIGH 8.8EPSS 5.75% | 26 January 2023 |
| CVE-2022-4510 | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. | EXPLOITHIGH 7.8EPSS 22.0% | 26 January 2023 |
| CVE-2022-45639 | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. | EXPLOITHIGH 7.8EPSS 4.66% | 24 January 2023 |
| CVE-2023-23488 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | EXPLOIT ✓CRITICAL 9.8EPSS 92.5% | 20 January 2023 |
| CVE-2022-41441 | Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters. | EXPLOITMEDIUM 6.1EPSS 5.19% | 20 January 2023 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. | EXPLOITHIGH 7.8EPSS 55.4% | 18 January 2023 |
| CVE-2023-0214 | A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any… | EXPLOITMEDIUM 6.1EPSS 1.89% | 18 January 2023 |
| CVE-2022-40319 | The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. | EXPLOITHIGH 7.5EPSS 7.20% | 17 January 2023 |
| CVE-2022-39195 | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. | EXPLOITMEDIUM 6.1EPSS 6.31% | 17 January 2023 |
| CVE-2023-0315 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | EXPLOITHIGH 8.8EPSS 97.7% | 16 January 2023 |
| CVE-2023-0297 | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | EXPLOIT ✓CRITICAL 9.8EPSS 95.9% | 14 January 2023 |
| CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | EXPLOITHIGH 7.1EPSS 5.33% | 10 January 2023 |
| CVE-2022-44149 | The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. | EXPLOITHIGH 8.8EPSS 64.4% | 6 January 2023 |
| CVE-2022-44877 | CWP Control Web Panel OS Command Injection Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0% | 5 January 2023 |
| CVE-2022-4297 | The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection | EXPLOITCRITICAL 9.8EPSS 3.60% | 2 January 2023 |
| CVE-2022-48197 | Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. | EXPLOIT ✓MEDIUM 6.1EPSS 6.61% | 2 January 2023 |
| CVE-2022-48194 | TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate. | EXPLOITHIGH 8.8EPSS 33.5% | 30 December 2022 |
| CVE-2022-30519 | XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field. | EXPLOITMEDIUM 6.1EPSS 2.53% | 29 December 2022 |
| CVE-2022-36664 | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | EXPLOITMEDIUM 6.1EPSS 3.77% | 26 December 2022 |
| CVE-2022-37706 | enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring. | EXPLOITHIGH 7.8EPSS 5.53% | 25 December 2022 |
| CVE-2022-42953 | Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. | EXPLOITHIGH 7.5EPSS 4.83% | 25 December 2022 |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. | EXPLOITHIGH 7.5EPSS 46.0% | 23 December 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.