Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 16 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-21445 | Oracle ADF Faces Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 62.5% | 19 April 2022 |
| CVE-2022-29464 | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 18 April 2022 |
| CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | KEVMEDIUM 6.8EPSS 71.0% | 18 April 2022 |
| CVE-2022-26904 | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 9.59% | 15 April 2022 |
| CVE-2022-24521 | Microsoft Windows CLFS Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 7.13% | 15 April 2022 |
| CVE-2022-24816 | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 98.5% | 13 April 2022 |
| CVE-2022-22960 | VMware Multiple Products Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 35.8% | 13 April 2022 |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 11 April 2022 |
| CVE-2022-0609 | Google Chromium Animation Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 22.9% | 5 April 2022 |
| CVE-2022-22965 | Spring Framework JDK 9+ Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 1 April 2022 |
| CVE-2022-22963 | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 1 April 2022 |
| CVE-2022-26871 | Trend Micro Apex Central Arbitrary File Upload Vulnerability | KEVCRITICAL 9.8EPSS 19.6% | 29 March 2022 |
| CVE-2022-22948 | VMware vCenter Server Incorrect Default File Permissions Vulnerability | KEVMEDIUM 6.5EPSS 13.3% | 29 March 2022 |
| CVE-2022-26258 | D-Link DIR-820L Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 92.0% | 28 March 2022 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 9.52% | 25 March 2022 |
| CVE-2022-1040 | Sophos Firewall Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 25 March 2022 |
| CVE-2022-22620 | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 16.3% | 18 March 2022 |
| CVE-2022-22587 | Apple Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 11.6% | 18 March 2022 |
| CVE-2022-26501 | Veeam Backup & Replication Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 4.10% | 17 March 2022 |
| CVE-2022-26500 | Veeam Backup & Replication Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 5.83% | 17 March 2022 |
| CVE-2021-39793 | Google Pixel Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 0.74% | 16 March 2022 |
| CVE-2022-26143 | MiCollab, MiVoice Business Express Access Control Vulnerability | KEVCRITICAL 9.8EPSS 87.2% | 10 March 2022 |
| CVE-2022-0847 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 89.7% | 10 March 2022 |
| CVE-2022-26318 | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution | KEVCRITICAL 9.8EPSS 78.2% | 4 March 2022 |
| CVE-2022-22947 | VMware Spring Cloud Gateway Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 98.3% | 3 March 2022 |
| CVE-2022-0492 | Linux Kernel Improper Authentication Vulnerability | KEVHIGH 7.8EPSS 5.53% | 3 March 2022 |
| CVE-2022-22706 | Arm Mali GPU Kernel Driver Unspecified Vulnerability | KEVHIGH 7.8EPSS 1.09% | 3 March 2022 |
| CVE-2022-23176 | WatchGuard Firebox and XTM Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 12.7% | 24 February 2022 |
| CVE-2022-0543 | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | KEVCRITICAL 10.0EPSS 99.4% | 18 February 2022 |
| CVE-2021-45382 | D-Link Multiple Routers Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.8% | 17 February 2022 |
| CVE-2021-3560 | Red Hat Polkit Incorrect Authorization Vulnerability | KEVHIGH 7.8EPSS 22.2% | 16 February 2022 |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 16 February 2022 |
| CVE-2021-4102 | Google Chromium V8 Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 7.84% | 11 February 2022 |
| CVE-2022-0185 | Linux Kernel Heap-Based Buffer Overflow Vulnerability | KEVHIGH 8.4EPSS 25.2% | 11 February 2022 |
| CVE-2022-24112 | Apache APISIX Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 96.0% | 11 February 2022 |
| CVE-2022-20708 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVHIGH 8.0EPSS 14.9% | 10 February 2022 |
| CVE-2022-20703 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVHIGH 8.0EPSS 9.20% | 10 February 2022 |
| CVE-2022-20701 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 9.75% | 10 February 2022 |
| CVE-2022-20700 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 5.66% | 10 February 2022 |
| CVE-2022-20699 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 72.5% | 10 February 2022 |
| CVE-2022-22536 | SAP Multiple Products HTTP Request Smuggling Vulnerability | KEVCRITICAL 10.0EPSS 97.9% | 9 February 2022 |
| CVE-2022-22718 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.5% | 9 February 2022 |
| CVE-2022-21999 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 41.7% | 9 February 2022 |
| CVE-2022-21971 | Microsoft Windows Runtime Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 53.9% | 9 February 2022 |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 30.9% | 9 February 2022 |
| CVE-2021-40407 | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 47.6% | 28 January 2022 |
| CVE-2021-4034 | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability | KEVHIGH 7.8EPSS 94.9% | 28 January 2022 |
| CVE-2021-22600 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 6.08% | 26 January 2022 |
| CVE-2021-35587 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 96.3% | 19 January 2022 |
| CVE-2022-23227 | NUUO NVRmini2 Devices Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 48.5% | 14 January 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.