Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 14 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-25280 | D-Link DIR-820 Router OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 16 March 2023 |
| CVE-2023-28461 | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 68.1% | 15 March 2023 |
| CVE-2023-1389 | TP-Link Archer AX-21 Command Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 15 March 2023 |
| CVE-2023-24880 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVMEDIUM 4.4EPSS 78.2% | 14 March 2023 |
| CVE-2023-23397 | Microsoft Office Outlook Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 97.4% | 14 March 2023 |
| CVE-2023-27532 | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | KEVHIGH 7.5EPSS 77.6% | 10 March 2023 |
| CVE-2022-41328 | Fortinet FortiOS Path Traversal Vulnerability | KEVHIGH 7.1EPSS 10.7% | 7 March 2023 |
| CVE-2019-8720 | WebKitGTK Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 1.56% | 6 March 2023 |
| CVE-2023-23529 | Apple Multiple Products WebKit Type Confusion Vulnerability | KEVHIGH 8.8EPSS 9.50% | 27 February 2023 |
| CVE-2022-47986 | IBM Aspera Faspex Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 17 February 2023 |
| CVE-2023-23752 | Joomla! Improper Access Control Vulnerability | KEVMEDIUM 5.3EPSS 99.8% | 16 February 2023 |
| CVE-2023-21823 | Microsoft Windows Graphic Component Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.56% | 14 February 2023 |
| CVE-2023-23376 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 10.9% | 14 February 2023 |
| CVE-2023-21715 | Microsoft Office Publisher Security Feature Bypass Vulnerability | KEVHIGH 7.3EPSS 12.0% | 14 February 2023 |
| CVE-2023-21529 | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 62.1% | 14 February 2023 |
| CVE-2023-25717 | Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | KEVCRITICAL 9.8EPSS 98.1% | 13 February 2023 |
| CVE-2022-24990 | TerraMaster OS Remote Command Execution Vulnerability | KEVHIGH 7.5EPSS 83.6% | 7 February 2023 |
| CVE-2023-0669 | Fortra GoAnywhere MFT Remote Code Execution Vulnerability | KEVHIGH 7.2EPSS 100.0% | 6 February 2023 |
| CVE-2023-0266 | Linux Kernel Use-After-Free Vulnerability | KEVHIGH 7.0EPSS 3.70% | 30 January 2023 |
| CVE-2023-21608 | Adobe Acrobat and Reader Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 61.5% | 18 January 2023 |
| CVE-2022-47966 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 18 January 2023 |
| CVE-2023-21839 | Oracle WebLogic Server Unspecified Vulnerability | KEVHIGH 7.5EPSS 99.9% | 18 January 2023 |
| CVE-2023-22952 | Multiple SugarCRM Products Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 80.1% | 11 January 2023 |
| CVE-2023-21674 | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 41.8% | 10 January 2023 |
| CVE-2022-44877 | CWP Control Web Panel OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 January 2023 |
| CVE-2022-42475 | Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 2 January 2023 |
| CVE-2022-26486 | Mozilla Firefox Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 2.35% | 22 December 2022 |
| CVE-2022-26485 | Mozilla Firefox Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 14.3% | 22 December 2022 |
| CVE-2022-42856 | Apple iOS Type Confusion Vulnerability | KEVHIGH 8.8EPSS 8.52% | 15 December 2022 |
| CVE-2022-44698 | Microsoft Defender SmartScreen Security Feature Bypass Vulnerability | KEVMEDIUM 5.4EPSS 76.3% | 13 December 2022 |
| CVE-2022-27518 | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 6.88% | 13 December 2022 |
| CVE-2022-46169 | Cacti Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 5 December 2022 |
| CVE-2022-4262 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 16.0% | 2 December 2022 |
| CVE-2022-40799 | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | KEVHIGH 8.8EPSS 33.7% | 29 November 2022 |
| CVE-2022-4135 | Google Chromium GPU Heap Buffer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 31.9% | 25 November 2022 |
| CVE-2022-41223 | Mitel MiVoice Connect Code Injection Vulnerability | KEVMEDIUM 6.8EPSS 10.6% | 22 November 2022 |
| CVE-2022-40765 | Mitel MiVoice Connect Command Injection Vulnerability | KEVMEDIUM 6.8EPSS 10.5% | 22 November 2022 |
| CVE-2022-23748 | Dante Discovery Process Control Vulnerability | KEVHIGH 7.8EPSS 9.09% | 17 November 2022 |
| CVE-2022-41128 | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 24.6% | 9 November 2022 |
| CVE-2022-41125 | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.02% | 9 November 2022 |
| CVE-2022-41091 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | KEVMEDIUM 5.4EPSS 1.81% | 9 November 2022 |
| CVE-2022-41080 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 77.3% | 9 November 2022 |
| CVE-2022-41073 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.26% | 9 November 2022 |
| CVE-2022-41049 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | KEVMEDIUM 5.4EPSS 2.49% | 9 November 2022 |
| CVE-2022-31199 | Netwrix Auditor Insecure Object Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 36.0% | 8 November 2022 |
| CVE-2022-3723 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 7.92% | 1 November 2022 |
| CVE-2022-42827 | Apple iOS and iPadOS Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 1.05% | 1 November 2022 |
| CVE-2022-38181 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 13.6% | 25 October 2022 |
| CVE-2016-20017 | D-Link DSL-2750B Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 65.2% | 19 October 2022 |
| CVE-2022-21587 | Oracle E-Business Suite Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 18 October 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.