SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 16 of 501

CVESummaryPriorityPublished
CVE-2022-23513In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint.EXPLOITMEDIUM 5.3EPSS 40.2%23 December 2022
CVE-2022-4407Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.EXPLOITMEDIUM 6.1EPSS 4.38%11 December 2022
CVE-2022-25630An authenticated user can embed malicious content with XSS into the admin group policy page.EXPLOITMEDIUM 5.4EPSS 1.53%9 December 2022
CVE-2022-46770qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through…EXPLOITHIGH 7.5EPSS 21.7%7 December 2022
CVE-2020-6627The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a…EXPLOITCRITICAL 9.8EPSS 12.8%6 December 2022
CVE-2022-46169Cacti Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.8%5 December 2022
CVE-2022-41413perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.EXPLOITMEDIUM 4.3EPSS 2.05%30 November 2022
CVE-2022-37197IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.EXPLOITHIGH 7.8EPSS 1.08%18 November 2022
CVE-2022-37109patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.EXPLOITCRITICAL 9.8EPSS 49.5%14 November 2022
CVE-2022-3766Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.EXPLOITMEDIUM 6.1EPSS 6.13%31 October 2022
CVE-2022-38580Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).EXPLOITCRITICAL 9.8EPSS 11.5%25 October 2022
CVE-2022-41358A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.EXPLOITMEDIUM 5.4EPSS 3.12%20 October 2022
CVE-2022-41544GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.EXPLOITCRITICAL 9.8EPSS 10.4%18 October 2022
CVE-2022-40684Fortinet Multiple Products Authentication Bypass VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0%18 October 2022
CVE-2022-3552Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.EXPLOITHIGH 7.2EPSS 44.0%17 October 2022
CVE-2022-2884A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpointEXPLOITCRITICAL 9.9EPSS 75.7%17 October 2022
CVE-2022-42889Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.EXPLOITCRITICAL 9.8EPSS 99.9%13 October 2022
CVE-2022-39291Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder.EXPLOITMEDIUM 5.4EPSS 5.62%7 October 2022
CVE-2022-39290In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application.EXPLOITMEDIUM 6.5EPSS 5.97%7 October 2022
CVE-2022-39285ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets.EXPLOITMEDIUM 5.4EPSS 4.05%7 October 2022
CVE-2022-36551A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system.EXPLOITMEDIUM 6.5EPSS 5.56%3 October 2022
CVE-2022-35155Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.EXPLOITMEDIUM 6.1EPSS 2.17%30 September 2022
CVE-2019-5797Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.EXPLOITHIGH 7.5EPSS 2.88%29 September 2022
CVE-2022-2070In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction.EXPLOITCRITICAL 9.8EPSS 4.77%23 September 2022
CVE-2022-2025an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction.EXPLOITCRITICAL 9.8EPSS 4.45%23 September 2022
CVE-2022-35914Teclib GLPI Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%19 September 2022
CVE-2022-3142The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections.EXPLOITHIGH 8.8EPSS 14.6%19 September 2022
CVE-2022-3141The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection.EXPLOITHIGH 8.8EPSS 5.08%19 September 2022
CVE-2022-2840The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injectionsEXPLOITCRITICAL 9.8EPSS 12.9%19 September 2022
CVE-2022-37661SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.EXPLOITCRITICAL 9.8EPSS 33.9%14 September 2022
CVE-2022-35513The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.EXPLOITHIGH 7.5EPSS 5.90%7 September 2022
CVE-2022-2941The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0.EXPLOITMEDIUM 4.8EPSS 7.25%6 September 2022
CVE-2022-31814pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header.EXPLOITCRITICAL 9.8EPSS 91.9%5 September 2022
CVE-2022-34668NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and…EXPLOITCRITICAL 9.8EPSS 10.9%29 August 2022
CVE-2022-36804Atlassian Bitbucket Server and Data Center Command Injection VulnerabilityKEVEXPLOITHIGH 8.8EPSS 99.2%25 August 2022
CVE-2022-36633Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution.EXPLOITHIGH 8.8EPSS 50.3%24 August 2022
CVE-2022-28598Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.EXPLOITMEDIUM 6.1EPSS 4.09%22 August 2022
CVE-2022-35583wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source.EXPLOITCRITICAL 9.8EPSS 15.4%22 August 2022
CVE-2022-2552The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.EXPLOITMEDIUM 5.3EPSS 11.3%22 August 2022
CVE-2022-2551The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full…EXPLOITHIGH 7.5EPSS 16.7%22 August 2022
CVE-2022-2841A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806.EXPLOITLOW 2.7EPSS 4.89%22 August 2022
CVE-2022-37061All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection.EXPLOITCRITICAL 9.8EPSS 99.6%18 August 2022
CVE-2022-2846The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields.EXPLOITMEDIUM 4.3EPSS 2.65%16 August 2022
CVE-2021-42751A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.EXPLOITMEDIUM 4.8EPSS 3.05%12 August 2022
CVE-2021-42750A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.EXPLOITMEDIUM 4.8EPSS 3.05%12 August 2022
CVE-2022-32429An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to…EXPLOITCRITICAL 9.8EPSS 75.6%10 August 2022
CVE-2022-36267In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.EXPLOITCRITICAL 9.8EPSS 54.5%8 August 2022
CVE-2022-2651Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.EXPLOITCRITICAL 9.8EPSS 15.4%4 August 2022
CVE-2022-35919Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process.EXPLOITLOW 2.7EPSS 52.3%1 August 2022
CVE-2022-31188Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability.EXPLOITCRITICAL 9.8EPSS 48.6%1 August 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.