Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 18 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-1388 | F5 BIG-IP Missing Authentication Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 5 May 2022 |
| CVE-2021-45783 | Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information. | EXPLOITMEDIUM 4.6EPSS 1.87% | 5 May 2022 |
| CVE-2022-1588 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 5 May 2022 |
| CVE-2021-43164 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless. | EXPLOITHIGH 8.8EPSS 35.0% | 4 May 2022 |
| CVE-2021-42165 | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path". | EXPLOITHIGH 8.8EPSS 14.1% | 3 May 2022 |
| CVE-2021-31674 | Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant. | EXPLOITMEDIUM 6.1EPSS 3.95% | 2 May 2022 |
| CVE-2021-31673 | A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter. | EXPLOITMEDIUM 6.1EPSS 2.56% | 2 May 2022 |
| CVE-2021-44596 | Fone as of 2021-12-06 version is affected by Remote code execution. | EXPLOITCRITICAL 9.8EPSS 22.9% | 29 April 2022 |
| CVE-2021-44595 | Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. | EXPLOIT ✓HIGH 8.8EPSS 21.1% | 29 April 2022 |
| CVE-2022-28117 | A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter. | EXPLOITMEDIUM 4.9EPSS 22.9% | 28 April 2022 |
| CVE-2021-46424 | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request. | EXPLOITCRITICAL 9.1EPSS 36.5% | 27 April 2022 |
| CVE-2021-46422 | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. | EXPLOIT ×2CRITICAL 9.8EPSS 94.3% | 27 April 2022 |
| CVE-2022-24706 | Apache CouchDB Insecure Default Initialization of Resource Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 92.5% | 26 April 2022 |
| CVE-2021-25094 | By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. | EXPLOITHIGH 8.1EPSS 83.4% | 25 April 2022 |
| CVE-2022-29548 | A reflected XSS issue exists in the Management Console of several WSO2 products. | EXPLOITMEDIUM 6.1EPSS 41.1% | 21 April 2022 |
| CVE-2021-43481 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | EXPLOITCRITICAL 9.8EPSS 5.61% | 20 April 2022 |
| CVE-2022-29457 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | EXPLOITHIGH 8.8EPSS 7.95% | 18 April 2022 |
| CVE-2022-1257 | Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. | EXPLOITMEDIUM 5.5EPSS 0.65% | 14 April 2022 |
| CVE-2021-42136 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. | EXPLOITCRITICAL 9.0EPSS 4.66% | 13 April 2022 |
| CVE-2022-28213 | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the… | EXPLOITHIGH 8.1EPSS 12.5% | 12 April 2022 |
| CVE-2022-26180 | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. | EXPLOITHIGH 8.8EPSS 3.75% | 8 April 2022 |
| CVE-2021-43149 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 8 April 2022 |
| CVE-2021-43009 | A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL. | EXPLOITMEDIUM 6.1EPSS 2.29% | 8 April 2022 |
| CVE-2021-46419 | An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts. | EXPLOITCRITICAL 9.1EPSS 71.4% | 7 April 2022 |
| CVE-2021-46418 | An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts. | EXPLOITHIGH 7.5EPSS 23.9% | 7 April 2022 |
| CVE-2021-46417 | Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580. | EXPLOITHIGH 7.5EPSS 59.8% | 7 April 2022 |
| CVE-2021-46416 | Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling. | EXPLOITHIGH 8.1EPSS 4.26% | 7 April 2022 |
| CVE-2022-26986 | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. | EXPLOITHIGH 7.2EPSS 4.13% | 5 April 2022 |
| CVE-2022-26982 | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. | EXPLOIT ✓HIGH 7.2EPSS 9.19% | 5 April 2022 |
| CVE-2022-23909 | This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. | EXPLOITHIGH 7.8EPSS 1.03% | 5 April 2022 |
| CVE-2022-1175 | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes. | EXPLOITMEDIUM 6.1EPSS 82.0% | 4 April 2022 |
| CVE-2022-1162 | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. | EXPLOITCRITICAL 9.8EPSS 76.2% | 4 April 2022 |
| CVE-2022-0088 | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. | EXPLOITHIGH 7.4EPSS 1.99% | 3 April 2022 |
| CVE-2022-28368 | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file). | EXPLOITCRITICAL 9.8EPSS 82.4% | 3 April 2022 |
| CVE-2022-22963 | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 1 April 2022 |
| CVE-2022-24181 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | EXPLOITMEDIUM 6.1EPSS 6.08% | 1 April 2022 |
| CVE-2022-1163 | Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next. | EXPLOITMEDIUM 4.8EPSS 3.51% | 30 March 2022 |
| CVE-2021-43701 | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters. | EXPLOITMEDIUM 6.5EPSS 3.35% | 29 March 2022 |
| CVE-2021-26599 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | EXPLOITCRITICAL 9.8EPSS 21.0% | 28 March 2022 |
| CVE-2022-1040 | Sophos Firewall Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.8% | 25 March 2022 |
| CVE-2021-43650 | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. | EXPLOITCRITICAL 9.8EPSS 6.16% | 22 March 2022 |
| CVE-2022-27226 | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. | EXPLOITHIGH 8.8EPSS 33.7% | 19 March 2022 |
| CVE-2022-24637 | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. | EXPLOITCRITICAL 9.8EPSS 99.1% | 18 March 2022 |
| CVE-2022-26965 | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. | EXPLOITHIGH 7.2EPSS 36.3% | 18 March 2022 |
| CVE-2022-0967 | Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. | EXPLOITMEDIUM 5.4EPSS 3.26% | 15 March 2022 |
| CVE-2021-45010 | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution. | EXPLOITHIGH 8.8EPSS 70.1% | 15 March 2022 |
| CVE-2021-24966 | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder | EXPLOITMEDIUM 4.9EPSS 5.19% | 14 March 2022 |
| CVE-2021-44673 | A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script. | EXPLOITHIGH 8.8EPSS 8.96% | 10 March 2022 |
| CVE-2022-26521 | Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid… | EXPLOIT ✓HIGH 7.2EPSS 9.62% | 10 March 2022 |
| CVE-2022-25090 | Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition. | EXPLOITHIGH 8.1EPSS 11.1% | 10 March 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.