SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,488 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 43 of 348

CVESummaryPriorityPublished
CVE-2023-34259Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges.MEDIUM 4.9EPSS 60.5%3 November 2023
CVE-2023-31102Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.HIGH 7.8EPSS 57.1%3 November 2023
CVE-2023-46695As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.HIGH 7.5EPSS 49.8%2 November 2023
CVE-2023-20048A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is…CRITICAL 9.9EPSS 15.8%1 November 2023
CVE-2023-1718Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".HIGH 7.5EPSS 24.1%1 November 2023
CVE-2023-4197Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.HIGH 8.8EPSS 32.8%1 November 2023
CVE-2023-3676A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes.HIGH 8.8EPSS 13.2%31 October 2023
CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityKEVCRITICAL 9.8EPSS 100.0%31 October 2023
CVE-2023-5360The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.CRITICAL 9.8EPSS 81.7%31 October 2023
CVE-2023-46865/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.HIGH 7.2EPSS 20.3%30 October 2023
CVE-2023-5830A vulnerability classified as critical has been found in ColumbiaSoft Document Locator.CRITICAL 9.8EPSS 60.8%27 October 2023
CVE-2023-46604Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 99.7%27 October 2023
CVE-2023-46818PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.HIGH 7.2EPSS 15.7%27 October 2023
CVE-2023-45498VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.CRITICAL 9.8EPSS 20.5%27 October 2023
CVE-2018-17879The CGI scripts allow remote attackers to execute code via system() as root.CRITICAL 9.8EPSS 21.9%26 October 2023
CVE-2023-46747F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 96.5%26 October 2023
CVE-2023-31419A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.HIGH 7.5EPSS 60.7%26 October 2023
CVE-2023-43208NextGen Healthcare Mirth Connect Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 82.7%26 October 2023
CVE-2023-5044Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.HIGH 8.8EPSS 56.6%25 October 2023
CVE-2023-46574An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.CRITICAL 9.8EPSS 65.4%25 October 2023
CVE-2023-46370Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.CRITICAL 9.8EPSS 18.1%25 October 2023
CVE-2023-46347In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection.CRITICAL 9.8EPSS 49.9%25 October 2023
CVE-2023-43795GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.CRITICAL 9.8EPSS 67.7%25 October 2023
CVE-2023-34048VMware vCenter Server Out-of-Bounds Write VulnerabilityKEVCRITICAL 9.8EPSS 99.4%25 October 2023
CVE-2023-20273Cisco IOS XE Web UI Command Injection VulnerabilityKEVHIGH 7.2EPSS 89.6%25 October 2023
CVE-2023-46127A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection.MEDIUM 5.4EPSS 37.0%23 October 2023
CVE-2023-43622An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server.HIGH 7.5EPSS 70.6%23 October 2023
CVE-2023-5702A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic.MEDIUM 6.5EPSS 14.5%23 October 2023
CVE-2023-5684A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012.CRITICAL 9.8EPSS 78.4%21 October 2023
CVE-2023-5683A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical.CRITICAL 9.8EPSS 18.0%21 October 2023
CVE-2023-34051VMware Aria Operations for Logs contains an authentication bypass vulnerability.CRITICAL 9.8EPSS 44.7%20 October 2023
CVE-2023-46042An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().CRITICAL 9.8EPSS 22.6%19 October 2023
CVE-2023-35180The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.HIGH 8.8EPSS 27.4%19 October 2023
CVE-2023-46229LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.HIGH 8.8EPSS 44.7%19 October 2023
CVE-2023-5642Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.CRITICAL 9.8EPSS 16.7%18 October 2023
CVE-2023-5631Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 5.4EPSS 75.9%18 October 2023
CVE-2023-38545This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.CRITICAL 9.8EPSS 78.5%18 October 2023
CVE-2023-39456Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.HIGH 7.5EPSS 53.8%17 October 2023
CVE-2023-44693D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.CRITICAL 9.8EPSS 13.3%17 October 2023
CVE-2023-45375In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().`HIGH 8.8EPSS 38.5%17 October 2023
CVE-2023-5003The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs.HIGH 7.5EPSS 25.9%16 October 2023
CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation VulnerabilityKEVCRITICAL 10.0EPSS 99.6%16 October 2023
CVE-2023-5591SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.MEDIUM 6.5EPSS 22.2%16 October 2023
CVE-2023-45852In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.CRITICAL 9.8EPSS 14.0%14 October 2023
CVE-2023-45138Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly.CRITICAL 9.6EPSS 71.2%12 October 2023
CVE-2023-43661Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version.HIGH 8.8EPSS 46.9%11 October 2023
CVE-2023-32645A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108.CRITICAL 9.8EPSS 53.8%11 October 2023
CVE-2023-41772Win32k Elevation of Privilege VulnerabilityHIGH 7.8EPSS 11.8%10 October 2023
CVE-2023-41763Microsoft Skype for Business Privilege Escalation VulnerabilityKEVMEDIUM 5.3EPSS 90.4%10 October 2023
CVE-2023-38171Microsoft QUIC Denial of Service VulnerabilityHIGH 7.5EPSS 69.7%10 October 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.