SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 47 of 348

CVESummaryPriorityPublished
CVE-2023-38925Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi.HIGH 8.8EPSS 15.2%7 August 2023
CVE-2023-4169A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5.HIGH 8.8EPSS 49.2%5 August 2023
CVE-2023-4168A vulnerability was found in Templatecookie Adlisting 2.14.0.HIGH 7.5EPSS 46.0%5 August 2023
CVE-2023-4166A vulnerability has been found in Tongda OA and classified as critical.CRITICAL 9.8EPSS 12.3%5 August 2023
CVE-2023-4165A vulnerability, which was classified as critical, was found in Tongda OA.CRITICAL 9.8EPSS 12.3%5 August 2023
CVE-2023-39143PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.CRITICAL 9.8EPSS 80.6%4 August 2023
CVE-2023-29689PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.CRITICAL 9.8EPSS 53.5%4 August 2023
CVE-2023-38950ZKTeco BioTime Path Traversal VulnerabilityKEVHIGH 7.5EPSS 84.7%3 August 2023
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) Path Traversal VulnerabilityKEVHIGH 7.2EPSS 63.6%3 August 2023
CVE-2023-4120A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical.CRITICAL 9.8EPSS 62.3%3 August 2023
CVE-2023-37679A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.CRITICAL 9.8EPSS 99.4%3 August 2023
CVE-2023-36255An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.HIGH 8.8EPSS 53.1%3 August 2023
CVE-2023-36212File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.HIGH 8.8EPSS 25.8%3 August 2023
CVE-2023-4069Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 24.9%3 August 2023
CVE-2023-4068Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.HIGH 8.1EPSS 16.0%3 August 2023
CVE-2023-3364A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.HIGH 7.5EPSS 44.5%2 August 2023
CVE-2023-2164It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.MEDIUM 5.4EPSS 65.0%2 August 2023
CVE-2023-36210MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.CRITICAL 9.8EPSS 30.9%1 August 2023
CVE-2023-4050This resulted in a potentially exploitable crash which could have led to a sandbox escape.HIGH 7.5EPSS 12.5%1 August 2023
CVE-2022-39987A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/get_wgkey.php.HIGH 8.8EPSS 37.3%1 August 2023
CVE-2022-39986A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.CRITICAL 9.8EPSS 99.0%1 August 2023
CVE-2023-34960A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.CRITICAL 9.8EPSS 99.3%1 August 2023
CVE-2023-3983An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752.HIGH 8.8EPSS 16.7%31 July 2023
CVE-2023-37580Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 46.7%31 July 2023
CVE-2022-4906Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.HIGH 8.8EPSS 13.0%29 July 2023
CVE-2023-38992jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.CRITICAL 9.8EPSS 73.4%28 July 2023
CVE-2023-37754PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.CRITICAL 9.8EPSS 30.0%28 July 2023
CVE-2023-37450Apple Multiple Products WebKit Code Execution VulnerabilityKEVHIGH 8.8EPSS 18.9%27 July 2023
CVE-2023-31465Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.CRITICAL 9.8EPSS 46.3%26 July 2023
CVE-2023-28130Local user may lead to privilege escalation using Gaia Portal hostnames page.HIGH 7.2EPSS 20.9%26 July 2023
CVE-2023-32629Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernelsHIGH 7.8EPSS 10.4%26 July 2023
CVE-2023-2640On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper…HIGH 7.8EPSS 15.2%26 July 2023
CVE-2023-3486An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage.HIGH 7.5EPSS 79.2%25 July 2023
CVE-2023-35078Ivanti Endpoint Manager Mobile Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%25 July 2023
CVE-2023-3852A vulnerability was found in OpenRapid RapidCMS up to 1.3.1.HIGH 7.2EPSS 25.2%23 July 2023
CVE-2023-3836A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713.CRITICAL 9.8EPSS 73.7%22 July 2023
CVE-2023-38646Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level.CRITICAL 9.8EPSS 98.7%21 July 2023
CVE-2023-35086It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U.HIGH 7.2EPSS 38.5%21 July 2023
CVE-2023-37645eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.MEDIUM 5.3EPSS 24.9%20 July 2023
CVE-2023-38203Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 97.1%20 July 2023
CVE-2023-34967A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight.MEDIUM 5.3EPSS 61.2%20 July 2023
CVE-2023-34966An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight.HIGH 7.5EPSS 62.4%20 July 2023
CVE-2023-38408The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system.CRITICAL 9.8EPSS 79.7%20 July 2023
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.7%19 July 2023
CVE-2023-3765Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.CRITICAL 10.0EPSS 67.5%19 July 2023
CVE-2023-22047Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).HIGH 7.5EPSS 77.0%18 July 2023
CVE-2021-4428A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic.HIGH 7.5EPSS 15.8%18 July 2023
CVE-2023-37791D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.CRITICAL 9.8EPSS 12.7%17 July 2023
CVE-2023-37462Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros…HIGH 8.8EPSS 91.6%14 July 2023
CVE-2023-37474Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder.HIGH 7.5EPSS 44.9%14 July 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.