SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 49 of 348

CVESummaryPriorityPublished
CVE-2023-3388The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping.MEDIUM 6.1EPSS 84.3%24 June 2023
CVE-2023-32439Apple Multiple Products WebKit Type Confusion VulnerabilityKEVHIGH 8.8EPSS 23.8%23 June 2023
CVE-2023-32435Apple Multiple Products WebKit Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 22.8%23 June 2023
CVE-2023-32434Apple Multiple Products Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 51.5%23 June 2023
CVE-2023-32409Apple Multiple Products WebKit Sandbox Escape VulnerabilityKEVHIGH 8.6EPSS 16.5%23 June 2023
CVE-2023-32373Apple Multiple Products WebKit Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 12.2%23 June 2023
CVE-2023-28204Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityKEVMEDIUM 6.5EPSS 14.3%23 June 2023
CVE-2023-35150Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to remote code execution by crafting an url with a dangerous payload.HIGH 8.0EPSS 77.7%23 June 2023
CVE-2023-30258Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.CRITICAL 9.8EPSS 94.3%23 June 2023
CVE-2023-33299A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port.CRITICAL 9.8EPSS 24.3%23 June 2023
CVE-2023-36355TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm.CRITICAL 9.9EPSS 31.7%22 June 2023
CVE-2023-32571Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.CRITICAL 9.8EPSS 34.9%22 June 2023
CVE-2023-29711An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.CRITICAL 9.8EPSS 70.3%22 June 2023
CVE-2023-20894The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol.CRITICAL 9.8EPSS 33.9%22 June 2023
CVE-2023-29708An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.HIGH 7.5EPSS 14.2%22 June 2023
CVE-2023-33405Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.MEDIUM 6.1EPSS 31.3%21 June 2023
CVE-2023-24261A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.HIGH 7.2EPSS 18.8%21 June 2023
CVE-2023-33584Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application.CRITICAL 9.8EPSS 14.2%21 June 2023
CVE-2023-34563netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.CRITICAL 9.8EPSS 13.7%20 June 2023
CVE-2023-35885CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.CRITICAL 9.8EPSS 74.9%20 June 2023
CVE-2023-35166It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension.HIGH 8.8EPSS 62.2%20 June 2023
CVE-2023-34600Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.CRITICAL 9.8EPSS 24.2%20 June 2023
CVE-2023-2533PaperCut NG/MF Cross-Site Request Forgery (CSRF) VulnerabilityKEVHIGH 8.8EPSS 29.2%20 June 2023
CVE-2023-27992Zyxel Multiple NAS Devices Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 83.8%19 June 2023
CVE-2023-3306A vulnerability was found in Ruijie RG-EW1200G EW_3.0(1)B11P204.CRITICAL 9.8EPSS 23.1%18 June 2023
CVE-2023-35813Multiple Sitecore products allow remote code execution.CRITICAL 9.8EPSS 86.7%17 June 2023
CVE-2023-34659jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.CRITICAL 9.8EPSS 12.5%16 June 2023
CVE-2023-30625Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection.HIGH 8.8EPSS 85.8%16 June 2023
CVE-2023-35708In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an…CRITICAL 9.8EPSS 96.7%16 June 2023
CVE-2023-28810Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities.MEDIUM 4.3EPSS 10.4%15 June 2023
CVE-2023-34800D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.CRITICAL 9.8EPSS 29.3%15 June 2023
CVE-2023-32031Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 81.5%14 June 2023
CVE-2023-28310Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.0EPSS 25.0%14 June 2023
CVE-2023-34747File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.CRITICAL 9.8EPSS 20.0%14 June 2023
CVE-2023-3001A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.HIGH 7.8EPSS 31.9%14 June 2023
CVE-2023-33133Microsoft Excel Remote Code Execution VulnerabilityHIGH 7.8EPSS 44.0%14 June 2023
CVE-2023-32029Microsoft Excel Remote Code Execution VulnerabilityHIGH 7.8EPSS 53.5%14 June 2023
CVE-2023-29360Microsoft Streaming Service Untrusted Pointer Dereference VulnerabilityKEVHIGH 8.4EPSS 22.1%14 June 2023
CVE-2023-29357Microsoft SharePoint Server Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 100.0%14 June 2023
CVE-2023-3224Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.CRITICAL 9.8EPSS 58.6%13 June 2023
CVE-2023-3217Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 13.3%13 June 2023
CVE-2023-3215Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 13.8%13 June 2023
CVE-2023-20867VMware Tools Authentication Bypass VulnerabilityKEVLOW 3.9EPSS 13.5%13 June 2023
CVE-2023-33568An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.HIGH 7.5EPSS 14.9%13 June 2023
CVE-2023-33919A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05).HIGH 7.2EPSS 47.7%13 June 2023
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 85.7%13 June 2023
CVE-2023-34941A stored cross-site scripting (XSS) vulnerability in the urlFilterList function of Asus RT-N10LX Router v2.0.0.39 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL Keyword List text field.MEDIUM 5.4EPSS 23.8%12 June 2023
CVE-2023-33625D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.CRITICAL 9.8EPSS 33.2%12 June 2023
CVE-2023-34468The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.HIGH 8.8EPSS 61.9%12 June 2023
CVE-2023-35042GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023.CRITICAL 9.8EPSS 43.2%12 June 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.