Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 49 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-3388 | The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. | MEDIUM 6.1EPSS 84.3% | 24 June 2023 |
| CVE-2023-32439 | Apple Multiple Products WebKit Type Confusion Vulnerability | KEVHIGH 8.8EPSS 23.8% | 23 June 2023 |
| CVE-2023-32435 | Apple Multiple Products WebKit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 22.8% | 23 June 2023 |
| CVE-2023-32434 | Apple Multiple Products Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 51.5% | 23 June 2023 |
| CVE-2023-32409 | Apple Multiple Products WebKit Sandbox Escape Vulnerability | KEVHIGH 8.6EPSS 16.5% | 23 June 2023 |
| CVE-2023-32373 | Apple Multiple Products WebKit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 12.2% | 23 June 2023 |
| CVE-2023-28204 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | KEVMEDIUM 6.5EPSS 14.3% | 23 June 2023 |
| CVE-2023-35150 | Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload. | HIGH 8.0EPSS 77.7% | 23 June 2023 |
| CVE-2023-30258 | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request. | CRITICAL 9.8EPSS 94.3% | 23 June 2023 |
| CVE-2023-33299 | A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. | CRITICAL 9.8EPSS 24.3% | 23 June 2023 |
| CVE-2023-36355 | TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. | CRITICAL 9.9EPSS 31.7% | 22 June 2023 |
| CVE-2023-32571 | Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed. | CRITICAL 9.8EPSS 34.9% | 22 June 2023 |
| CVE-2023-29711 | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request. | CRITICAL 9.8EPSS 70.3% | 22 June 2023 |
| CVE-2023-20894 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. | CRITICAL 9.8EPSS 33.9% | 22 June 2023 |
| CVE-2023-29708 | An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload. | HIGH 7.5EPSS 14.2% | 22 June 2023 |
| CVE-2023-33405 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | MEDIUM 6.1EPSS 31.3% | 21 June 2023 |
| CVE-2023-24261 | A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request. | HIGH 7.2EPSS 18.8% | 21 June 2023 |
| CVE-2023-33584 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. | CRITICAL 9.8EPSS 14.2% | 21 June 2023 |
| CVE-2023-34563 | netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication. | CRITICAL 9.8EPSS 13.7% | 20 June 2023 |
| CVE-2023-35885 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | CRITICAL 9.8EPSS 74.9% | 20 June 2023 |
| CVE-2023-35166 | It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. | HIGH 8.8EPSS 62.2% | 20 June 2023 |
| CVE-2023-34600 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | CRITICAL 9.8EPSS 24.2% | 20 June 2023 |
| CVE-2023-2533 | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | KEVHIGH 8.8EPSS 29.2% | 20 June 2023 |
| CVE-2023-27992 | Zyxel Multiple NAS Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 83.8% | 19 June 2023 |
| CVE-2023-3306 | A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204. | CRITICAL 9.8EPSS 23.1% | 18 June 2023 |
| CVE-2023-35813 | Multiple Sitecore products allow remote code execution. | CRITICAL 9.8EPSS 86.7% | 17 June 2023 |
| CVE-2023-34659 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | CRITICAL 9.8EPSS 12.5% | 16 June 2023 |
| CVE-2023-30625 | Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. | HIGH 8.8EPSS 85.8% | 16 June 2023 |
| CVE-2023-35708 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an… | CRITICAL 9.8EPSS 96.7% | 16 June 2023 |
| CVE-2023-28810 | Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. | MEDIUM 4.3EPSS 10.4% | 15 June 2023 |
| CVE-2023-34800 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. | CRITICAL 9.8EPSS 29.3% | 15 June 2023 |
| CVE-2023-32031 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 81.5% | 14 June 2023 |
| CVE-2023-28310 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.0EPSS 25.0% | 14 June 2023 |
| CVE-2023-34747 | File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload. | CRITICAL 9.8EPSS 20.0% | 14 June 2023 |
| CVE-2023-3001 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. | HIGH 7.8EPSS 31.9% | 14 June 2023 |
| CVE-2023-33133 | Microsoft Excel Remote Code Execution Vulnerability | HIGH 7.8EPSS 44.0% | 14 June 2023 |
| CVE-2023-32029 | Microsoft Excel Remote Code Execution Vulnerability | HIGH 7.8EPSS 53.5% | 14 June 2023 |
| CVE-2023-29360 | Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability | KEVHIGH 8.4EPSS 22.1% | 14 June 2023 |
| CVE-2023-29357 | Microsoft SharePoint Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 14 June 2023 |
| CVE-2023-3224 | Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. | CRITICAL 9.8EPSS 58.6% | 13 June 2023 |
| CVE-2023-3217 | Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 13.3% | 13 June 2023 |
| CVE-2023-3215 | Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 13.8% | 13 June 2023 |
| CVE-2023-20867 | VMware Tools Authentication Bypass Vulnerability | KEVLOW 3.9EPSS 13.5% | 13 June 2023 |
| CVE-2023-33568 | An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists. | HIGH 7.5EPSS 14.9% | 13 June 2023 |
| CVE-2023-33919 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). | HIGH 7.2EPSS 47.7% | 13 June 2023 |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 85.7% | 13 June 2023 |
| CVE-2023-34941 | A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyword List text field. | MEDIUM 5.4EPSS 23.8% | 12 June 2023 |
| CVE-2023-33625 | D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function. | CRITICAL 9.8EPSS 33.2% | 12 June 2023 |
| CVE-2023-34468 | The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. | HIGH 8.8EPSS 61.9% | 12 June 2023 |
| CVE-2023-35042 | GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. | CRITICAL 9.8EPSS 43.2% | 12 June 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.