Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 40 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-5674 | The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor. | HIGH 8.8EPSS 10.8% | 26 December 2023 |
| CVE-2023-51092 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade. | CRITICAL 9.8EPSS 12.9% | 26 December 2023 |
| CVE-2023-51467 | The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code | CRITICAL 9.8EPSS 96.0% | 26 December 2023 |
| CVE-2023-50968 | Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. | HIGH 7.5EPSS 63.4% | 26 December 2023 |
| CVE-2022-34267 | Adding a token parameter with the value of 02 bypasses all authentication requirements. | CRITICAL 9.8EPSS 42.2% | 25 December 2023 |
| CVE-2023-7095 | A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. | CRITICAL 9.8EPSS 13.7% | 25 December 2023 |
| CVE-2023-7102 | Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. | CRITICAL 9.8EPSS 44.6% | 24 December 2023 |
| CVE-2023-7101 | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 19.1% | 24 December 2023 |
| CVE-2023-7002 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. | HIGH 7.2EPSS 30.6% | 23 December 2023 |
| CVE-2023-51449 | Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. | HIGH 7.5EPSS 28.3% | 22 December 2023 |
| CVE-2023-51448 | Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. | HIGH 8.8EPSS 67.3% | 22 December 2023 |
| CVE-2023-49085 | In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. | HIGH 8.8EPSS 74.3% | 22 December 2023 |
| CVE-2023-49084 | While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. | HIGH 8.8EPSS 64.2% | 21 December 2023 |
| CVE-2023-7039 | A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. | CRITICAL 9.8EPSS 14.2% | 21 December 2023 |
| CVE-2023-38126 | Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. | HIGH 7.2EPSS 71.2% | 19 December 2023 |
| CVE-2023-46264 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | CRITICAL 9.8EPSS 90.2% | 19 December 2023 |
| CVE-2023-46263 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution. | CRITICAL 9.8EPSS 81.9% | 19 December 2023 |
| CVE-2023-46262 | An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server. | HIGH 7.5EPSS 82.8% | 19 December 2023 |
| CVE-2023-46261 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 11.3% | 19 December 2023 |
| CVE-2023-46259 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 11.3% | 19 December 2023 |
| CVE-2023-46257 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 11.3% | 19 December 2023 |
| CVE-2023-46225 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 11.3% | 19 December 2023 |
| CVE-2023-46220 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 11.3% | 19 December 2023 |
| CVE-2023-46217 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 36.4% | 19 December 2023 |
| CVE-2023-46216 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 36.4% | 19 December 2023 |
| CVE-2023-41727 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CRITICAL 9.8EPSS 36.4% | 19 December 2023 |
| CVE-2021-22962 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | CRITICAL 9.1EPSS 91.0% | 19 December 2023 |
| CVE-2023-6856 | The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. | HIGH 8.8EPSS 20.6% | 19 December 2023 |
| CVE-2023-6065 | The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code | MEDIUM 5.3EPSS 18.6% | 18 December 2023 |
| CVE-2023-51385 | In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. | MEDIUM 6.5EPSS 19.8% | 18 December 2023 |
| CVE-2023-48795 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and… | MEDIUM 5.9EPSS 93.3% | 18 December 2023 |
| CVE-2023-6909 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. | HIGH 7.5EPSS 89.7% | 18 December 2023 |
| CVE-2023-6895 | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). | CRITICAL 9.8EPSS 89.1% | 17 December 2023 |
| CVE-2023-6893 | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. | HIGH 7.5EPSS 70.2% | 17 December 2023 |
| CVE-2023-50721 | Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax containing script macros… | HIGH 8.8EPSS 78.8% | 15 December 2023 |
| CVE-2023-50720 | Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. | MEDIUM 5.3EPSS 59.1% | 15 December 2023 |
| CVE-2023-50719 | Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. | HIGH 7.5EPSS 83.5% | 15 December 2023 |
| CVE-2023-50917 | MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. | CRITICAL 9.8EPSS 38.0% | 15 December 2023 |
| CVE-2023-6553 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. | CRITICAL 9.8EPSS 97.8% | 15 December 2023 |
| CVE-2023-6702 | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 43.8% | 14 December 2023 |
| CVE-2023-49294 | In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. | HIGH 7.5EPSS 45.6% | 14 December 2023 |
| CVE-2023-50269 | Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. | HIGH 7.5EPSS 57.6% | 14 December 2023 |
| CVE-2023-50564 | An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file. | HIGH 8.8EPSS 29.1% | 14 December 2023 |
| CVE-2022-45365 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2. | MEDIUM 6.1EPSS 48.9% | 14 December 2023 |
| CVE-2023-48085 | Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php. | CRITICAL 9.8EPSS 75.8% | 14 December 2023 |
| CVE-2023-48084 | Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. | CRITICAL 9.8EPSS 33.7% | 14 December 2023 |
| CVE-2023-31546 | Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature. | CRITICAL 9.6EPSS 49.4% | 14 December 2023 |
| CVE-2023-46727 | Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. | CRITICAL 9.8EPSS 67.7% | 13 December 2023 |
| CVE-2023-43813 | Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. | HIGH 8.8EPSS 30.9% | 13 December 2023 |
| CVE-2023-50252 | This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. | CRITICAL 9.8EPSS 23.9% | 12 December 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.