Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 46 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-41265 | Qlik Sense HTTP Tunneling Vulnerability | KEVCRITICAL 9.9EPSS 88.2% | 29 August 2023 |
| CVE-2023-34039 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. | CRITICAL 9.8EPSS 67.2% | 29 August 2023 |
| CVE-2023-20890 | Aria Operations for Networks contains an arbitrary file write vulnerability. | HIGH 7.2EPSS 20.2% | 29 August 2023 |
| CVE-2023-40787 | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | CRITICAL 9.8EPSS 18.2% | 29 August 2023 |
| CVE-2023-41109 | SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection. | CRITICAL 9.8EPSS 64.5% | 28 August 2023 |
| CVE-2023-4548 | A vulnerability classified as critical has been found in SPA-Cart eCommerce CMS 1.9.0.3. | CRITICAL 9.8EPSS 27.9% | 26 August 2023 |
| CVE-2023-4547 | A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. | MEDIUM 6.1EPSS 61.3% | 26 August 2023 |
| CVE-2023-4542 | A vulnerability was found in D-Link DAR-8000-10 up to 20230809. | CRITICAL 9.8EPSS 86.0% | 25 August 2023 |
| CVE-2023-41249 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | MEDIUM 6.1EPSS 55.5% | 25 August 2023 |
| CVE-2023-40176 | Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. | MEDIUM 5.4EPSS 80.0% | 23 August 2023 |
| CVE-2023-38831 | RARLAB WinRAR Code Execution Vulnerability | KEVHIGH 7.8EPSS 98.0% | 23 August 2023 |
| CVE-2023-4428 | Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | HIGH 8.1EPSS 11.3% | 23 August 2023 |
| CVE-2023-4427 | Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | HIGH 8.1EPSS 35.0% | 23 August 2023 |
| CVE-2023-39026 | Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component. | HIGH 7.5EPSS 17.9% | 22 August 2023 |
| CVE-2023-38836 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | HIGH 8.8EPSS 76.0% | 21 August 2023 |
| CVE-2023-38035 | Ivanti Sentry Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 21 August 2023 |
| CVE-2023-4450 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. | CRITICAL 9.8EPSS 11.5% | 21 August 2023 |
| CVE-2023-39750 | D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. | CRITICAL 9.8EPSS 14.1% | 21 August 2023 |
| CVE-2022-24989 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. | CRITICAL 9.8EPSS 31.9% | 20 August 2023 |
| CVE-2023-4415 | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. | HIGH 8.8EPSS 58.3% | 18 August 2023 |
| CVE-2023-36847 | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | KEVMEDIUM 5.3EPSS 85.8% | 17 August 2023 |
| CVE-2023-36846 | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | KEVMEDIUM 5.3EPSS 94.8% | 17 August 2023 |
| CVE-2023-36845 | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | KEVCRITICAL 9.8EPSS 95.1% | 17 August 2023 |
| CVE-2023-36844 | Juniper Junos OS EX Series PHP External Variable Modification Vulnerability | KEVMEDIUM 5.3EPSS 90.0% | 17 August 2023 |
| CVE-2023-26469 | In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server. | CRITICAL 9.8EPSS 82.9% | 17 August 2023 |
| CVE-2023-2917 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. | CRITICAL 9.8EPSS 72.2% | 17 August 2023 |
| CVE-2023-2915 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. | CRITICAL 9.1EPSS 81.8% | 17 August 2023 |
| CVE-2023-2914 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. | HIGH 7.5EPSS 39.9% | 17 August 2023 |
| CVE-2023-20209 | A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command… | HIGH 7.2EPSS 40.8% | 16 August 2023 |
| CVE-2023-4362 | Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 19.1% | 15 August 2023 |
| CVE-2023-4357 | Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. | HIGH 8.8EPSS 47.1% | 15 August 2023 |
| CVE-2023-4355 | Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 27.7% | 15 August 2023 |
| CVE-2023-40028 | Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. | MEDIUM 6.5EPSS 68.7% | 15 August 2023 |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 15 August 2023 |
| CVE-2023-2916 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. | MEDIUM 5.3EPSS 24.0% | 15 August 2023 |
| CVE-2023-4347 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0. | MEDIUM 5.4EPSS 69.7% | 15 August 2023 |
| CVE-2023-29468 | Using a specially crafted frame, a buffer overflow can be triggered that can potentially lead to remote code execution. | CRITICAL 9.8EPSS 10.1% | 14 August 2023 |
| CVE-2023-3824 | In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or… | CRITICAL 9.8EPSS 21.8% | 11 August 2023 |
| CVE-2023-32564 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | CRITICAL 9.8EPSS 44.4% | 10 August 2023 |
| CVE-2023-32563 | An unauthenticated attacker could achieve the code execution through a RemoteControl server. | CRITICAL 9.8EPSS 89.1% | 10 August 2023 |
| CVE-2023-32562 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | CRITICAL 9.8EPSS 45.6% | 10 August 2023 |
| CVE-2023-32560 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. | CRITICAL 9.8EPSS 99.4% | 10 August 2023 |
| CVE-2023-32782 | A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the… | HIGH 7.2EPSS 56.2% | 9 August 2023 |
| CVE-2023-32781 | A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the… | HIGH 7.2EPSS 14.3% | 9 August 2023 |
| CVE-2023-38180 | Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 14.0% | 8 August 2023 |
| CVE-2023-36899 | ASP.NET Elevation of Privilege Vulnerability | HIGH 8.8EPSS 76.7% | 8 August 2023 |
| CVE-2023-38181 | Microsoft Exchange Server Spoofing Vulnerability | HIGH 8.8EPSS 10.8% | 8 August 2023 |
| CVE-2023-36900 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH 7.8EPSS 10.6% | 8 August 2023 |
| CVE-2023-20588 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | MEDIUM 5.5EPSS 11.3% | 8 August 2023 |
| CVE-2023-37569 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. | HIGH 8.8EPSS 33.9% | 8 August 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.