SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,488 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 42 of 348

CVESummaryPriorityPublished
CVE-2023-43177CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.CRITICAL 9.8EPSS 81.8%18 November 2023
CVE-2023-44355Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass.MEDIUM 4.3EPSS 47.2%17 November 2023
CVE-2023-44353Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.CRITICAL 9.8EPSS 80.2%17 November 2023
CVE-2023-44352Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability.MEDIUM 6.1EPSS 84.8%17 November 2023
CVE-2023-44351Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.CRITICAL 9.8EPSS 50.2%17 November 2023
CVE-2023-44350Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.CRITICAL 9.8EPSS 64.6%17 November 2023
CVE-2023-26347Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.HIGH 7.5EPSS 10.1%17 November 2023
CVE-2023-6020LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.HIGH 7.5EPSS 14.7%16 November 2023
CVE-2023-46214This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.HIGH 8.8EPSS 89.2%16 November 2023
CVE-2023-6021LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.HIGH 7.5EPSS 37.1%16 November 2023
CVE-2023-6019A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.CRITICAL 9.8EPSS 74.6%16 November 2023
CVE-2023-6018An attacker can overwrite any file on the server hosting MLflow without any authentication.CRITICAL 9.8EPSS 47.9%16 November 2023
CVE-2023-6016An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.CRITICAL 9.8EPSS 30.6%16 November 2023
CVE-2023-48365Qlik Sense HTTP Tunneling VulnerabilityKEVCRITICAL 9.9EPSS 24.5%15 November 2023
CVE-2023-6112Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 24.7%15 November 2023
CVE-2023-36049.NET, .NET Framework, and Visual Studio Elevation of Privilege VulnerabilityCRITICAL 9.8EPSS 12.5%14 November 2023
CVE-2023-36424Microsoft Windows Out-of-Bounds Read VulnerabilityKEVHIGH 7.8EPSS 12.2%14 November 2023
CVE-2023-36413Microsoft Office Security Feature Bypass VulnerabilityMEDIUM 6.5EPSS 30.0%14 November 2023
CVE-2023-36397Windows Pragmatic General Multicast (PGM) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 17.5%14 November 2023
CVE-2023-36052Azure CLI REST Command Information Disclosure VulnerabilityHIGH 8.6EPSS 21.1%14 November 2023
CVE-2023-36050Microsoft Exchange Server Spoofing VulnerabilityHIGH 8.0EPSS 39.2%14 November 2023
CVE-2023-36041Microsoft Excel Remote Code Execution VulnerabilityHIGH 7.8EPSS 56.7%14 November 2023
CVE-2023-36039Microsoft Exchange Server Spoofing VulnerabilityHIGH 8.0EPSS 73.0%14 November 2023
CVE-2023-36036Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 16.7%14 November 2023
CVE-2023-36035Microsoft Exchange Server Spoofing VulnerabilityHIGH 8.0EPSS 86.6%14 November 2023
CVE-2023-36033Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 12.0%14 November 2023
CVE-2023-36025Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 88.1%14 November 2023
CVE-2023-36017Windows Scripting Engine Memory Corruption VulnerabilityHIGH 8.8EPSS 25.3%14 November 2023
CVE-2023-34991A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute…CRITICAL 9.8EPSS 28.8%14 November 2023
CVE-2023-45878GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication.CRITICAL 9.8EPSS 63.1%14 November 2023
CVE-2023-42326An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.HIGH 8.8EPSS 64.0%14 November 2023
CVE-2023-42327Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.MEDIUM 5.4EPSS 55.4%14 November 2023
CVE-2023-42325Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.MEDIUM 5.4EPSS 57.9%14 November 2023
CVE-2022-45835Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.HIGH 7.5EPSS 37.7%13 November 2023
CVE-2023-47246SysAid Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 98.9%10 November 2023
CVE-2023-47248Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution.CRITICAL 9.8EPSS 14.5%9 November 2023
CVE-2023-4249Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of network requests.CRITICAL 9.8EPSS 12.9%8 November 2023
CVE-2023-3959Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows.CRITICAL 9.8EPSS 48.8%8 November 2023
CVE-2023-41425Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.MEDIUM 6.1EPSS 54.3%7 November 2023
CVE-2023-41723A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule.MEDIUM 4.3EPSS 12.3%7 November 2023
CVE-2023-38549A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.MEDIUM 5.4EPSS 19.1%7 November 2023
CVE-2023-38548A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.MEDIUM 4.3EPSS 11.8%7 November 2023
CVE-2023-38547A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database.CRITICAL 9.8EPSS 18.9%7 November 2023
CVE-2023-46731This allows any user with read access to the document `XWiki.AdminSheet` (by default, everyone including unauthenticated users) to execute code including Groovy code.CRITICAL 9.8EPSS 88.5%6 November 2023
CVE-2023-47253Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.CRITICAL 9.8EPSS 14.3%6 November 2023
CVE-2023-23369An OS command injection vulnerability has been reported to affect several QNAP operating system versions.CRITICAL 9.8EPSS 14.5%3 November 2023
CVE-2023-23368An OS command injection vulnerability has been reported to affect several QNAP operating system versions.CRITICAL 9.8EPSS 18.8%3 November 2023
CVE-2023-46848Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.HIGH 7.5EPSS 10.2%3 November 2023
CVE-2023-46847Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.HIGH 7.5EPSS 88.4%3 November 2023
CVE-2023-34260Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.HIGH 7.5EPSS 73.4%3 November 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.