Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 17 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-2591 | A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. | EXPLOITHIGH 7.5EPSS 8.35% | 1 August 2022 |
| CVE-2022-34140 | A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field. | EXPLOIT ×2MEDIUM 5.4EPSS 4.59% | 28 July 2022 |
| CVE-2022-36446 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | EXPLOITCRITICAL 9.8EPSS 96.0% | 25 July 2022 |
| CVE-2022-35899 | This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file. | EXPLOITHIGH 7.8EPSS 0.90% | 21 July 2022 |
| CVE-2022-34048 | Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. | EXPLOITMEDIUM 6.1EPSS 6.60% | 20 July 2022 |
| CVE-2022-34047 | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd]. | EXPLOITHIGH 7.5EPSS 21.8% | 20 July 2022 |
| CVE-2022-34046 | An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);]. | EXPLOITHIGH 7.5EPSS 20.8% | 20 July 2022 |
| CVE-2022-24082 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying… | EXPLOITCRITICAL 9.8EPSS 12.3% | 19 July 2022 |
| CVE-2022-1565 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. | EXPLOIT ✓HIGH 7.2EPSS 15.4% | 18 July 2022 |
| CVE-2021-36711 | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. | EXPLOITCRITICAL 9.8EPSS 16.1% | 16 July 2022 |
| CVE-2022-31161 | Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. | EXPLOITCRITICAL 9.8EPSS 28.4% | 15 July 2022 |
| CVE-2022-29593 | relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request. | EXPLOITMEDIUM 5.9EPSS 14.0% | 14 July 2022 |
| CVE-2022-35411 | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. | EXPLOITCRITICAL 9.8EPSS 46.1% | 8 July 2022 |
| CVE-2022-33098 | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. | EXPLOITMEDIUM 6.1EPSS 52.7% | 7 July 2022 |
| CVE-2022-31854 | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. | EXPLOITHIGH 7.2EPSS 32.8% | 7 July 2022 |
| CVE-2022-31126 | A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. | EXPLOIT ✓CRITICAL 9.8EPSS 52.1% | 6 July 2022 |
| CVE-2022-31125 | A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. | EXPLOIT ✓CRITICAL 9.8EPSS 20.6% | 6 July 2022 |
| CVE-2021-43116 | An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login. | EXPLOITHIGH 8.8EPSS 7.56% | 5 July 2022 |
| CVE-2022-31886 | Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). | EXPLOITMEDIUM 6.5EPSS 2.18% | 28 June 2022 |
| CVE-2022-31885 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | EXPLOITCRITICAL 9.8EPSS 32.8% | 28 June 2022 |
| CVE-2022-31056 | In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. | EXPLOITCRITICAL 9.8EPSS 8.95% | 28 June 2022 |
| CVE-2022-31101 | In affected versions an authenticated customer can perform SQL injection. | EXPLOITHIGH 8.8EPSS 23.5% | 27 June 2022 |
| CVE-2022-28171 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. | EXPLOITCRITICAL 9.8EPSS 51.6% | 27 June 2022 |
| CVE-2013-1916 | This backdoor can be called (executed) even if the photo has not been yet approved. | EXPLOIT ✓HIGH 8.8EPSS 12.8% | 24 June 2022 |
| CVE-2013-1891 | In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. | EXPLOIT ✓MEDIUM 6.5EPSS 6.58% | 24 June 2022 |
| CVE-2022-29301 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 23 June 2022 |
| CVE-2022-29299 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 23 June 2022 |
| CVE-2022-31062 | ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used. | EXPLOITMEDIUM 5.3EPSS 5.91% | 20 June 2022 |
| CVE-2022-24562 | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and… | EXPLOITCRITICAL 9.8EPSS 54.5% | 16 June 2022 |
| CVE-2022-32272 | OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation. | EXPLOITCRITICAL 9.8EPSS 9.55% | 9 June 2022 |
| CVE-2022-30075 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation. | EXPLOITHIGH 8.8EPSS 33.8% | 9 June 2022 |
| CVE-2022-31325 | There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. | EXPLOITHIGH 7.2EPSS 5.22% | 8 June 2022 |
| CVE-2022-31470 | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a… | EXPLOITMEDIUM 6.1EPSS 52.7% | 7 June 2022 |
| CVE-2021-37589 | Virtua Cobranca before 12R allows SQL Injection on the login page. | EXPLOITHIGH 7.5EPSS 32.7% | 7 June 2022 |
| CVE-2022-29296 | A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | EXPLOITMEDIUM 6.1EPSS 2.49% | 6 June 2022 |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 3 June 2022 |
| CVE-2022-1103 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | EXPLOITHIGH 8.8EPSS 15.6% | 16 May 2022 |
| CVE-2022-30781 | Gitea before 1.16.7 does not escape git fetch remote. | EXPLOIT ✓HIGH 7.5EPSS 87.9% | 16 May 2022 |
| CVE-2022-29303 | SolarView Compact Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 98.0% | 12 May 2022 |
| CVE-2022-29298 | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. | EXPLOITHIGH 7.5EPSS 46.8% | 12 May 2022 |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 12 May 2022 |
| CVE-2022-29885 | The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. | EXPLOITHIGH 7.5EPSS 73.5% | 12 May 2022 |
| CVE-2022-29727 | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. | EXPLOITMEDIUM 5.4EPSS 2.39% | 11 May 2022 |
| CVE-2022-27412 | Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. | EXPLOITCRITICAL 9.8EPSS 4.05% | 9 May 2022 |
| CVE-2022-27308 | A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title. | EXPLOITMEDIUM 5.4EPSS 2.59% | 9 May 2022 |
| CVE-2022-1104 | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | EXPLOITMEDIUM 4.8EPSS 56.4% | 9 May 2022 |
| CVE-2022-1631 | Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. | EXPLOITHIGH 8.8EPSS 8.85% | 9 May 2022 |
| CVE-2022-30286 | pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code. | EXPLOITHIGH 7.5EPSS 13.6% | 9 May 2022 |
| CVE-2022-28080 | Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | EXPLOITHIGH 8.8EPSS 56.9% | 5 May 2022 |
| CVE-2022-28079 | College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | EXPLOITHIGH 8.8EPSS 28.5% | 5 May 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.