SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,488 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 44 of 348

CVESummaryPriorityPublished
CVE-2023-36606Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityHIGH 7.5EPSS 67.2%10 October 2023
CVE-2023-36594Windows Graphics Component Elevation of Privilege VulnerabilityHIGH 7.8EPSS 11.6%10 October 2023
CVE-2023-36563Microsoft WordPad Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 20.7%10 October 2023
CVE-2023-34993A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http…CRITICAL 9.8EPSS 18.1%10 October 2023
CVE-2023-34992A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.CRITICAL 9.8EPSS 79.9%10 October 2023
CVE-2023-5494A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical.HIGH 8.8EPSS 14.8%10 October 2023
CVE-2023-30806The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability.CRITICAL 9.8EPSS 65.8%10 October 2023
CVE-2023-30805The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability.CRITICAL 9.8EPSS 65.8%10 October 2023
CVE-2023-30804The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability.MEDIUM 6.5EPSS 12.8%10 October 2023
CVE-2023-30803The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability.CRITICAL 9.8EPSS 18.2%10 October 2023
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-44487HTTP/2 Rapid Reset Attack VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-44959An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.HIGH 8.8EPSS 20.5%10 October 2023
CVE-2023-43641Versions 2.2.1 and prior are vulnerable to out-of-bounds array access.HIGH 8.8EPSS 16.6%9 October 2023
CVE-2023-45363It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.HIGH 7.5EPSS 22.7%9 October 2023
CVE-2023-44860An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.HIGH 7.5EPSS 19.5%6 October 2023
CVE-2023-5399A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.CRITICAL 9.8EPSS 38.5%4 October 2023
CVE-2023-27121A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…MEDIUM 6.1EPSS 21.3%4 October 2023
CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityKEVCRITICAL 9.8EPSS 99.2%4 October 2023
CVE-2023-43261An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.HIGH 7.5EPSS 59.6%4 October 2023
CVE-2023-5375Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.MEDIUM 6.1EPSS 35.1%4 October 2023
CVE-2023-44974An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.CRITICAL 9.8EPSS 19.1%3 October 2023
CVE-2023-4911GNU C Library Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 81.4%3 October 2023
CVE-2023-5322** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231.HIGH 8.8EPSS 16.7%1 October 2023
CVE-2023-44466There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames.HIGH 8.8EPSS 45.3%29 September 2023
CVE-2023-30591Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object…HIGH 7.5EPSS 53.8%29 September 2023
CVE-2023-43654TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk.CRITICAL 9.8EPSS 35.5%28 September 2023
CVE-2023-5217Google Chromium libvpx Heap Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 49.0%28 September 2023
CVE-2023-38874A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023).HIGH 8.8EPSS 28.5%28 September 2023
CVE-2023-5222A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0.CRITICAL 9.8EPSS 74.5%27 September 2023
CVE-2023-44018Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.CRITICAL 9.8EPSS 15.4%27 September 2023
CVE-2023-43187A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.CRITICAL 9.8EPSS 45.4%27 September 2023
CVE-2023-42657In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.CRITICAL 9.6EPSS 17.0%27 September 2023
CVE-2023-41326There are no known workarounds for this vulnerability.HIGH 8.8EPSS 31.2%27 September 2023
CVE-2023-41323There are no known workarounds for this vulnerability.MEDIUM 5.3EPSS 33.9%27 September 2023
CVE-2023-41320UI layout preferences management can be hijacked to lead to SQL injection.CRITICAL 9.8EPSS 31.9%27 September 2023
CVE-2023-40044Progress WS_FTP Server Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 90.1%27 September 2023
CVE-2023-4521The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE.CRITICAL 9.8EPSS 40.6%25 September 2023
CVE-2023-5154** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical.HIGH 8.8EPSS 15.1%25 September 2023
CVE-2023-5151** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231.HIGH 8.8EPSS 81.5%25 September 2023
CVE-2023-5150** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231.HIGH 8.8EPSS 22.8%25 September 2023
CVE-2023-5149** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231.HIGH 8.8EPSS 21.0%25 September 2023
CVE-2023-5148** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231.HIGH 8.8EPSS 30.7%25 September 2023
CVE-2023-5147** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231.HIGH 8.8EPSS 26.6%25 September 2023
CVE-2023-5146** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical.HIGH 8.8EPSS 32.9%25 September 2023
CVE-2023-5145** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000 up to 20151231 and classified as critical.HIGH 8.8EPSS 34.3%25 September 2023
CVE-2023-43770Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 58.5%22 September 2023
CVE-2023-31719FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.CRITICAL 9.8EPSS 27.2%22 September 2023
CVE-2023-41993Apple Multiple Products WebKit Code Execution VulnerabilityKEVHIGH 8.8EPSS 29.2%21 September 2023
CVE-2023-43240D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.CRITICAL 9.8EPSS 12.2%21 September 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.