Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,488 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 43 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-34259 | Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. | MEDIUM 4.9EPSS 60.5% | 3 November 2023 |
| CVE-2023-31102 | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | HIGH 7.8EPSS 57.1% | 3 November 2023 |
| CVE-2023-46695 | As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters. | HIGH 7.5EPSS 49.8% | 2 November 2023 |
| CVE-2023-20048 | A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is… | CRITICAL 9.9EPSS 15.8% | 1 November 2023 |
| CVE-2023-1718 | Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url". | HIGH 7.5EPSS 24.1% | 1 November 2023 |
| CVE-2023-4197 | Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. | HIGH 8.8EPSS 32.8% | 1 November 2023 |
| CVE-2023-3676 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. | HIGH 8.8EPSS 13.2% | 31 October 2023 |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 31 October 2023 |
| CVE-2023-5360 | The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE. | CRITICAL 9.8EPSS 81.7% | 31 October 2023 |
| CVE-2023-46865 | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image. | HIGH 7.2EPSS 20.3% | 30 October 2023 |
| CVE-2023-5830 | A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. | CRITICAL 9.8EPSS 60.8% | 27 October 2023 |
| CVE-2023-46604 | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 27 October 2023 |
| CVE-2023-46818 | PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled. | HIGH 7.2EPSS 15.7% | 27 October 2023 |
| CVE-2023-45498 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. | CRITICAL 9.8EPSS 20.5% | 27 October 2023 |
| CVE-2018-17879 | The CGI scripts allow remote attackers to execute code via system() as root. | CRITICAL 9.8EPSS 21.9% | 26 October 2023 |
| CVE-2023-46747 | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 96.5% | 26 October 2023 |
| CVE-2023-31419 | A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. | HIGH 7.5EPSS 60.7% | 26 October 2023 |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 82.7% | 26 October 2023 |
| CVE-2023-5044 | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | HIGH 8.8EPSS 56.6% | 25 October 2023 |
| CVE-2023-46574 | An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function. | CRITICAL 9.8EPSS 65.4% | 25 October 2023 |
| CVE-2023-46370 | Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function. | CRITICAL 9.8EPSS 18.1% | 25 October 2023 |
| CVE-2023-46347 | In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. | CRITICAL 9.8EPSS 49.9% | 25 October 2023 |
| CVE-2023-43795 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | CRITICAL 9.8EPSS 67.7% | 25 October 2023 |
| CVE-2023-34048 | VMware vCenter Server Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 25 October 2023 |
| CVE-2023-20273 | Cisco IOS XE Web UI Command Injection Vulnerability | KEVHIGH 7.2EPSS 89.6% | 25 October 2023 |
| CVE-2023-46127 | A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. | MEDIUM 5.4EPSS 37.0% | 23 October 2023 |
| CVE-2023-43622 | An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. | HIGH 7.5EPSS 70.6% | 23 October 2023 |
| CVE-2023-5702 | A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. | MEDIUM 6.5EPSS 14.5% | 23 October 2023 |
| CVE-2023-5684 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. | CRITICAL 9.8EPSS 78.4% | 21 October 2023 |
| CVE-2023-5683 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. | CRITICAL 9.8EPSS 18.0% | 21 October 2023 |
| CVE-2023-34051 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. | CRITICAL 9.8EPSS 44.7% | 20 October 2023 |
| CVE-2023-46042 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo(). | CRITICAL 9.8EPSS 22.6% | 19 October 2023 |
| CVE-2023-35180 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. | HIGH 8.8EPSS 27.4% | 19 October 2023 |
| CVE-2023-46229 | LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server. | HIGH 8.8EPSS 44.7% | 19 October 2023 |
| CVE-2023-5642 | Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information. | CRITICAL 9.8EPSS 16.7% | 18 October 2023 |
| CVE-2023-5631 | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 5.4EPSS 75.9% | 18 October 2023 |
| CVE-2023-38545 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. | CRITICAL 9.8EPSS 78.5% | 18 October 2023 |
| CVE-2023-39456 | Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. | HIGH 7.5EPSS 53.8% | 17 October 2023 |
| CVE-2023-44693 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. | CRITICAL 9.8EPSS 13.3% | 17 October 2023 |
| CVE-2023-45375 | In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().` | HIGH 8.8EPSS 38.5% | 17 October 2023 |
| CVE-2023-5003 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. | HIGH 7.5EPSS 25.9% | 16 October 2023 |
| CVE-2023-20198 | Cisco IOS XE Web UI Privilege Escalation Vulnerability | KEVCRITICAL 10.0EPSS 99.6% | 16 October 2023 |
| CVE-2023-5591 | SQL Injection in GitHub repository librenms/librenms prior to 23.10.0. | MEDIUM 6.5EPSS 22.2% | 16 October 2023 |
| CVE-2023-45852 | In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method. | CRITICAL 9.8EPSS 14.0% | 14 October 2023 |
| CVE-2023-45138 | Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. | CRITICAL 9.6EPSS 71.2% | 12 October 2023 |
| CVE-2023-43661 | Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. | HIGH 8.8EPSS 46.9% | 11 October 2023 |
| CVE-2023-32645 | A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. | CRITICAL 9.8EPSS 53.8% | 11 October 2023 |
| CVE-2023-41772 | Win32k Elevation of Privilege Vulnerability | HIGH 7.8EPSS 11.8% | 10 October 2023 |
| CVE-2023-41763 | Microsoft Skype for Business Privilege Escalation Vulnerability | KEVMEDIUM 5.3EPSS 90.4% | 10 October 2023 |
| CVE-2023-38171 | Microsoft QUIC Denial of Service Vulnerability | HIGH 7.5EPSS 69.7% | 10 October 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.