SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 20 of 501

CVESummaryPriorityPublished
CVE-2022-24124The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.EXPLOITHIGH 7.5EPSS 55.3%29 January 2022
CVE-2021-4034Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityKEVEXPLOITHIGH 7.8EPSS 94.9%28 January 2022
CVE-2022-0332An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.EXPLOITCRITICAL 9.8EPSS 44.9%25 January 2022
CVE-2021-25076The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection.EXPLOITHIGH 8.8EPSS 17.1%24 January 2022
CVE-2022-23366HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.EXPLOITCRITICAL 9.8EPSS 6.71%21 January 2022
CVE-2022-23046PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.phpEXPLOITHIGH 7.2EPSS 25.2%19 January 2022
CVE-2022-21371Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).EXPLOITHIGH 7.5EPSS 92.6%19 January 2022
CVE-2022-23178When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface.EXPLOITCRITICAL 9.8EPSS 75.2%15 January 2022
CVE-2022-21907HTTP Protocol Stack Remote Code Execution VulnerabilityEXPLOITCRITICAL 9.8EPSS 92.8%11 January 2022
CVE-2021-24862The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issueEXPLOITHIGH 7.2EPSS 73.3%10 January 2022
CVE-2022-22836CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.EXPLOITMEDIUM 6.5EPSS 5.37%10 January 2022
CVE-2021-43579A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.EXPLOITHIGH 7.8EPSS 7.35%10 January 2022
CVE-2022-21661Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way.EXPLOITHIGH 7.5EPSS 97.8%6 January 2022
CVE-2021-45428TLR-2005KSH is affected by an incorrect access control vulnerability.EXPLOITCRITICAL 9.8EPSS 56.9%3 January 2022
CVE-2021-24786The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issueEXPLOITHIGH 7.2EPSS 17.3%3 January 2022
CVE-2021-45814Nettmp NNT 5.1 is affected by a SQL injection vulnerability.EXPLOITCRITICAL 9.8EPSS 6.34%28 December 2021
CVE-2021-45425Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.EXPLOITMEDIUM 6.1EPSS 3.39%28 December 2021
CVE-2021-43857Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.EXPLOITHIGH 8.8EPSS 55.3%27 December 2021
CVE-2021-24750The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to…EXPLOITHIGH 8.8EPSS 38.3%21 December 2021
CVE-2021-44916Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability.EXPLOITMEDIUM 6.1EPSS 3.71%20 December 2021
CVE-2021-44790A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts).EXPLOITCRITICAL 9.8EPSS 96.8%20 December 2021
CVE-2021-45092Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.EXPLOITCRITICAL 9.8EPSS 40.6%16 December 2021
CVE-2021-44655Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability.EXPLOITCRITICAL 9.8EPSS 5.97%15 December 2021
CVE-2021-44653Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.EXPLOITCRITICAL 9.8EPSS 5.97%15 December 2021
CVE-2021-45043HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.EXPLOITHIGH 7.5EPSS 33.1%15 December 2021
CVE-2021-43326Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.EXPLOITHIGH 7.8EPSS 1.23%15 December 2021
CVE-2021-39312The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.EXPLOITHIGH 7.5EPSS 77.9%14 December 2021
CVE-2021-24946The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated…EXPLOITCRITICAL 9.8EPSS 72.8%13 December 2021
CVE-2021-44848In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.EXPLOITMEDIUM 5.3EPSS 23.0%13 December 2021
CVE-2021-44228Apache Log4j2 Remote Code Execution VulnerabilityKEVEXPLOIT ×3CRITICAL 10.0EPSS 100.0%10 December 2021
CVE-2021-3817wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL CommandEXPLOITCRITICAL 9.8EPSS 38.4%9 December 2021
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability KEVEXPLOITCRITICAL 9.8EPSS 99.1%8 December 2021
CVE-2021-38759If not changed, attackers can gain administrator privileges.EXPLOITCRITICAL 9.8EPSS 15.7%7 December 2021
CVE-2021-43798Grafana Path Traversal VulnerabilityKEVEXPLOITHIGH 7.5EPSS 88.5%7 December 2021
CVE-2021-40859Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.EXPLOITCRITICAL 9.8EPSS 72.0%7 December 2021
CVE-2021-43936The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.EXPLOITCRITICAL 9.8EPSS 35.8%6 December 2021
CVE-2021-24931The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a…EXPLOITCRITICAL 9.8EPSS 78.8%6 December 2021
CVE-2021-42362The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload…EXPLOITHIGH 8.8EPSS 79.8%17 November 2021
CVE-2021-42580Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated…EXPLOITCRITICAL 9.8EPSS 9.98%15 November 2021
CVE-2021-43617Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based…EXPLOITCRITICAL 9.8EPSS 19.8%14 November 2021
CVE-2021-43136An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.EXPLOITCRITICAL 9.8EPSS 15.7%10 November 2021
CVE-2021-40577A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.EXPLOITMEDIUM 5.4EPSS 1.64%8 November 2021
CVE-2021-24664The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.EXPLOITMEDIUM 4.8EPSS 2.36%8 November 2021
CVE-2021-43405An issue was discovered in FusionPBX before 4.5.30.EXPLOITHIGH 8.8EPSS 35.6%5 November 2021
CVE-2021-43339In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality.EXPLOITHIGH 8.8EPSS 9.56%3 November 2021
CVE-2021-43338Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —3 November 2021
CVE-2021-43140SQL Injection vulnerability exists in Sourcecodester.EXPLOITCRITICAL 9.8EPSS 4.73%3 November 2021
CVE-2021-42697Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.EXPLOITHIGH 7.5EPSS 36.1%2 November 2021
CVE-2017-5123Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.EXPLOIT ×2HIGH 8.8EPSS 3.71%2 November 2021
CVE-2021-3441A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).EXPLOITMEDIUM 4.8EPSS 1.73%29 October 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.