Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,582 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 51 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-2924 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. | CRITICAL 9.8EPSS 24.3% | 27 May 2023 |
| CVE-2023-32315 | Ignite Realtime Openfire Path Traversal Vulnerability | KEVHIGH 7.5EPSS 100.0% | 26 May 2023 |
| CVE-2023-2825 | An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. | HIGH 7.5EPSS 71.6% | 26 May 2023 |
| CVE-2023-33440 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | HIGH 7.2EPSS 14.5% | 26 May 2023 |
| CVE-2023-30145 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | CRITICAL 9.8EPSS 46.1% | 26 May 2023 |
| CVE-2023-2732 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. | CRITICAL 9.8EPSS 67.5% | 25 May 2023 |
| CVE-2023-2868 | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 87.7% | 24 May 2023 |
| CVE-2023-33246 | Apache RocketMQ Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.6% | 24 May 2023 |
| CVE-2023-33010 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 28.8% | 24 May 2023 |
| CVE-2023-33009 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 28.1% | 24 May 2023 |
| CVE-2023-29919 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. | CRITICAL 9.1EPSS 60.2% | 23 May 2023 |
| CVE-2023-31689 | In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. | CRITICAL 9.8EPSS 20.2% | 22 May 2023 |
| CVE-2023-28709 | If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded… | HIGH 7.5EPSS 48.0% | 22 May 2023 |
| CVE-2023-20189 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an… | CRITICAL 9.8EPSS 11.1% | 18 May 2023 |
| CVE-2023-20161 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an… | CRITICAL 9.8EPSS 10.3% | 18 May 2023 |
| CVE-2023-20160 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an… | CRITICAL 9.8EPSS 10.3% | 18 May 2023 |
| CVE-2023-20159 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an… | CRITICAL 9.8EPSS 10.3% | 18 May 2023 |
| CVE-2023-2766 | A vulnerability was found in Weaver OA 9.5 and classified as problematic. | HIGH 7.5EPSS 54.2% | 17 May 2023 |
| CVE-2023-2745 | WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. | MEDIUM 5.4EPSS 79.5% | 17 May 2023 |
| CVE-2023-2725 | Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 24.7% | 16 May 2023 |
| CVE-2023-2724 | Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 29.1% | 16 May 2023 |
| CVE-2023-2723 | Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 15.4% | 16 May 2023 |
| CVE-2023-32986 | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins… | HIGH 8.8EPSS 60.7% | 16 May 2023 |
| CVE-2023-32985 | Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins… | MEDIUM 4.3EPSS 72.4% | 16 May 2023 |
| CVE-2023-32068 | This vulnerability was partially fixed in the past for XWiki 12.10.7 and 13.3RC1 but there is still the possibility to force specific URLs to skip some checks, e.g. using URLs like `http:example.com` in the parameter would allow the redirect. | MEDIUM 6.1EPSS 55.1% | 15 May 2023 |
| CVE-2023-1549 | The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | HIGH 7.2EPSS 16.9% | 15 May 2023 |
| CVE-2023-1698 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise. | CRITICAL 9.8EPSS 82.0% | 15 May 2023 |
| CVE-2023-31983 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations. | CRITICAL 9.8EPSS 24.9% | 12 May 2023 |
| CVE-2023-27823 | An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | CRITICAL 9.8EPSS 53.6% | 12 May 2023 |
| CVE-2023-32243 | Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. | CRITICAL 9.8EPSS 75.5% | 12 May 2023 |
| CVE-2023-29809 | SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request. | CRITICAL 9.8EPSS 10.5% | 12 May 2023 |
| CVE-2023-31475 | The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer. | CRITICAL 9.8EPSS 13.7% | 11 May 2023 |
| CVE-2023-2648 | A vulnerability was found in Weaver E-Office 9.5. | CRITICAL 9.8EPSS 28.5% | 11 May 2023 |
| CVE-2023-30194 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | CRITICAL 9.8EPSS 32.4% | 10 May 2023 |
| CVE-2023-30777 | Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. | MEDIUM 6.1EPSS 38.8% | 10 May 2023 |
| CVE-2023-22361 | Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. | MEDIUM 6.5EPSS 35.9% | 10 May 2023 |
| CVE-2023-31478 | An issue was discovered on GL.iNet devices before 3.216. | HIGH 7.5EPSS 29.7% | 9 May 2023 |
| CVE-2023-28128 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. | HIGH 7.2EPSS 84.7% | 9 May 2023 |
| CVE-2023-28127 | A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure. | HIGH 7.5EPSS 58.6% | 9 May 2023 |
| CVE-2023-28126 | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message. | MEDIUM 5.9EPSS 66.7% | 9 May 2023 |
| CVE-2023-31472 | There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. | HIGH 7.5EPSS 19.9% | 9 May 2023 |
| CVE-2023-29336 | Microsoft Win32K Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 40.9% | 9 May 2023 |
| CVE-2023-29325 | Windows OLE Remote Code Execution Vulnerability | HIGH 7.5EPSS 84.4% | 9 May 2023 |
| CVE-2023-24955 | Microsoft SharePoint Server Code Injection Vulnerability | KEVHIGH 7.2EPSS 85.4% | 9 May 2023 |
| CVE-2023-24950 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM 6.5EPSS 67.5% | 9 May 2023 |
| CVE-2023-24949 | Windows Kernel Elevation of Privilege Vulnerability | HIGH 7.8EPSS 24.6% | 9 May 2023 |
| CVE-2023-24941 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 94.7% | 9 May 2023 |
| CVE-2023-24932 | Secure Boot Security Feature Bypass Vulnerability | MEDIUM 6.7EPSS 10.6% | 9 May 2023 |
| CVE-2023-32071 | Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. | CRITICAL 9.0EPSS 70.4% | 9 May 2023 |
| CVE-2023-31133 | Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. | HIGH 7.5EPSS 45.7% | 8 May 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.