SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,014 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 15 of 35

CVESummaryPriorityPublished
CVE-2022-40684Fortinet Multiple Products Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%18 October 2022
CVE-2022-41033Microsoft Windows COM+ Event System Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 1.67%11 October 2022
CVE-2022-38028Microsoft Windows Print Spooler Privilege Escalation Vulnerability KEVHIGH 7.8EPSS 14.9%11 October 2022
CVE-2022-41082Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 8.0EPSS 100.0%3 October 2022
CVE-2022-41040Microsoft Exchange Server Server-Side Request Forgery VulnerabilityKEVHIGH 8.8EPSS 100.0%3 October 2022
CVE-2022-20775Cisco SD-WAN Path Traversal VulnerabilityKEVHIGH 7.8EPSS 12.5%30 September 2022
CVE-2022-3075Google Chromium Mojo Insufficient Data Validation VulnerabilityKEVCRITICAL 9.6EPSS 5.76%26 September 2022
CVE-2022-3038Google Chromium Network Service Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 24.7%26 September 2022
CVE-2022-2856Google Chromium Intents Insufficient Input Validation VulnerabilityKEVMEDIUM 6.5EPSS 4.53%26 September 2022
CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityKEVCRITICAL 9.8EPSS 95.5%26 September 2022
CVE-2022-3236Sophos Firewall Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.9%23 September 2022
CVE-2022-39197Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 46.4%22 September 2022
CVE-2022-32917Apple iOS, iPadOS, and macOS Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 5.60%20 September 2022
CVE-2022-40139Trend Micro Apex One and Apex One as a Service Improper Validation VulnerabilityKEVHIGH 7.2EPSS 2.86%19 September 2022
CVE-2022-35914Teclib GLPI Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%19 September 2022
CVE-2022-37969Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 28.3%13 September 2022
CVE-2022-27593QNAP Photo Station Externally Controlled Reference VulnerabilityKEVCRITICAL 9.1EPSS 87.9%8 September 2022
CVE-2022-37055D-Link Routers Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 55.5%28 August 2022
CVE-2022-36537ZK Framework AuUploader Unspecified VulnerabilityKEVHIGH 7.5EPSS 95.4%26 August 2022
CVE-2022-36804Atlassian Bitbucket Server and Data Center Command Injection VulnerabilityKEVHIGH 8.8EPSS 99.2%25 August 2022
CVE-2022-32894Apple iOS and macOS Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 3.29%24 August 2022
CVE-2022-32893Apple iOS and macOS Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 9.93%24 August 2022
CVE-2022-37042Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 91.9%12 August 2022
CVE-2022-0028Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service VulnerabilityKEVHIGH 8.6EPSS 2.38%10 August 2022
CVE-2022-34713Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 67.8%9 August 2022
CVE-2022-2294WebRTC Heap Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 70.5%28 July 2022
CVE-2022-1364Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 13.7%26 July 2022
CVE-2022-1096Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 24.4%23 July 2022
CVE-2022-26138Atlassian Questions For Confluence App Hard-coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 98.2%20 July 2022
CVE-2022-35405Zoho ManageEngine Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%19 July 2022
CVE-2022-33891Apache Spark Command Injection VulnerabilityKEVHIGH 8.8EPSS 93.1%18 July 2022
CVE-2022-26352dotCMS Unrestricted Upload of File VulnerabilityKEVCRITICAL 9.8EPSS 91.6%17 July 2022
CVE-2022-22047Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 18.8%12 July 2022
CVE-2022-22071Qualcomm Multiple Chipsets Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.46%14 June 2022
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%3 June 2022
CVE-2022-30190Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 99.2%1 June 2022
CVE-2022-22675Apple macOS Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 12.5%26 May 2022
CVE-2022-22674Apple macOS Out-of-Bounds Read VulnerabilityKEVMEDIUM 5.5EPSS 1.13%26 May 2022
CVE-2022-20821Cisco IOS XR Open Port VulnerabilityKEVMEDIUM 6.5EPSS 12.1%26 May 2022
CVE-2022-29303SolarView Compact Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.0%12 May 2022
CVE-2022-30525Zyxel Multiple Firewalls OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.9%12 May 2022
CVE-2022-26925Microsoft Windows LSA Spoofing VulnerabilityKEVMEDIUM 5.9EPSS 10.7%10 May 2022
CVE-2022-26923Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 83.5%10 May 2022
CVE-2022-30333RARLAB UnRAR Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 99.1%9 May 2022
CVE-2022-1388F5 BIG-IP Missing Authentication VulnerabilityKEVCRITICAL 9.8EPSS 100.0%5 May 2022
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource VulnerabilityKEVCRITICAL 9.8EPSS 92.5%26 April 2022
CVE-2022-29499Mitel MiVoice Connect Data Validation VulnerabilityKEVCRITICAL 9.8EPSS 55.6%26 April 2022
CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 17.6%21 April 2022
CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityKEVHIGH 7.2EPSS 98.7%21 April 2022
CVE-2022-27924Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityKEVHIGH 7.5EPSS 85.4%21 April 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.