Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,488 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 45 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-43239 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC. | CRITICAL 9.8EPSS 12.2% | 21 September 2023 |
| CVE-2023-43237 | D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC. | CRITICAL 9.8EPSS 12.2% | 21 September 2023 |
| CVE-2023-39677 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | HIGH 7.5EPSS 32.1% | 20 September 2023 |
| CVE-2023-5074 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 | CRITICAL 9.8EPSS 67.9% | 20 September 2023 |
| CVE-2023-43478 | fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on… | CRITICAL 9.8EPSS 17.4% | 20 September 2023 |
| CVE-2023-43477 | The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to… | HIGH 8.8EPSS 15.7% | 20 September 2023 |
| CVE-2023-38886 | An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | HIGH 7.2EPSS 28.7% | 20 September 2023 |
| CVE-2023-40931 | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | MEDIUM 6.5EPSS 11.3% | 19 September 2023 |
| CVE-2023-42793 | JetBrains TeamCity Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 19 September 2023 |
| CVE-2023-22513 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. | HIGH 8.8EPSS 14.3% | 19 September 2023 |
| CVE-2023-41599 | An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. | MEDIUM 5.3EPSS 11.2% | 19 September 2023 |
| CVE-2023-33831 | A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request. | CRITICAL 9.8EPSS 22.7% | 18 September 2023 |
| CVE-2023-42442 | SessionViewSet permission classes set to `[RBACPermission | IsSessionAssignee]`, relation is or, so any permission matched will be allowed. | MEDIUM 5.3EPSS 55.9% | 15 September 2023 |
| CVE-2023-41887 | Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. | CRITICAL 9.8EPSS 42.5% | 15 September 2023 |
| CVE-2023-38039 | However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory. | HIGH 7.5EPSS 58.1% | 15 September 2023 |
| CVE-2023-38205 | Adobe ColdFusion Improper Access Control Vulnerability | KEVHIGH 7.5EPSS 99.7% | 14 September 2023 |
| CVE-2023-38204 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. | CRITICAL 9.8EPSS 66.8% | 14 September 2023 |
| CVE-2023-41892 | Craft CMS is a platform for creating digital experiences. | CRITICAL 9.8EPSS 94.2% | 13 September 2023 |
| CVE-2023-3710 | Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. | CRITICAL 9.8EPSS 49.0% | 12 September 2023 |
| CVE-2023-38162 | DHCP Server Service Denial of Service Vulnerability | HIGH 7.5EPSS 10.7% | 12 September 2023 |
| CVE-2023-38152 | DHCP Server Service Information Disclosure Vulnerability | MEDIUM 5.3EPSS 25.8% | 12 September 2023 |
| CVE-2023-38146 | Windows Themes Remote Code Execution Vulnerability | HIGH 8.8EPSS 39.2% | 12 September 2023 |
| CVE-2023-36802 | Microsoft Streaming Service Proxy Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 27.9% | 12 September 2023 |
| CVE-2023-36777 | Microsoft Exchange Server Information Disclosure Vulnerability | MEDIUM 5.7EPSS 52.0% | 12 September 2023 |
| CVE-2023-36761 | Microsoft Word Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 19.6% | 12 September 2023 |
| CVE-2023-36757 | Microsoft Exchange Server Spoofing Vulnerability | HIGH 8.0EPSS 36.9% | 12 September 2023 |
| CVE-2023-36756 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.0EPSS 49.2% | 12 September 2023 |
| CVE-2023-36745 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.0EPSS 79.3% | 12 September 2023 |
| CVE-2023-36744 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.0EPSS 62.3% | 12 September 2023 |
| CVE-2023-4863 | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 100.0% | 12 September 2023 |
| CVE-2023-2071 | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. | CRITICAL 9.8EPSS 17.3% | 12 September 2023 |
| CVE-2023-39780 | ASUS RT-AX55 Routers OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 40.2% | 11 September 2023 |
| CVE-2023-38743 | Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine. | HIGH 7.2EPSS 11.1% | 11 September 2023 |
| CVE-2023-4873 | A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. | CRITICAL 9.8EPSS 22.1% | 10 September 2023 |
| CVE-2023-39584 | Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. | HIGH 7.5EPSS 34.5% | 8 September 2023 |
| CVE-2023-4528 | Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface | HIGH 7.2EPSS 31.9% | 7 September 2023 |
| CVE-2023-41064 | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 45.1% | 7 September 2023 |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | KEVCRITICAL 9.1EPSS 25.5% | 6 September 2023 |
| CVE-2023-20238 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an… | CRITICAL 9.8EPSS 16.3% | 6 September 2023 |
| CVE-2023-39265 | Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. | MEDIUM 6.5EPSS 86.2% | 6 September 2023 |
| CVE-2023-37941 | If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. | MEDIUM 6.6EPSS 35.5% | 6 September 2023 |
| CVE-2023-4634 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. | CRITICAL 9.8EPSS 85.9% | 6 September 2023 |
| CVE-2023-35719 | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. | MEDIUM 6.8EPSS 26.4% | 6 September 2023 |
| CVE-2023-4762 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 41.1% | 5 September 2023 |
| CVE-2023-39362 | In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. | HIGH 7.2EPSS 85.3% | 5 September 2023 |
| CVE-2023-39361 | Affected versions are subject to a SQL injection discovered in graph_view.php. | CRITICAL 9.8EPSS 88.8% | 5 September 2023 |
| CVE-2023-4708 | A vulnerability was found in Infosoftbd Clcknshop 1.0.0. | CRITICAL 9.8EPSS 31.2% | 1 September 2023 |
| CVE-2023-4481 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). | HIGH 7.5EPSS 18.2% | 1 September 2023 |
| CVE-2023-4596 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. | CRITICAL 9.8EPSS 14.3% | 30 August 2023 |
| CVE-2023-41266 | Qlik Sense Path Traversal Vulnerability | KEVMEDIUM 6.5EPSS 84.8% | 29 August 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.