SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 50 of 348

CVESummaryPriorityPublished
CVE-2023-3206A vulnerability classified as problematic was found in Chengdu VEC40G 3.0.HIGH 7.5EPSS 18.7%12 June 2023
CVE-2023-35036In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an…CRITICAL 9.1EPSS 12.8%12 June 2023
CVE-2023-2249The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7.HIGH 8.8EPSS 60.8%9 June 2023
CVE-2023-0992The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header.MEDIUM 6.1EPSS 93.0%9 June 2023
CVE-2023-32749Pydio Cells allows users by default to create so-called external users in order to share files with them.HIGH 8.8EPSS 14.1%8 June 2023
CVE-2023-34096In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system.HIGH 8.8EPSS 62.7%8 June 2023
CVE-2023-2986The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2.CRITICAL 9.8EPSS 42.5%8 June 2023
CVE-2023-2442A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.MEDIUM 5.4EPSS 96.1%7 June 2023
CVE-2023-20889Aria Operations for Networks contains an information disclosure vulnerability.HIGH 7.5EPSS 79.3%7 June 2023
CVE-2023-20888Aria Operations for Networks contains an authenticated deserialization vulnerability.HIGH 8.8EPSS 82.3%7 June 2023
CVE-2023-20887Vmware Aria Operations for Networks Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.3%7 June 2023
CVE-2023-33538TP-Link Multiple Routers Command Injection VulnerabilityKEVHIGH 8.8EPSS 41.9%7 June 2023
CVE-2023-3124The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6.HIGH 8.8EPSS 22.7%7 June 2023
CVE-2021-4374The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2.CRITICAL 9.8EPSS 16.4%7 June 2023
CVE-2020-36708The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance…CRITICAL 9.8EPSS 65.3%7 June 2023
CVE-2023-33782D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.HIGH 8.8EPSS 36.6%7 June 2023
CVE-2023-33781An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.HIGH 8.8EPSS 32.0%7 June 2023
CVE-2023-0921A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested,…MEDIUM 4.3EPSS 84.4%6 June 2023
CVE-2023-33532There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48.CRITICAL 9.8EPSS 16.2%6 June 2023
CVE-2023-33381A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2).HIGH 7.2EPSS 22.4%6 June 2023
CVE-2023-2833The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function.HIGH 8.8EPSS 17.5%6 June 2023
CVE-2023-3079Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 32.1%5 June 2023
CVE-2023-30149SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute…CRITICAL 9.8EPSS 16.9%2 June 2023
CVE-2023-34362Progress MOVEit Transfer SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.9%2 June 2023
CVE-2022-45938An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..CRITICAL 9.0EPSS 45.1%2 June 2023
CVE-2023-32714In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation…HIGH 8.1EPSS 42.8%1 June 2023
CVE-2023-32707In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of…HIGH 8.8EPSS 79.0%1 June 2023
CVE-2023-29154SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3.HIGH 7.2EPSS 41.4%1 June 2023
CVE-2023-28651Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.MEDIUM 4.8EPSS 62.4%1 June 2023
CVE-2022-35742Microsoft Outlook Denial of Service VulnerabilityHIGH 7.5EPSS 22.4%1 June 2023
CVE-2023-33735D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.CRITICAL 9.8EPSS 32.6%31 May 2023
CVE-2022-35756Windows Kerberos Elevation of Privilege VulnerabilityHIGH 7.8EPSS 11.3%31 May 2023
CVE-2022-35748HTTP.sys Denial of Service VulnerabilityHIGH 7.5EPSS 47.2%31 May 2023
CVE-2023-34225In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possibleMEDIUM 5.4EPSS 60.7%31 May 2023
CVE-2023-34220In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possibleMEDIUM 5.4EPSS 61.2%31 May 2023
CVE-2023-2936Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 23.0%30 May 2023
CVE-2023-2935Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 23.9%30 May 2023
CVE-2023-31185ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.HIGH 7.5EPSS 12.8%30 May 2023
CVE-2023-2650Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may…MEDIUM 6.5EPSS 75.1%30 May 2023
CVE-2023-2288This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.HIGH 8.8EPSS 18.0%30 May 2023
CVE-2023-0329The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator…HIGH 7.2EPSS 19.7%30 May 2023
CVE-2023-30253Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.HIGH 8.8EPSS 82.1%29 May 2023
CVE-2022-24632It is directory traversal during file download via the BrowseFiles.php view parameter.MEDIUM 5.3EPSS 27.4%29 May 2023
CVE-2022-24631It is stored XSS via the ajaxTenants.php desc parameter.MEDIUM 5.4EPSS 43.2%29 May 2023
CVE-2022-24630BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.HIGH 7.2EPSS 23.9%29 May 2023
CVE-2022-24629Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php.CRITICAL 9.8EPSS 37.2%29 May 2023
CVE-2022-24627It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.CRITICAL 9.8EPSS 26.4%29 May 2023
CVE-2023-2948Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.MEDIUM 6.1EPSS 96.7%28 May 2023
CVE-2023-2947Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.MEDIUM 4.8EPSS 90.4%27 May 2023
CVE-2023-2928A vulnerability was found in DedeCMS up to 5.7.106.HIGH 8.8EPSS 51.4%27 May 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.