Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,488 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 42 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-43177 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | CRITICAL 9.8EPSS 81.8% | 18 November 2023 |
| CVE-2023-44355 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. | MEDIUM 4.3EPSS 47.2% | 17 November 2023 |
| CVE-2023-44353 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | CRITICAL 9.8EPSS 80.2% | 17 November 2023 |
| CVE-2023-44352 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | MEDIUM 6.1EPSS 84.8% | 17 November 2023 |
| CVE-2023-44351 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | CRITICAL 9.8EPSS 50.2% | 17 November 2023 |
| CVE-2023-44350 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | CRITICAL 9.8EPSS 64.6% | 17 November 2023 |
| CVE-2023-26347 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | HIGH 7.5EPSS 10.1% | 17 November 2023 |
| CVE-2023-6020 | LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. | HIGH 7.5EPSS 14.7% | 16 November 2023 |
| CVE-2023-46214 | This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance. | HIGH 8.8EPSS 89.2% | 16 November 2023 |
| CVE-2023-6021 | LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. | HIGH 7.5EPSS 37.1% | 16 November 2023 |
| CVE-2023-6019 | A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. | CRITICAL 9.8EPSS 74.6% | 16 November 2023 |
| CVE-2023-6018 | An attacker can overwrite any file on the server hosting MLflow without any authentication. | CRITICAL 9.8EPSS 47.9% | 16 November 2023 |
| CVE-2023-6016 | An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature. | CRITICAL 9.8EPSS 30.6% | 16 November 2023 |
| CVE-2023-48365 | Qlik Sense HTTP Tunneling Vulnerability | KEVCRITICAL 9.9EPSS 24.5% | 15 November 2023 |
| CVE-2023-6112 | Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 24.7% | 15 November 2023 |
| CVE-2023-36049 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | CRITICAL 9.8EPSS 12.5% | 14 November 2023 |
| CVE-2023-36424 | Microsoft Windows Out-of-Bounds Read Vulnerability | KEVHIGH 7.8EPSS 12.2% | 14 November 2023 |
| CVE-2023-36413 | Microsoft Office Security Feature Bypass Vulnerability | MEDIUM 6.5EPSS 30.0% | 14 November 2023 |
| CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 17.5% | 14 November 2023 |
| CVE-2023-36052 | Azure CLI REST Command Information Disclosure Vulnerability | HIGH 8.6EPSS 21.1% | 14 November 2023 |
| CVE-2023-36050 | Microsoft Exchange Server Spoofing Vulnerability | HIGH 8.0EPSS 39.2% | 14 November 2023 |
| CVE-2023-36041 | Microsoft Excel Remote Code Execution Vulnerability | HIGH 7.8EPSS 56.7% | 14 November 2023 |
| CVE-2023-36039 | Microsoft Exchange Server Spoofing Vulnerability | HIGH 8.0EPSS 73.0% | 14 November 2023 |
| CVE-2023-36036 | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 16.7% | 14 November 2023 |
| CVE-2023-36035 | Microsoft Exchange Server Spoofing Vulnerability | HIGH 8.0EPSS 86.6% | 14 November 2023 |
| CVE-2023-36033 | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 12.0% | 14 November 2023 |
| CVE-2023-36025 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 88.1% | 14 November 2023 |
| CVE-2023-36017 | Windows Scripting Engine Memory Corruption Vulnerability | HIGH 8.8EPSS 25.3% | 14 November 2023 |
| CVE-2023-34991 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute… | CRITICAL 9.8EPSS 28.8% | 14 November 2023 |
| CVE-2023-45878 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. | CRITICAL 9.8EPSS 63.1% | 14 November 2023 |
| CVE-2023-42326 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | HIGH 8.8EPSS 64.0% | 14 November 2023 |
| CVE-2023-42327 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | MEDIUM 5.4EPSS 55.4% | 14 November 2023 |
| CVE-2023-42325 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | MEDIUM 5.4EPSS 57.9% | 14 November 2023 |
| CVE-2022-45835 | Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15. | HIGH 7.5EPSS 37.7% | 13 November 2023 |
| CVE-2023-47246 | SysAid Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 10 November 2023 |
| CVE-2023-47248 | Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. | CRITICAL 9.8EPSS 14.5% | 9 November 2023 |
| CVE-2023-4249 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of network requests. | CRITICAL 9.8EPSS 12.9% | 8 November 2023 |
| CVE-2023-3959 | Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. | CRITICAL 9.8EPSS 48.8% | 8 November 2023 |
| CVE-2023-41425 | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component. | MEDIUM 6.1EPSS 54.3% | 7 November 2023 |
| CVE-2023-41723 | A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. | MEDIUM 4.3EPSS 12.3% | 7 November 2023 |
| CVE-2023-38549 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. | MEDIUM 5.4EPSS 19.1% | 7 November 2023 |
| CVE-2023-38548 | A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. | MEDIUM 4.3EPSS 11.8% | 7 November 2023 |
| CVE-2023-38547 | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. | CRITICAL 9.8EPSS 18.9% | 7 November 2023 |
| CVE-2023-46731 | This allows any user with read access to the document `XWiki.AdminSheet` (by default, everyone including unauthenticated users) to execute code including Groovy code. | CRITICAL 9.8EPSS 88.5% | 6 November 2023 |
| CVE-2023-47253 | Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter. | CRITICAL 9.8EPSS 14.3% | 6 November 2023 |
| CVE-2023-23369 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. | CRITICAL 9.8EPSS 14.5% | 3 November 2023 |
| CVE-2023-23368 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. | CRITICAL 9.8EPSS 18.8% | 3 November 2023 |
| CVE-2023-46848 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. | HIGH 7.5EPSS 10.2% | 3 November 2023 |
| CVE-2023-46847 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. | HIGH 7.5EPSS 88.4% | 3 November 2023 |
| CVE-2023-34260 | Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory. | HIGH 7.5EPSS 73.4% | 3 November 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.