Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 15 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-40684 | Fortinet Multiple Products Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 18 October 2022 |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 1.67% | 11 October 2022 |
| CVE-2022-38028 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 14.9% | 11 October 2022 |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 8.0EPSS 100.0% | 3 October 2022 |
| CVE-2022-41040 | Microsoft Exchange Server Server-Side Request Forgery Vulnerability | KEVHIGH 8.8EPSS 100.0% | 3 October 2022 |
| CVE-2022-20775 | Cisco SD-WAN Path Traversal Vulnerability | KEVHIGH 7.8EPSS 12.5% | 30 September 2022 |
| CVE-2022-3075 | Google Chromium Mojo Insufficient Data Validation Vulnerability | KEVCRITICAL 9.6EPSS 5.76% | 26 September 2022 |
| CVE-2022-3038 | Google Chromium Network Service Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 24.7% | 26 September 2022 |
| CVE-2022-2856 | Google Chromium Intents Insufficient Input Validation Vulnerability | KEVMEDIUM 6.5EPSS 4.53% | 26 September 2022 |
| CVE-2022-41352 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | KEVCRITICAL 9.8EPSS 95.5% | 26 September 2022 |
| CVE-2022-3236 | Sophos Firewall Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 23 September 2022 |
| CVE-2022-39197 | Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 46.4% | 22 September 2022 |
| CVE-2022-32917 | Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 5.60% | 20 September 2022 |
| CVE-2022-40139 | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | KEVHIGH 7.2EPSS 2.86% | 19 September 2022 |
| CVE-2022-35914 | Teclib GLPI Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 19 September 2022 |
| CVE-2022-37969 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 28.3% | 13 September 2022 |
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Vulnerability | KEVCRITICAL 9.1EPSS 87.9% | 8 September 2022 |
| CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 55.5% | 28 August 2022 |
| CVE-2022-36537 | ZK Framework AuUploader Unspecified Vulnerability | KEVHIGH 7.5EPSS 95.4% | 26 August 2022 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | KEVHIGH 8.8EPSS 99.2% | 25 August 2022 |
| CVE-2022-32894 | Apple iOS and macOS Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 3.29% | 24 August 2022 |
| CVE-2022-32893 | Apple iOS and macOS Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 9.93% | 24 August 2022 |
| CVE-2022-37042 | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 12 August 2022 |
| CVE-2022-0028 | Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability | KEVHIGH 8.6EPSS 2.38% | 10 August 2022 |
| CVE-2022-34713 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 67.8% | 9 August 2022 |
| CVE-2022-2294 | WebRTC Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 70.5% | 28 July 2022 |
| CVE-2022-1364 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 13.7% | 26 July 2022 |
| CVE-2022-1096 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 24.4% | 23 July 2022 |
| CVE-2022-26138 | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 98.2% | 20 July 2022 |
| CVE-2022-35405 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 19 July 2022 |
| CVE-2022-33891 | Apache Spark Command Injection Vulnerability | KEVHIGH 8.8EPSS 93.1% | 18 July 2022 |
| CVE-2022-26352 | dotCMS Unrestricted Upload of File Vulnerability | KEVCRITICAL 9.8EPSS 91.6% | 17 July 2022 |
| CVE-2022-22047 | Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.8% | 12 July 2022 |
| CVE-2022-22071 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.46% | 14 June 2022 |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 3 June 2022 |
| CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.2% | 1 June 2022 |
| CVE-2022-22675 | Apple macOS Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 12.5% | 26 May 2022 |
| CVE-2022-22674 | Apple macOS Out-of-Bounds Read Vulnerability | KEVMEDIUM 5.5EPSS 1.13% | 26 May 2022 |
| CVE-2022-20821 | Cisco IOS XR Open Port Vulnerability | KEVMEDIUM 6.5EPSS 12.1% | 26 May 2022 |
| CVE-2022-29303 | SolarView Compact Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 12 May 2022 |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 12 May 2022 |
| CVE-2022-26925 | Microsoft Windows LSA Spoofing Vulnerability | KEVMEDIUM 5.9EPSS 10.7% | 10 May 2022 |
| CVE-2022-26923 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 83.5% | 10 May 2022 |
| CVE-2022-30333 | RARLAB UnRAR Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 99.1% | 9 May 2022 |
| CVE-2022-1388 | F5 BIG-IP Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 May 2022 |
| CVE-2022-24706 | Apache CouchDB Insecure Default Initialization of Resource Vulnerability | KEVCRITICAL 9.8EPSS 92.5% | 26 April 2022 |
| CVE-2022-29499 | Mitel MiVoice Connect Data Validation Vulnerability | KEVCRITICAL 9.8EPSS 55.6% | 26 April 2022 |
| CVE-2022-27926 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 17.6% | 21 April 2022 |
| CVE-2022-27925 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | KEVHIGH 7.2EPSS 98.7% | 21 April 2022 |
| CVE-2022-27924 | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability | KEVHIGH 7.5EPSS 85.4% | 21 April 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.