SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 48 of 348

CVESummaryPriorityPublished
CVE-2022-24834A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution.HIGH 8.8EPSS 41.4%13 July 2023
CVE-2023-29452Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.MEDIUM 5.4EPSS 64.1%13 July 2023
CVE-2023-34133Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database.HIGH 7.5EPSS 72.6%13 July 2023
CVE-2023-34129Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any…HIGH 8.8EPSS 41.2%13 July 2023
CVE-2023-34127Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges.HIGH 8.8EPSS 86.5%13 July 2023
CVE-2023-34125Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges.MEDIUM 6.5EPSS 25.4%13 July 2023
CVE-2023-34124The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass.CRITICAL 9.8EPSS 50.2%13 July 2023
CVE-2023-3643A vulnerability was found in Boss Mini 1.4.0 Build 6221.CRITICAL 9.8EPSS 75.4%12 July 2023
CVE-2023-37629Online Piggery Management System 1.0 is vulnerable to File Upload.CRITICAL 9.8EPSS 23.3%12 July 2023
CVE-2023-29301Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass.HIGH 7.5EPSS 34.7%12 July 2023
CVE-2023-29300Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 100.0%12 July 2023
CVE-2023-29298Adobe ColdFusion Improper Access Control VulnerabilityKEVHIGH 7.5EPSS 99.8%12 July 2023
CVE-2023-37582The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.CRITICAL 9.8EPSS 90.4%12 July 2023
CVE-2023-36884Microsoft Windows Search Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 98.9%11 July 2023
CVE-2023-36874Microsoft Windows Error Reporting Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 43.4%11 July 2023
CVE-2023-35311Microsoft Outlook Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 15.5%11 July 2023
CVE-2023-33157Microsoft SharePoint Remote Code Execution VulnerabilityHIGH 8.8EPSS 38.2%11 July 2023
CVE-2023-32046Microsoft Windows MSHTML Platform Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 10.0%11 July 2023
CVE-2023-36824In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corruption and potentially remote code execution.HIGH 8.8EPSS 77.4%11 July 2023
CVE-2023-3608A vulnerability was found in Ruijie BCR810W 2.5.10.HIGH 8.8EPSS 12.3%10 July 2023
CVE-2023-24489Citrix Content Collaboration ShareFile Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 97.3%10 July 2023
CVE-2023-24488Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scriptingMEDIUM 6.1EPSS 80.9%10 July 2023
CVE-2023-2796The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.MEDIUM 5.3EPSS 42.7%10 July 2023
CVE-2023-1183An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.MEDIUM 5.5EPSS 64.6%10 July 2023
CVE-2023-36460Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location.CRITICAL 9.9EPSS 40.1%6 July 2023
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVCRITICAL 9.0EPSS 77.3%6 July 2023
CVE-2023-36969CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.HIGH 8.8EPSS 49.3%6 July 2023
CVE-2023-36808Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack.CRITICAL 9.8EPSS 47.8%5 July 2023
CVE-2023-35924Starting in version 10.0.0 and prior to version 10.0.8, GLPI inventory endpoint can be used to drive a SQL injection attack.CRITICAL 9.8EPSS 50.7%5 July 2023
CVE-2023-36934In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that…CRITICAL 9.1EPSS 95.2%5 July 2023
CVE-2023-36933In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception.HIGH 7.5EPSS 72.2%5 July 2023
CVE-2023-36932In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application…HIGH 8.1EPSS 81.1%5 July 2023
CVE-2023-3460The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will.CRITICAL 9.8EPSS 72.3%4 July 2023
CVE-2023-26258Arcserve UDP through 9.0.6034 allows authentication bypass.CRITICAL 9.8EPSS 37.7%3 July 2023
CVE-2023-28324A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.CRITICAL 9.8EPSS 12.9%1 July 2023
CVE-2023-36812OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration.CRITICAL 9.8EPSS 16.5%30 June 2023
CVE-2023-36144An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.HIGH 7.5EPSS 36.5%30 June 2023
CVE-2023-36347A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.HIGH 7.5EPSS 34.1%30 June 2023
CVE-2023-36469Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents.HIGH 8.8EPSS 82.0%29 June 2023
CVE-2023-31222Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device…HIGH 8.8EPSS 28.5%29 June 2023
CVE-2023-26613An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.CRITICAL 9.8EPSS 31.4%29 June 2023
CVE-2023-34598Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.CRITICAL 9.8EPSS 47.2%29 June 2023
CVE-2023-2982The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4.CRITICAL 9.8EPSS 46.2%29 June 2023
CVE-2023-3450A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical.HIGH 7.2EPSS 50.8%28 June 2023
CVE-2023-2877This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.HIGH 8.8EPSS 22.5%27 June 2023
CVE-2023-2068The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode.CRITICAL 9.8EPSS 39.6%27 June 2023
CVE-2023-32521A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.CRITICAL 9.1EPSS 66.8%26 June 2023
CVE-2023-3420Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 56.2%26 June 2023
CVE-2023-33404An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.CRITICAL 9.8EPSS 25.8%26 June 2023
CVE-2023-30261Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET request.CRITICAL 9.8EPSS 31.7%26 June 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.