SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 19 of 501

CVESummaryPriorityPublished
CVE-2022-0847Linux Kernel Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 89.7%10 March 2022
CVE-2021-4045TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root.EXPLOITCRITICAL 9.8EPSS 72.4%10 March 2022
CVE-2022-24734In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages.EXPLOITHIGH 7.2EPSS 77.8%9 March 2022
CVE-2022-0482Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.EXPLOITCRITICAL 9.1EPSS 43.7%9 March 2022
CVE-2022-24716Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials.EXPLOITHIGH 7.5EPSS 89.4%8 March 2022
CVE-2022-24715Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code.EXPLOITHIGH 8.8EPSS 14.7%8 March 2022
CVE-2022-0448The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.EXPLOITMEDIUM 4.8EPSS 5.73%7 March 2022
CVE-2022-0441The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an adminEXPLOITCRITICAL 9.8EPSS 85.3%7 March 2022
CVE-2021-46381Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].EXPLOITHIGH 7.5EPSS 58.9%4 March 2022
CVE-2021-46379DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.EXPLOITMEDIUM 6.1EPSS 15.8%4 March 2022
CVE-2021-46378DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.EXPLOITHIGH 7.5EPSS 31.9%4 March 2022
CVE-2022-0848OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.EXPLOITCRITICAL 9.8EPSS 35.4%4 March 2022
CVE-2022-22947VMware Spring Cloud Gateway Code Injection VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 98.3%3 March 2022
CVE-2022-25089Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.EXPLOITCRITICAL 9.8EPSS 18.4%3 March 2022
CVE-2022-22909HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.EXPLOITHIGH 8.8EPSS 45.4%3 March 2022
CVE-2022-0824Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.EXPLOITHIGH 8.8EPSS 97.0%2 March 2022
CVE-2021-46387ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS).EXPLOITMEDIUM 6.1EPSS 21.0%1 March 2022
CVE-2021-4039A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.EXPLOITCRITICAL 9.8EPSS 71.0%1 March 2022
CVE-2022-0377An attacker can use this vulnerability in order to rename an arbitrary image file.EXPLOITMEDIUM 4.3EPSS 3.21%28 February 2022
CVE-2021-24901The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.EXPLOITMEDIUM 4.8EPSS 5.06%28 February 2022
CVE-2022-26149MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.EXPLOITHIGH 7.2EPSS 9.31%26 February 2022
CVE-2022-25359On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.EXPLOITCRITICAL 9.1EPSS 37.3%26 February 2022
CVE-2021-44665A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php.EXPLOITMEDIUM 6.5EPSS 7.69%24 February 2022
CVE-2021-44664An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload…EXPLOITHIGH 8.8EPSS 12.8%24 February 2022
CVE-2022-25148The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication…EXPLOITCRITICAL 9.8EPSS 80.9%24 February 2022
CVE-2022-24707UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642.EXPLOITHIGH 8.8EPSS 7.16%24 February 2022
CVE-2021-44567An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.EXPLOITCRITICAL 9.8EPSS 23.1%24 February 2022
CVE-2022-23642Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service.EXPLOITHIGH 8.8EPSS 74.3%18 February 2022
CVE-2021-3560Red Hat Polkit Incorrect Authorization VulnerabilityKEVEXPLOITHIGH 7.8EPSS 23.7%16 February 2022
CVE-2022-25241In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).EXPLOITHIGH 8.8EPSS 3.27%16 February 2022
CVE-2021-35380A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to…EXPLOITHIGH 7.5EPSS 39.0%15 February 2022
CVE-2021-24904The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the…EXPLOITMEDIUM 4.8EPSS 5.06%14 February 2022
CVE-2022-24112Apache APISIX Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 96.1%11 February 2022
CVE-2022-0557OS Command Injection in Packagist microweber/microweber prior to 1.2.11.EXPLOITHIGH 7.2EPSS 51.2%11 February 2022
CVE-2022-0020A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web…EXPLOITMEDIUM 5.4EPSS 1.71%10 February 2022
CVE-2021-45901The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.EXPLOITMEDIUM 5.3EPSS 14.3%10 February 2022
CVE-2022-22536SAP Multiple Products HTTP Request Smuggling VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 97.9%9 February 2022
CVE-2021-46360Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.EXPLOITHIGH 8.8EPSS 9.18%9 February 2022
CVE-2021-46354Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site.EXPLOITHIGH 7.5EPSS 12.9%9 February 2022
CVE-2022-23626Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk.EXPLOITHIGH 8.8EPSS 9.87%8 February 2022
CVE-2022-22833An attacker can obtain sensitive information via a /js/app.js request.EXPLOITHIGH 7.5EPSS 11.6%6 February 2022
CVE-2022-22832An issue was discovered in Servisnet Tessa 0.0.2.EXPLOITCRITICAL 9.8EPSS 14.1%6 February 2022
CVE-2022-22831An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.EXPLOITCRITICAL 9.8EPSS 11.4%6 February 2022
CVE-2021-46398A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.EXPLOITHIGH 8.8EPSS 6.66%4 February 2022
CVE-2021-43062A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code…EXPLOITMEDIUM 6.1EPSS 12.9%2 February 2022
CVE-2022-24223AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.EXPLOITCRITICAL 9.8EPSS 62.0%1 February 2022
CVE-2021-24926The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issueEXPLOITMEDIUM 6.1EPSS 12.9%1 February 2022
CVE-2021-24762The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.EXPLOITCRITICAL 9.8EPSS 86.8%1 February 2022
CVE-2022-24263Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.EXPLOITCRITICAL 9.8EPSS 8.24%31 January 2022
CVE-2022-23409The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.EXPLOITMEDIUM 4.9EPSS 13.8%31 January 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.