Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,488 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 44 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-36606 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH 7.5EPSS 67.2% | 10 October 2023 |
| CVE-2023-36594 | Windows Graphics Component Elevation of Privilege Vulnerability | HIGH 7.8EPSS 11.6% | 10 October 2023 |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 20.7% | 10 October 2023 |
| CVE-2023-34993 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http… | CRITICAL 9.8EPSS 18.1% | 10 October 2023 |
| CVE-2023-34992 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests. | CRITICAL 9.8EPSS 79.9% | 10 October 2023 |
| CVE-2023-5494 | A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical. | HIGH 8.8EPSS 14.8% | 10 October 2023 |
| CVE-2023-30806 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. | CRITICAL 9.8EPSS 65.8% | 10 October 2023 |
| CVE-2023-30805 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. | CRITICAL 9.8EPSS 65.8% | 10 October 2023 |
| CVE-2023-30804 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. | MEDIUM 6.5EPSS 12.8% | 10 October 2023 |
| CVE-2023-30803 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. | CRITICAL 9.8EPSS 18.2% | 10 October 2023 |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-44487 | HTTP/2 Rapid Reset Attack Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-44959 | An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page. | HIGH 8.8EPSS 20.5% | 10 October 2023 |
| CVE-2023-43641 | Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. | HIGH 8.8EPSS 16.6% | 9 October 2023 |
| CVE-2023-45363 | It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set. | HIGH 7.5EPSS 22.7% | 9 October 2023 |
| CVE-2023-44860 | An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request. | HIGH 7.5EPSS 19.5% | 6 October 2023 |
| CVE-2023-5399 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command. | CRITICAL 9.8EPSS 38.5% | 4 October 2023 |
| CVE-2023-27121 | A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… | MEDIUM 6.1EPSS 21.3% | 4 October 2023 |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 4 October 2023 |
| CVE-2023-43261 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | HIGH 7.5EPSS 59.6% | 4 October 2023 |
| CVE-2023-5375 | Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2. | MEDIUM 6.1EPSS 35.1% | 4 October 2023 |
| CVE-2023-44974 | An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | CRITICAL 9.8EPSS 19.1% | 3 October 2023 |
| CVE-2023-4911 | GNU C Library Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 81.4% | 3 October 2023 |
| CVE-2023-5322 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. | HIGH 8.8EPSS 16.7% | 1 October 2023 |
| CVE-2023-44466 | There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. | HIGH 8.8EPSS 45.3% | 29 September 2023 |
| CVE-2023-30591 | Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object… | HIGH 7.5EPSS 53.8% | 29 September 2023 |
| CVE-2023-43654 | TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. | CRITICAL 9.8EPSS 35.5% | 28 September 2023 |
| CVE-2023-5217 | Google Chromium libvpx Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 49.0% | 28 September 2023 |
| CVE-2023-38874 | A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). | HIGH 8.8EPSS 28.5% | 28 September 2023 |
| CVE-2023-5222 | A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. | CRITICAL 9.8EPSS 74.5% | 27 September 2023 |
| CVE-2023-44018 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function. | CRITICAL 9.8EPSS 15.4% | 27 September 2023 |
| CVE-2023-43187 | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests. | CRITICAL 9.8EPSS 45.4% | 27 September 2023 |
| CVE-2023-42657 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. | CRITICAL 9.6EPSS 17.0% | 27 September 2023 |
| CVE-2023-41326 | There are no known workarounds for this vulnerability. | HIGH 8.8EPSS 31.2% | 27 September 2023 |
| CVE-2023-41323 | There are no known workarounds for this vulnerability. | MEDIUM 5.3EPSS 33.9% | 27 September 2023 |
| CVE-2023-41320 | UI layout preferences management can be hijacked to lead to SQL injection. | CRITICAL 9.8EPSS 31.9% | 27 September 2023 |
| CVE-2023-40044 | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 90.1% | 27 September 2023 |
| CVE-2023-4521 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. | CRITICAL 9.8EPSS 40.6% | 25 September 2023 |
| CVE-2023-5154 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. | HIGH 8.8EPSS 15.1% | 25 September 2023 |
| CVE-2023-5151 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231. | HIGH 8.8EPSS 81.5% | 25 September 2023 |
| CVE-2023-5150 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. | HIGH 8.8EPSS 22.8% | 25 September 2023 |
| CVE-2023-5149 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. | HIGH 8.8EPSS 21.0% | 25 September 2023 |
| CVE-2023-5148 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. | HIGH 8.8EPSS 30.7% | 25 September 2023 |
| CVE-2023-5147 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. | HIGH 8.8EPSS 26.6% | 25 September 2023 |
| CVE-2023-5146 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical. | HIGH 8.8EPSS 32.9% | 25 September 2023 |
| CVE-2023-5145 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000 up to 20151231 and classified as critical. | HIGH 8.8EPSS 34.3% | 25 September 2023 |
| CVE-2023-43770 | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 58.5% | 22 September 2023 |
| CVE-2023-31719 | FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. | CRITICAL 9.8EPSS 27.2% | 22 September 2023 |
| CVE-2023-41993 | Apple Multiple Products WebKit Code Execution Vulnerability | KEVHIGH 8.8EPSS 29.2% | 21 September 2023 |
| CVE-2023-43240 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter. | CRITICAL 9.8EPSS 12.2% | 21 September 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.