SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 17 of 501

CVESummaryPriorityPublished
CVE-2022-2591A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0.EXPLOITHIGH 7.5EPSS 8.35%1 August 2022
CVE-2022-34140A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.EXPLOIT ×2MEDIUM 5.4EPSS 4.59%28 July 2022
CVE-2022-36446software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.EXPLOITCRITICAL 9.8EPSS 96.0%25 July 2022
CVE-2022-35899This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.EXPLOITHIGH 7.8EPSS 0.90%21 July 2022
CVE-2022-34048Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.EXPLOITMEDIUM 6.1EPSS 6.60%20 July 2022
CVE-2022-34047An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].EXPLOITHIGH 7.5EPSS 21.8%20 July 2022
CVE-2022-34046An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].EXPLOITHIGH 7.5EPSS 20.8%20 July 2022
CVE-2022-24082If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying…EXPLOITCRITICAL 9.8EPSS 12.3%19 July 2022
CVE-2022-1565The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7.EXPLOITHIGH 7.2EPSS 15.4%18 July 2022
CVE-2021-36711WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.EXPLOITCRITICAL 9.8EPSS 16.1%16 July 2022
CVE-2022-31161Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file.EXPLOITCRITICAL 9.8EPSS 28.4%15 July 2022
CVE-2022-29593relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.EXPLOITMEDIUM 5.9EPSS 14.0%14 July 2022
CVE-2022-35411rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.EXPLOITCRITICAL 9.8EPSS 46.1%8 July 2022
CVE-2022-33098Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.EXPLOITMEDIUM 6.1EPSS 52.7%7 July 2022
CVE-2022-31854Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.EXPLOITHIGH 7.2EPSS 32.8%7 July 2022
CVE-2022-31126A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file.EXPLOITCRITICAL 9.8EPSS 52.1%6 July 2022
CVE-2022-31125A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request.EXPLOITCRITICAL 9.8EPSS 20.6%6 July 2022
CVE-2021-43116An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.EXPLOITHIGH 8.8EPSS 7.56%5 July 2022
CVE-2022-31886Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF).EXPLOITMEDIUM 6.5EPSS 2.18%28 June 2022
CVE-2022-31885Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.EXPLOITCRITICAL 9.8EPSS 32.8%28 June 2022
CVE-2022-31056In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields.EXPLOITCRITICAL 9.8EPSS 8.95%28 June 2022
CVE-2022-31101In affected versions an authenticated customer can perform SQL injection.EXPLOITHIGH 8.8EPSS 23.5%27 June 2022
CVE-2022-28171The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.EXPLOITCRITICAL 9.8EPSS 51.6%27 June 2022
CVE-2013-1916This backdoor can be called (executed) even if the photo has not been yet approved.EXPLOITHIGH 8.8EPSS 12.8%24 June 2022
CVE-2013-1891In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.EXPLOITMEDIUM 6.5EPSS 6.58%24 June 2022
CVE-2022-29301Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —23 June 2022
CVE-2022-29299Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —23 June 2022
CVE-2022-31062### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.EXPLOITMEDIUM 5.3EPSS 5.91%20 June 2022
CVE-2022-24562In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and…EXPLOITCRITICAL 9.8EPSS 54.5%16 June 2022
CVE-2022-32272OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.EXPLOITCRITICAL 9.8EPSS 9.55%9 June 2022
CVE-2022-30075In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.EXPLOITHIGH 8.8EPSS 33.8%9 June 2022
CVE-2022-31325There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.EXPLOITHIGH 7.2EPSS 5.22%8 June 2022
CVE-2022-31470An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a…EXPLOITMEDIUM 6.1EPSS 52.7%7 June 2022
CVE-2021-37589Virtua Cobranca before 12R allows SQL Injection on the login page.EXPLOITHIGH 7.5EPSS 32.7%7 June 2022
CVE-2022-29296A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.EXPLOITMEDIUM 6.1EPSS 2.49%6 June 2022
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%3 June 2022
CVE-2022-1103The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCEEXPLOITHIGH 8.8EPSS 15.6%16 May 2022
CVE-2022-30781Gitea before 1.16.7 does not escape git fetch remote.EXPLOITHIGH 7.5EPSS 87.9%16 May 2022
CVE-2022-29303SolarView Compact Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 98.0%12 May 2022
CVE-2022-29298SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.EXPLOITHIGH 7.5EPSS 46.8%12 May 2022
CVE-2022-30525Zyxel Multiple Firewalls OS Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%12 May 2022
CVE-2022-29885The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network.EXPLOITHIGH 7.5EPSS 73.5%12 May 2022
CVE-2022-29727Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.EXPLOITMEDIUM 5.4EPSS 2.39%11 May 2022
CVE-2022-27412Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.EXPLOITCRITICAL 9.8EPSS 4.05%9 May 2022
CVE-2022-27308A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title.EXPLOITMEDIUM 5.4EPSS 2.59%9 May 2022
CVE-2022-1104The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…EXPLOITMEDIUM 4.8EPSS 56.4%9 May 2022
CVE-2022-1631Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email.EXPLOITHIGH 8.8EPSS 8.85%9 May 2022
CVE-2022-30286pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.EXPLOITHIGH 7.5EPSS 13.6%9 May 2022
CVE-2022-28080Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.EXPLOITHIGH 8.8EPSS 56.9%5 May 2022
CVE-2022-28079College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.EXPLOITHIGH 8.8EPSS 28.5%5 May 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.