SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 18 of 501

CVESummaryPriorityPublished
CVE-2022-1388F5 BIG-IP Missing Authentication VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%5 May 2022
CVE-2021-45783Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.EXPLOITMEDIUM 4.6EPSS 1.87%5 May 2022
CVE-2022-1588Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —5 May 2022
CVE-2021-43164A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.EXPLOITHIGH 8.8EPSS 35.0%4 May 2022
CVE-2021-42165MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".EXPLOITHIGH 8.8EPSS 14.1%3 May 2022
CVE-2021-31674Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.EXPLOITMEDIUM 6.1EPSS 3.95%2 May 2022
CVE-2021-31673A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.EXPLOITMEDIUM 6.1EPSS 2.56%2 May 2022
CVE-2021-44596Fone as of 2021-12-06 version is affected by Remote code execution.EXPLOITCRITICAL 9.8EPSS 22.9%29 April 2022
CVE-2021-44595Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control.EXPLOITHIGH 8.8EPSS 21.1%29 April 2022
CVE-2022-28117A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.EXPLOITMEDIUM 4.9EPSS 22.9%28 April 2022
CVE-2021-46424Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.EXPLOITCRITICAL 9.1EPSS 36.5%27 April 2022
CVE-2021-46422Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.EXPLOIT ×2CRITICAL 9.8EPSS 94.3%27 April 2022
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 92.5%26 April 2022
CVE-2021-25094By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.EXPLOITHIGH 8.1EPSS 83.4%25 April 2022
CVE-2022-29548A reflected XSS issue exists in the Management Console of several WSO2 products.EXPLOITMEDIUM 6.1EPSS 41.1%21 April 2022
CVE-2021-43481An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.EXPLOITCRITICAL 9.8EPSS 5.61%20 April 2022
CVE-2022-29457Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.EXPLOITHIGH 8.8EPSS 7.95%18 April 2022
CVE-2022-1257Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db.EXPLOITMEDIUM 5.5EPSS 0.65%14 April 2022
CVE-2021-42136A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value.EXPLOITCRITICAL 9.0EPSS 4.66%13 April 2022
CVE-2022-28213When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the…EXPLOITHIGH 8.1EPSS 12.5%12 April 2022
CVE-2022-26180qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.EXPLOITHIGH 8.8EPSS 3.75%8 April 2022
CVE-2021-43149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —8 April 2022
CVE-2021-43009A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.EXPLOITMEDIUM 6.1EPSS 2.29%8 April 2022
CVE-2021-46419An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.EXPLOITCRITICAL 9.1EPSS 71.4%7 April 2022
CVE-2021-46418An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.EXPLOITHIGH 7.5EPSS 23.9%7 April 2022
CVE-2021-46417Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.EXPLOITHIGH 7.5EPSS 59.8%7 April 2022
CVE-2021-46416Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.EXPLOITHIGH 8.1EPSS 4.26%7 April 2022
CVE-2022-26986SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application.EXPLOITHIGH 7.2EPSS 4.13%5 April 2022
CVE-2022-26982SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator.EXPLOITHIGH 7.2EPSS 9.19%5 April 2022
CVE-2022-23909This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.EXPLOITHIGH 7.8EPSS 1.03%5 April 2022
CVE-2022-1175Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.EXPLOITMEDIUM 6.1EPSS 82.0%4 April 2022
CVE-2022-1162A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.EXPLOITCRITICAL 9.8EPSS 76.2%4 April 2022
CVE-2022-0088Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.EXPLOITHIGH 7.4EPSS 1.99%3 April 2022
CVE-2022-28368Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).EXPLOITCRITICAL 9.8EPSS 82.4%3 April 2022
CVE-2022-22963VMware Tanzu Spring Cloud Function Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%1 April 2022
CVE-2022-24181Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.EXPLOITMEDIUM 6.1EPSS 6.08%1 April 2022
CVE-2022-1163Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.EXPLOITMEDIUM 4.8EPSS 3.51%30 March 2022
CVE-2021-43701CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.EXPLOITMEDIUM 6.5EPSS 3.35%29 March 2022
CVE-2021-26599ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.EXPLOITCRITICAL 9.8EPSS 21.0%28 March 2022
CVE-2022-1040Sophos Firewall Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.8%25 March 2022
CVE-2021-43650WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.EXPLOITCRITICAL 9.8EPSS 6.16%22 March 2022
CVE-2022-27226A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel.EXPLOITHIGH 8.8EPSS 33.7%19 March 2022
CVE-2022-24637Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.EXPLOITCRITICAL 9.8EPSS 99.1%18 March 2022
CVE-2022-26965In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.EXPLOITHIGH 7.2EPSS 36.3%18 March 2022
CVE-2022-0967Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.EXPLOITMEDIUM 5.4EPSS 3.26%15 March 2022
CVE-2021-45010A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.EXPLOITHIGH 8.8EPSS 70.1%15 March 2022
CVE-2021-24966The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folderEXPLOITMEDIUM 4.9EPSS 5.19%14 March 2022
CVE-2021-44673A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.EXPLOITHIGH 8.8EPSS 8.96%10 March 2022
CVE-2022-26521Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid…EXPLOITHIGH 7.2EPSS 9.62%10 March 2022
CVE-2022-25090Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.EXPLOITHIGH 8.1EPSS 11.1%10 March 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.