SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,633 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 52 of 348

CVESummaryPriorityPublished
CVE-2023-32233In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory.HIGH 7.8EPSS 13.0%8 May 2023
CVE-2023-2114The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.HIGH 7.2EPSS 44.6%8 May 2023
CVE-2023-1650The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blogCRITICAL 9.8EPSS 34.4%8 May 2023
CVE-2023-1347The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is presentHIGH 7.2EPSS 16.0%8 May 2023
CVE-2023-0603The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attackHIGH 8.8EPSS 13.9%8 May 2023
CVE-2023-2575Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.HIGH 8.8EPSS 15.5%8 May 2023
CVE-2023-2564OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.CRITICAL 10.0EPSS 40.5%7 May 2023
CVE-2023-2554External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.HIGH 7.2EPSS 29.1%5 May 2023
CVE-2023-30013TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg.CRITICAL 9.8EPSS 25.9%5 May 2023
CVE-2023-32235Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal.HIGH 7.5EPSS 39.1%5 May 2023
CVE-2023-20126A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.CRITICAL 9.8EPSS 36.7%4 May 2023
CVE-2023-2523A vulnerability was found in Weaver E-Office 9.5.CRITICAL 9.8EPSS 32.9%4 May 2023
CVE-2023-2522A vulnerability was found in Chengdu VEC40G 3.0.HIGH 7.2EPSS 33.7%4 May 2023
CVE-2023-31099Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.HIGH 8.8EPSS 81.6%4 May 2023
CVE-2023-25826Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system.CRITICAL 9.8EPSS 42.8%3 May 2023
CVE-2023-30403An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.HIGH 7.5EPSS 13.8%2 May 2023
CVE-2023-29778GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.CRITICAL 9.8EPSS 16.0%2 May 2023
CVE-2022-47878Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory.HIGH 8.8EPSS 35.7%2 May 2023
CVE-2022-47875A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.HIGH 8.8EPSS 10.2%2 May 2023
CVE-2022-47874Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.MEDIUM 6.5EPSS 21.1%2 May 2023
CVE-2023-2479OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.CRITICAL 9.8EPSS 22.0%2 May 2023
CVE-2023-29772A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or…MEDIUM 5.2EPSS 11.2%2 May 2023
CVE-2023-32007If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name.HIGH 8.8EPSS 76.0%2 May 2023
CVE-2023-1861The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacksMEDIUM 5.4EPSS 28.8%2 May 2023
CVE-2023-1730The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacksCRITICAL 9.8EPSS 40.6%2 May 2023
CVE-2023-1669The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.HIGH 7.2EPSS 17.7%2 May 2023
CVE-2023-30405A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup.MEDIUM 5.4EPSS 29.3%28 April 2023
CVE-2023-28400mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.HIGH 8.8EPSS 24.6%27 April 2023
CVE-2023-28384mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.HIGH 8.8EPSS 44.8%27 April 2023
CVE-2023-29489XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669.MEDIUM 6.1EPSS 65.5%27 April 2023
CVE-2023-25437An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.HIGH 8.8EPSS 14.1%27 April 2023
CVE-2023-28770The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the…HIGH 7.5EPSS 57.8%27 April 2023
CVE-2023-25652Git is a revision control system.HIGH 7.5EPSS 51.9%25 April 2023
CVE-2023-29552Service Location Protocol (SLP) Denial-of-Service VulnerabilityKEVHIGH 7.5EPSS 65.9%25 April 2023
CVE-2023-28771Zyxel Multiple Firewalls OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.3%25 April 2023
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource VulnerabilityKEVCRITICAL 9.8EPSS 97.4%24 April 2023
CVE-2023-28131A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in.CRITICAL 9.6EPSS 23.2%24 April 2023
CVE-2023-2227Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.CRITICAL 9.1EPSS 44.0%21 April 2023
CVE-2023-20864VMware Aria Operations for Logs contains a deserialization vulnerability.CRITICAL 9.8EPSS 70.4%20 April 2023
CVE-2023-27351PaperCut NG/MF Improper Authentication VulnerabilityKEVHIGH 7.5EPSS 78.1%20 April 2023
CVE-2023-27350PaperCut MF/NG Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 100.0%20 April 2023
CVE-2023-22621Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server.HIGH 7.2EPSS 76.8%19 April 2023
CVE-2023-29525Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint.HIGH 8.8EPSS 77.8%19 April 2023
CVE-2023-29524It's possible to execute anything with the right of the Scheduler Application sheet page.HIGH 8.8EPSS 75.7%19 April 2023
CVE-2023-29516Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation.HIGH 8.8EPSS 65.9%19 April 2023
CVE-2023-21932Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI).HIGH 7.2EPSS 44.7%18 April 2023
CVE-2023-21931Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).HIGH 7.5EPSS 82.3%18 April 2023
CVE-2023-30547There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context.CRITICAL 10.0EPSS 72.1%17 April 2023
CVE-2023-29509Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation.HIGH 8.8EPSS 75.7%16 April 2023
CVE-2021-33990Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.CRITICAL 9.8EPSS 11.9%16 April 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.