SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,488 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 45 of 348

CVESummaryPriorityPublished
CVE-2023-43239D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.CRITICAL 9.8EPSS 12.2%21 September 2023
CVE-2023-43237D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.CRITICAL 9.8EPSS 12.2%21 September 2023
CVE-2023-39677MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.HIGH 7.5EPSS 32.1%20 September 2023
CVE-2023-5074Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28CRITICAL 9.8EPSS 67.9%20 September 2023
CVE-2023-43478fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on…CRITICAL 9.8EPSS 17.4%20 September 2023
CVE-2023-43477The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to…HIGH 8.8EPSS 15.7%20 September 2023
CVE-2023-38886An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.HIGH 7.2EPSS 28.7%20 September 2023
CVE-2023-40931A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.phpMEDIUM 6.5EPSS 11.3%19 September 2023
CVE-2023-42793JetBrains TeamCity Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%19 September 2023
CVE-2023-22513This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server.HIGH 8.8EPSS 14.3%19 September 2023
CVE-2023-41599An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.MEDIUM 5.3EPSS 11.2%19 September 2023
CVE-2023-33831A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.CRITICAL 9.8EPSS 22.7%18 September 2023
CVE-2023-42442SessionViewSet permission classes set to `[RBACPermission | IsSessionAssignee]`, relation is or, so any permission matched will be allowed.MEDIUM 5.3EPSS 55.9%15 September 2023
CVE-2023-41887Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server.CRITICAL 9.8EPSS 42.5%15 September 2023
CVE-2023-38039However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.HIGH 7.5EPSS 58.1%15 September 2023
CVE-2023-38205Adobe ColdFusion Improper Access Control VulnerabilityKEVHIGH 7.5EPSS 99.7%14 September 2023
CVE-2023-38204Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution.CRITICAL 9.8EPSS 66.8%14 September 2023
CVE-2023-41892Craft CMS is a platform for creating digital experiences.CRITICAL 9.8EPSS 94.2%13 September 2023
CVE-2023-3710Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004.CRITICAL 9.8EPSS 49.0%12 September 2023
CVE-2023-38162DHCP Server Service Denial of Service VulnerabilityHIGH 7.5EPSS 10.7%12 September 2023
CVE-2023-38152DHCP Server Service Information Disclosure VulnerabilityMEDIUM 5.3EPSS 25.8%12 September 2023
CVE-2023-38146Windows Themes Remote Code Execution VulnerabilityHIGH 8.8EPSS 39.2%12 September 2023
CVE-2023-36802Microsoft Streaming Service Proxy Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 27.9%12 September 2023
CVE-2023-36777Microsoft Exchange Server Information Disclosure VulnerabilityMEDIUM 5.7EPSS 52.0%12 September 2023
CVE-2023-36761Microsoft Word Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 19.6%12 September 2023
CVE-2023-36757Microsoft Exchange Server Spoofing VulnerabilityHIGH 8.0EPSS 36.9%12 September 2023
CVE-2023-36756Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.0EPSS 49.2%12 September 2023
CVE-2023-36745Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.0EPSS 79.3%12 September 2023
CVE-2023-36744Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.0EPSS 62.3%12 September 2023
CVE-2023-4863Google Chromium WebP Heap-Based Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 100.0%12 September 2023
CVE-2023-2071Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.CRITICAL 9.8EPSS 17.3%12 September 2023
CVE-2023-39780ASUS RT-AX55 Routers OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 40.2%11 September 2023
CVE-2023-38743Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.HIGH 7.2EPSS 11.1%11 September 2023
CVE-2023-4873A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906.CRITICAL 9.8EPSS 22.1%10 September 2023
CVE-2023-39584Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.HIGH 7.5EPSS 34.5%8 September 2023
CVE-2023-4528Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interfaceHIGH 7.2EPSS 31.9%7 September 2023
CVE-2023-41064Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 45.1%7 September 2023
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityKEVCRITICAL 9.1EPSS 25.5%6 September 2023
CVE-2023-20238A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an…CRITICAL 9.8EPSS 16.3%6 September 2023
CVE-2023-39265Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports.MEDIUM 6.5EPSS 86.2%6 September 2023
CVE-2023-37941If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend.MEDIUM 6.6EPSS 35.5%6 September 2023
CVE-2023-4634The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09.CRITICAL 9.8EPSS 85.9%6 September 2023
CVE-2023-35719ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability.MEDIUM 6.8EPSS 26.4%6 September 2023
CVE-2023-4762Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 41.1%5 September 2023
CVE-2023-39362In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.HIGH 7.2EPSS 85.3%5 September 2023
CVE-2023-39361Affected versions are subject to a SQL injection discovered in graph_view.php.CRITICAL 9.8EPSS 88.8%5 September 2023
CVE-2023-4708A vulnerability was found in Infosoftbd Clcknshop 1.0.0.CRITICAL 9.8EPSS 31.2%1 September 2023
CVE-2023-4481An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).HIGH 7.5EPSS 18.2%1 September 2023
CVE-2023-4596The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6.CRITICAL 9.8EPSS 14.3%30 August 2023
CVE-2023-41266Qlik Sense Path Traversal VulnerabilityKEVMEDIUM 6.5EPSS 84.8%29 August 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.