Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 41 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-36019 | Microsoft Power Platform Connector Spoofing Vulnerability | HIGH 7.4EPSS 15.8% | 12 December 2023 |
| CVE-2023-36005 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH 8.1EPSS 23.9% | 12 December 2023 |
| CVE-2023-35636 | Microsoft Outlook Information Disclosure Vulnerability | MEDIUM 6.5EPSS 17.7% | 12 December 2023 |
| CVE-2023-35628 | Windows MSHTML Platform Remote Code Execution Vulnerability | HIGH 8.1EPSS 92.8% | 12 December 2023 |
| CVE-2023-46456 | In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality. | CRITICAL 9.8EPSS 24.7% | 12 December 2023 |
| CVE-2023-46455 | In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality. | HIGH 7.5EPSS 47.0% | 12 December 2023 |
| CVE-2023-46454 | In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality. | CRITICAL 9.8EPSS 23.5% | 12 December 2023 |
| CVE-2023-49964 | By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). | HIGH 8.8EPSS 34.7% | 11 December 2023 |
| CVE-2023-6612 | A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. | CRITICAL 9.8EPSS 30.7% | 8 December 2023 |
| CVE-2023-47565 | QNAP VioStor NVR OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 73.3% | 8 December 2023 |
| CVE-2023-6579 | A vulnerability, which was classified as critical, has been found in osCommerce 4. | CRITICAL 9.8EPSS 24.0% | 7 December 2023 |
| CVE-2022-45362 | Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0. | MEDIUM 6.5EPSS 41.8% | 7 December 2023 |
| CVE-2023-50164 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. | CRITICAL 9.8EPSS 80.8% | 7 December 2023 |
| CVE-2023-48123 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file. | HIGH 8.8EPSS 67.8% | 6 December 2023 |
| CVE-2023-49897 | FXC AE1021, AE1021PE OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 50.4% | 6 December 2023 |
| CVE-2023-22524 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. | CRITICAL 9.8EPSS 24.7% | 6 December 2023 |
| CVE-2023-22523 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. | HIGH 8.8EPSS 11.1% | 6 December 2023 |
| CVE-2023-22522 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. | HIGH 8.8EPSS 12.8% | 6 December 2023 |
| CVE-2023-44221 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 76.3% | 5 December 2023 |
| CVE-2023-49070 | Pre-auth RCE in Apache Ofbiz 18.12.09. | CRITICAL 9.8EPSS 95.4% | 5 December 2023 |
| CVE-2023-43472 | An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API. | HIGH 7.5EPSS 36.6% | 5 December 2023 |
| CVE-2023-49286 | Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. | HIGH 7.5EPSS 10.4% | 4 December 2023 |
| CVE-2023-49285 | Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. | HIGH 7.5EPSS 88.1% | 4 December 2023 |
| CVE-2023-6063 | The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | HIGH 7.5EPSS 73.7% | 4 December 2023 |
| CVE-2023-42916 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | KEVMEDIUM 6.5EPSS 17.8% | 30 November 2023 |
| CVE-2023-47207 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges. | CRITICAL 9.8EPSS 16.6% | 30 November 2023 |
| CVE-2023-6360 | The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route. | CRITICAL 9.8EPSS 63.1% | 30 November 2023 |
| CVE-2023-47505 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4. | MEDIUM 5.4EPSS 25.3% | 30 November 2023 |
| CVE-2023-47464 | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function. | HIGH 8.8EPSS 22.6% | 30 November 2023 |
| CVE-2023-4474 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands… | CRITICAL 9.8EPSS 29.7% | 30 November 2023 |
| CVE-2023-4473 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a… | CRITICAL 9.8EPSS 41.3% | 30 November 2023 |
| CVE-2023-37928 | A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS)… | HIGH 8.8EPSS 60.2% | 30 November 2023 |
| CVE-2023-35138 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system… | CRITICAL 9.8EPSS 40.0% | 30 November 2023 |
| CVE-2023-6345 | Google Skia Integer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 16.5% | 29 November 2023 |
| CVE-2022-41678 | Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. | HIGH 8.8EPSS 85.8% | 28 November 2023 |
| CVE-2023-48023 | Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. | CRITICAL 9.1EPSS 35.3% | 28 November 2023 |
| CVE-2023-48022 | Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. | CRITICAL 9.8EPSS 83.9% | 28 November 2023 |
| CVE-2023-4220 | Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code… | MEDIUM 6.1EPSS 76.1% | 28 November 2023 |
| CVE-2023-3368 | Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. | CRITICAL 9.8EPSS 69.7% | 28 November 2023 |
| CVE-2023-6329 | An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. | CRITICAL 9.8EPSS 65.0% | 27 November 2023 |
| CVE-2023-4922 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter. | CRITICAL 9.8EPSS 15.7% | 27 November 2023 |
| CVE-2023-41998 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. | CRITICAL 9.8EPSS 15.3% | 27 November 2023 |
| CVE-2023-49043 | Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat. | CRITICAL 9.8EPSS 13.2% | 27 November 2023 |
| CVE-2023-48646 | Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings. | HIGH 7.2EPSS 82.2% | 22 November 2023 |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 43.2% | 21 November 2023 |
| CVE-2023-49103 | ownCloud graphapi Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 78.4% | 21 November 2023 |
| CVE-2023-5652 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL… | CRITICAL 9.8EPSS 63.7% | 20 November 2023 |
| CVE-2023-48292 | Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an attacker to execute arbitrary shell commands by tricking an admin into loading the URL… | HIGH 8.8EPSS 22.9% | 20 November 2023 |
| CVE-2023-48241 | Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all… | HIGH 7.5EPSS 72.8% | 20 November 2023 |
| CVE-2023-6187 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. | HIGH 8.8EPSS 51.3% | 18 November 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.