Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 19 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-0847 | Linux Kernel Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 89.7% | 10 March 2022 |
| CVE-2021-4045 | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. | EXPLOITCRITICAL 9.8EPSS 72.4% | 10 March 2022 |
| CVE-2022-24734 | In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. | EXPLOITHIGH 7.2EPSS 77.8% | 9 March 2022 |
| CVE-2022-0482 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | EXPLOITCRITICAL 9.1EPSS 43.7% | 9 March 2022 |
| CVE-2022-24716 | Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. | EXPLOITHIGH 7.5EPSS 89.4% | 8 March 2022 |
| CVE-2022-24715 | Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. | EXPLOITHIGH 8.8EPSS 14.7% | 8 March 2022 |
| CVE-2022-0448 | The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | EXPLOITMEDIUM 4.8EPSS 5.73% | 7 March 2022 |
| CVE-2022-0441 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | EXPLOITCRITICAL 9.8EPSS 85.3% | 7 March 2022 |
| CVE-2021-46381 | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | EXPLOITHIGH 7.5EPSS 58.9% | 4 March 2022 |
| CVE-2021-46379 | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. | EXPLOITMEDIUM 6.1EPSS 15.8% | 4 March 2022 |
| CVE-2021-46378 | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. | EXPLOITHIGH 7.5EPSS 31.9% | 4 March 2022 |
| CVE-2022-0848 | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | EXPLOITCRITICAL 9.8EPSS 35.4% | 4 March 2022 |
| CVE-2022-22947 | VMware Spring Cloud Gateway Code Injection Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 98.3% | 3 March 2022 |
| CVE-2022-25089 | Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData. | EXPLOITCRITICAL 9.8EPSS 18.4% | 3 March 2022 |
| CVE-2022-22909 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module. | EXPLOITHIGH 8.8EPSS 45.4% | 3 March 2022 |
| CVE-2022-0824 | Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. | EXPLOITHIGH 8.8EPSS 97.0% | 2 March 2022 |
| CVE-2021-46387 | ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). | EXPLOITMEDIUM 6.1EPSS 21.0% | 1 March 2022 |
| CVE-2021-4039 | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device. | EXPLOITCRITICAL 9.8EPSS 71.0% | 1 March 2022 |
| CVE-2022-0377 | An attacker can use this vulnerability in order to rename an arbitrary image file. | EXPLOITMEDIUM 4.3EPSS 3.21% | 28 February 2022 |
| CVE-2021-24901 | The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | EXPLOITMEDIUM 4.8EPSS 5.06% | 28 February 2022 |
| CVE-2022-26149 | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator. | EXPLOIT ✓HIGH 7.2EPSS 9.31% | 26 February 2022 |
| CVE-2022-25359 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | EXPLOITCRITICAL 9.1EPSS 37.3% | 26 February 2022 |
| CVE-2021-44665 | A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php. | EXPLOITMEDIUM 6.5EPSS 7.69% | 24 February 2022 |
| CVE-2021-44664 | An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload… | EXPLOITHIGH 8.8EPSS 12.8% | 24 February 2022 |
| CVE-2022-25148 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication… | EXPLOITCRITICAL 9.8EPSS 80.9% | 24 February 2022 |
| CVE-2022-24707 | UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. | EXPLOITHIGH 8.8EPSS 7.16% | 24 February 2022 |
| CVE-2021-44567 | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | EXPLOITCRITICAL 9.8EPSS 23.1% | 24 February 2022 |
| CVE-2022-23642 | Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. | EXPLOITHIGH 8.8EPSS 74.3% | 18 February 2022 |
| CVE-2021-3560 | Red Hat Polkit Incorrect Authorization Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 23.7% | 16 February 2022 |
| CVE-2022-25241 | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). | EXPLOITHIGH 8.8EPSS 3.27% | 16 February 2022 |
| CVE-2021-35380 | A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to… | EXPLOITHIGH 7.5EPSS 39.0% | 15 February 2022 |
| CVE-2021-24904 | The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the… | EXPLOITMEDIUM 4.8EPSS 5.06% | 14 February 2022 |
| CVE-2022-24112 | Apache APISIX Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 96.1% | 11 February 2022 |
| CVE-2022-0557 | OS Command Injection in Packagist microweber/microweber prior to 1.2.11. | EXPLOITHIGH 7.2EPSS 51.2% | 11 February 2022 |
| CVE-2022-0020 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web… | EXPLOITMEDIUM 5.4EPSS 1.71% | 10 February 2022 |
| CVE-2021-45901 | The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists. | EXPLOITMEDIUM 5.3EPSS 14.3% | 10 February 2022 |
| CVE-2022-22536 | SAP Multiple Products HTTP Request Smuggling Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 97.9% | 9 February 2022 |
| CVE-2021-46360 | Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr. | EXPLOIT ✓HIGH 8.8EPSS 9.18% | 9 February 2022 |
| CVE-2021-46354 | Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. | EXPLOITHIGH 7.5EPSS 12.9% | 9 February 2022 |
| CVE-2022-23626 | Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. | EXPLOITHIGH 8.8EPSS 9.87% | 8 February 2022 |
| CVE-2022-22833 | An attacker can obtain sensitive information via a /js/app.js request. | EXPLOITHIGH 7.5EPSS 11.6% | 6 February 2022 |
| CVE-2022-22832 | An issue was discovered in Servisnet Tessa 0.0.2. | EXPLOITCRITICAL 9.8EPSS 14.1% | 6 February 2022 |
| CVE-2022-22831 | An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. | EXPLOITCRITICAL 9.8EPSS 11.4% | 6 February 2022 |
| CVE-2021-46398 | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. | EXPLOITHIGH 8.8EPSS 6.66% | 4 February 2022 |
| CVE-2021-43062 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code… | EXPLOITMEDIUM 6.1EPSS 12.9% | 2 February 2022 |
| CVE-2022-24223 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | EXPLOITCRITICAL 9.8EPSS 62.0% | 1 February 2022 |
| CVE-2021-24926 | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 12.9% | 1 February 2022 |
| CVE-2021-24762 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. | EXPLOITCRITICAL 9.8EPSS 86.8% | 1 February 2022 |
| CVE-2022-24263 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | EXPLOITCRITICAL 9.8EPSS 8.24% | 31 January 2022 |
| CVE-2022-23409 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | EXPLOITMEDIUM 4.9EPSS 13.8% | 31 January 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.