Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 47 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-38925 | Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi. | HIGH 8.8EPSS 15.2% | 7 August 2023 |
| CVE-2023-4169 | A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. | HIGH 8.8EPSS 49.2% | 5 August 2023 |
| CVE-2023-4168 | A vulnerability was found in Templatecookie Adlisting 2.14.0. | HIGH 7.5EPSS 46.0% | 5 August 2023 |
| CVE-2023-4166 | A vulnerability has been found in Tongda OA and classified as critical. | CRITICAL 9.8EPSS 12.3% | 5 August 2023 |
| CVE-2023-4165 | A vulnerability, which was classified as critical, was found in Tongda OA. | CRITICAL 9.8EPSS 12.3% | 5 August 2023 |
| CVE-2023-39143 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. | CRITICAL 9.8EPSS 80.6% | 4 August 2023 |
| CVE-2023-29689 | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. | CRITICAL 9.8EPSS 53.5% | 4 August 2023 |
| CVE-2023-38950 | ZKTeco BioTime Path Traversal Vulnerability | KEVHIGH 7.5EPSS 84.7% | 3 August 2023 |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | KEVHIGH 7.2EPSS 63.6% | 3 August 2023 |
| CVE-2023-4120 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. | CRITICAL 9.8EPSS 62.3% | 3 August 2023 |
| CVE-2023-37679 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | CRITICAL 9.8EPSS 99.4% | 3 August 2023 |
| CVE-2023-36255 | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL. | HIGH 8.8EPSS 53.1% | 3 August 2023 |
| CVE-2023-36212 | File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function. | HIGH 8.8EPSS 25.8% | 3 August 2023 |
| CVE-2023-4069 | Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 24.9% | 3 August 2023 |
| CVE-2023-4068 | Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. | HIGH 8.1EPSS 16.0% | 3 August 2023 |
| CVE-2023-3364 | A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint. | HIGH 7.5EPSS 44.5% | 2 August 2023 |
| CVE-2023-2164 | It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta. | MEDIUM 5.4EPSS 65.0% | 2 August 2023 |
| CVE-2023-36210 | MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | CRITICAL 9.8EPSS 30.9% | 1 August 2023 |
| CVE-2023-4050 | This resulted in a potentially exploitable crash which could have led to a sandbox escape. | HIGH 7.5EPSS 12.5% | 1 August 2023 |
| CVE-2022-39987 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/get_wgkey.php. | HIGH 8.8EPSS 37.3% | 1 August 2023 |
| CVE-2022-39986 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php. | CRITICAL 9.8EPSS 99.0% | 1 August 2023 |
| CVE-2023-34960 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. | CRITICAL 9.8EPSS 99.3% | 1 August 2023 |
| CVE-2023-3983 | An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. | HIGH 8.8EPSS 16.7% | 31 July 2023 |
| CVE-2023-37580 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 46.7% | 31 July 2023 |
| CVE-2022-4906 | Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. | HIGH 8.8EPSS 13.0% | 29 July 2023 |
| CVE-2023-38992 | jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData. | CRITICAL 9.8EPSS 73.4% | 28 July 2023 |
| CVE-2023-37754 | PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. | CRITICAL 9.8EPSS 30.0% | 28 July 2023 |
| CVE-2023-37450 | Apple Multiple Products WebKit Code Execution Vulnerability | KEVHIGH 8.8EPSS 18.9% | 27 July 2023 |
| CVE-2023-31465 | Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server. | CRITICAL 9.8EPSS 46.3% | 26 July 2023 |
| CVE-2023-28130 | Local user may lead to privilege escalation using Gaia Portal hostnames page. | HIGH 7.2EPSS 20.9% | 26 July 2023 |
| CVE-2023-32629 | Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels | HIGH 7.8EPSS 10.4% | 26 July 2023 |
| CVE-2023-2640 | On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper… | HIGH 7.8EPSS 15.2% | 26 July 2023 |
| CVE-2023-3486 | An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. | HIGH 7.5EPSS 79.2% | 25 July 2023 |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 25 July 2023 |
| CVE-2023-3852 | A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. | HIGH 7.2EPSS 25.2% | 23 July 2023 |
| CVE-2023-3836 | A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. | CRITICAL 9.8EPSS 73.7% | 22 July 2023 |
| CVE-2023-38646 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. | CRITICAL 9.8EPSS 98.7% | 21 July 2023 |
| CVE-2023-35086 | It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. | HIGH 7.2EPSS 38.5% | 21 July 2023 |
| CVE-2023-37645 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | MEDIUM 5.3EPSS 24.9% | 20 July 2023 |
| CVE-2023-38203 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 97.1% | 20 July 2023 |
| CVE-2023-34967 | A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. | MEDIUM 5.3EPSS 61.2% | 20 July 2023 |
| CVE-2023-34966 | An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. | HIGH 7.5EPSS 62.4% | 20 July 2023 |
| CVE-2023-38408 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. | CRITICAL 9.8EPSS 79.7% | 20 July 2023 |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 19 July 2023 |
| CVE-2023-3765 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | CRITICAL 10.0EPSS 67.5% | 19 July 2023 |
| CVE-2023-22047 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). | HIGH 7.5EPSS 77.0% | 18 July 2023 |
| CVE-2021-4428 | A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic. | HIGH 7.5EPSS 15.8% | 18 July 2023 |
| CVE-2023-37791 | D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin. | CRITICAL 9.8EPSS 12.7% | 17 July 2023 |
| CVE-2023-37462 | Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros… | HIGH 8.8EPSS 91.6% | 14 July 2023 |
| CVE-2023-37474 | Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. | HIGH 7.5EPSS 44.9% | 14 July 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.