Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 16 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-23513 | In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. | EXPLOITMEDIUM 5.3EPSS 40.2% | 23 December 2022 |
| CVE-2022-4407 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9. | EXPLOITMEDIUM 6.1EPSS 4.38% | 11 December 2022 |
| CVE-2022-25630 | An authenticated user can embed malicious content with XSS into the admin group policy page. | EXPLOITMEDIUM 5.4EPSS 1.53% | 9 December 2022 |
| CVE-2022-46770 | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through… | EXPLOITHIGH 7.5EPSS 21.7% | 7 December 2022 |
| CVE-2020-6627 | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a… | EXPLOITCRITICAL 9.8EPSS 12.8% | 6 December 2022 |
| CVE-2022-46169 | Cacti Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.8% | 5 December 2022 |
| CVE-2022-41413 | perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function. | EXPLOITMEDIUM 4.3EPSS 2.05% | 30 November 2022 |
| CVE-2022-37197 | IOBit IOTransfer V4 is vulnerable to Unquoted Service Path. | EXPLOITHIGH 7.8EPSS 1.08% | 18 November 2022 |
| CVE-2022-37109 | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. | EXPLOITCRITICAL 9.8EPSS 49.5% | 14 November 2022 |
| CVE-2022-3766 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | EXPLOITMEDIUM 6.1EPSS 6.13% | 31 October 2022 |
| CVE-2022-38580 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | EXPLOITCRITICAL 9.8EPSS 11.5% | 25 October 2022 |
| CVE-2022-41358 | A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. | EXPLOITMEDIUM 5.4EPSS 3.12% | 20 October 2022 |
| CVE-2022-41544 | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. | EXPLOIT ✓CRITICAL 9.8EPSS 10.4% | 18 October 2022 |
| CVE-2022-40684 | Fortinet Multiple Products Authentication Bypass Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0% | 18 October 2022 |
| CVE-2022-3552 | Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1. | EXPLOIT ✓HIGH 7.2EPSS 44.0% | 17 October 2022 |
| CVE-2022-2884 | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint | EXPLOIT ✓CRITICAL 9.9EPSS 75.7% | 17 October 2022 |
| CVE-2022-42889 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. | EXPLOITCRITICAL 9.8EPSS 99.9% | 13 October 2022 |
| CVE-2022-39291 | Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. | EXPLOIT ✓MEDIUM 5.4EPSS 5.62% | 7 October 2022 |
| CVE-2022-39290 | In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. | EXPLOIT ✓MEDIUM 6.5EPSS 5.97% | 7 October 2022 |
| CVE-2022-39285 | ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. | EXPLOIT ✓MEDIUM 5.4EPSS 4.05% | 7 October 2022 |
| CVE-2022-36551 | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. | EXPLOITMEDIUM 6.5EPSS 5.56% | 3 October 2022 |
| CVE-2022-35155 | Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter. | EXPLOIT ✓MEDIUM 6.1EPSS 2.17% | 30 September 2022 |
| CVE-2019-5797 | Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | EXPLOIT ✓HIGH 7.5EPSS 2.88% | 29 September 2022 |
| CVE-2022-2070 | In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. | EXPLOITCRITICAL 9.8EPSS 4.77% | 23 September 2022 |
| CVE-2022-2025 | an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. | EXPLOITCRITICAL 9.8EPSS 4.45% | 23 September 2022 |
| CVE-2022-35914 | Teclib GLPI Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 19 September 2022 |
| CVE-2022-3142 | The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. | EXPLOIT ✓HIGH 8.8EPSS 14.6% | 19 September 2022 |
| CVE-2022-3141 | The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. | EXPLOIT ✓HIGH 8.8EPSS 5.08% | 19 September 2022 |
| CVE-2022-2840 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections | EXPLOIT ✓CRITICAL 9.8EPSS 12.9% | 19 September 2022 |
| CVE-2022-37661 | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. | EXPLOITCRITICAL 9.8EPSS 33.9% | 14 September 2022 |
| CVE-2022-35513 | The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. | EXPLOITHIGH 7.5EPSS 5.90% | 7 September 2022 |
| CVE-2022-2941 | The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. | EXPLOIT ✓MEDIUM 4.8EPSS 7.25% | 6 September 2022 |
| CVE-2022-31814 | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. | EXPLOITCRITICAL 9.8EPSS 91.9% | 5 September 2022 |
| CVE-2022-34668 | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and… | EXPLOITCRITICAL 9.8EPSS 10.9% | 29 August 2022 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | KEVEXPLOITHIGH 8.8EPSS 99.2% | 25 August 2022 |
| CVE-2022-36633 | Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. | EXPLOITHIGH 8.8EPSS 50.3% | 24 August 2022 |
| CVE-2022-28598 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. | EXPLOITMEDIUM 6.1EPSS 4.09% | 22 August 2022 |
| CVE-2022-35583 | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. | EXPLOITCRITICAL 9.8EPSS 15.4% | 22 August 2022 |
| CVE-2022-2552 | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. | EXPLOIT ✓MEDIUM 5.3EPSS 11.3% | 22 August 2022 |
| CVE-2022-2551 | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full… | EXPLOITHIGH 7.5EPSS 16.7% | 22 August 2022 |
| CVE-2022-2841 | A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. | EXPLOITLOW 2.7EPSS 4.89% | 22 August 2022 |
| CVE-2022-37061 | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. | EXPLOITCRITICAL 9.8EPSS 99.6% | 18 August 2022 |
| CVE-2022-2846 | The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. | EXPLOITMEDIUM 4.3EPSS 2.65% | 16 August 2022 |
| CVE-2021-42751 | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node. | EXPLOITMEDIUM 4.8EPSS 3.05% | 12 August 2022 |
| CVE-2021-42750 | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node. | EXPLOITMEDIUM 4.8EPSS 3.05% | 12 August 2022 |
| CVE-2022-32429 | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to… | EXPLOITCRITICAL 9.8EPSS 75.6% | 10 August 2022 |
| CVE-2022-36267 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. | EXPLOITCRITICAL 9.8EPSS 54.5% | 8 August 2022 |
| CVE-2022-2651 | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | EXPLOIT ✓CRITICAL 9.8EPSS 15.4% | 4 August 2022 |
| CVE-2022-35919 | Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. | EXPLOITLOW 2.7EPSS 52.3% | 1 August 2022 |
| CVE-2022-31188 | Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. | EXPLOITCRITICAL 9.8EPSS 48.6% | 1 August 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.