Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,633 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 52 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-32233 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. | HIGH 7.8EPSS 13.0% | 8 May 2023 |
| CVE-2023-2114 | The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. | HIGH 7.2EPSS 44.6% | 8 May 2023 |
| CVE-2023-1650 | The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog | CRITICAL 9.8EPSS 34.4% | 8 May 2023 |
| CVE-2023-1347 | The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | HIGH 7.2EPSS 16.0% | 8 May 2023 |
| CVE-2023-0603 | The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | HIGH 8.8EPSS 13.9% | 8 May 2023 |
| CVE-2023-2575 | Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request. | HIGH 8.8EPSS 15.5% | 8 May 2023 |
| CVE-2023-2564 | OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0. | CRITICAL 10.0EPSS 40.5% | 7 May 2023 |
| CVE-2023-2554 | External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0. | HIGH 7.2EPSS 29.1% | 5 May 2023 |
| CVE-2023-30013 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. | CRITICAL 9.8EPSS 25.9% | 5 May 2023 |
| CVE-2023-32235 | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. | HIGH 7.5EPSS 39.1% | 5 May 2023 |
| CVE-2023-20126 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. | CRITICAL 9.8EPSS 36.7% | 4 May 2023 |
| CVE-2023-2523 | A vulnerability was found in Weaver E-Office 9.5. | CRITICAL 9.8EPSS 32.9% | 4 May 2023 |
| CVE-2023-2522 | A vulnerability was found in Chengdu VEC40G 3.0. | HIGH 7.2EPSS 33.7% | 4 May 2023 |
| CVE-2023-31099 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. | HIGH 8.8EPSS 81.6% | 4 May 2023 |
| CVE-2023-25826 | Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. | CRITICAL 9.8EPSS 42.8% | 3 May 2023 |
| CVE-2023-30403 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user. | HIGH 7.5EPSS 13.8% | 2 May 2023 |
| CVE-2023-29778 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | CRITICAL 9.8EPSS 16.0% | 2 May 2023 |
| CVE-2022-47878 | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. | HIGH 8.8EPSS 35.7% | 2 May 2023 |
| CVE-2022-47875 | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. | HIGH 8.8EPSS 10.2% | 2 May 2023 |
| CVE-2022-47874 | Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'. | MEDIUM 6.5EPSS 21.1% | 2 May 2023 |
| CVE-2023-2479 | OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | CRITICAL 9.8EPSS 22.0% | 2 May 2023 |
| CVE-2023-29772 | A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC51U wireless router firmware version up to and including 3.0.0.4.380.8591 allows remote attackers to inject arbitrary web script or… | MEDIUM 5.2EPSS 11.2% | 2 May 2023 |
| CVE-2023-32007 | If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. | HIGH 8.8EPSS 76.0% | 2 May 2023 |
| CVE-2023-1861 | The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks | MEDIUM 5.4EPSS 28.8% | 2 May 2023 |
| CVE-2023-1730 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks | CRITICAL 9.8EPSS 40.6% | 2 May 2023 |
| CVE-2023-1669 | The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | HIGH 7.2EPSS 17.7% | 2 May 2023 |
| CVE-2023-30405 | A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup. | MEDIUM 5.4EPSS 29.3% | 28 April 2023 |
| CVE-2023-28400 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | HIGH 8.8EPSS 24.6% | 27 April 2023 |
| CVE-2023-28384 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | HIGH 8.8EPSS 44.8% | 27 April 2023 |
| CVE-2023-29489 | XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. | MEDIUM 6.1EPSS 65.5% | 27 April 2023 |
| CVE-2023-25437 | An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML. | HIGH 8.8EPSS 14.1% | 27 April 2023 |
| CVE-2023-28770 | The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the… | HIGH 7.5EPSS 57.8% | 27 April 2023 |
| CVE-2023-25652 | Git is a revision control system. | HIGH 7.5EPSS 51.9% | 25 April 2023 |
| CVE-2023-29552 | Service Location Protocol (SLP) Denial-of-Service Vulnerability | KEVHIGH 7.5EPSS 65.9% | 25 April 2023 |
| CVE-2023-28771 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 25 April 2023 |
| CVE-2023-27524 | Apache Superset Insecure Default Initialization of Resource Vulnerability | KEVCRITICAL 9.8EPSS 97.4% | 24 April 2023 |
| CVE-2023-28131 | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. | CRITICAL 9.6EPSS 23.2% | 24 April 2023 |
| CVE-2023-2227 | Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. | CRITICAL 9.1EPSS 44.0% | 21 April 2023 |
| CVE-2023-20864 | VMware Aria Operations for Logs contains a deserialization vulnerability. | CRITICAL 9.8EPSS 70.4% | 20 April 2023 |
| CVE-2023-27351 | PaperCut NG/MF Improper Authentication Vulnerability | KEVHIGH 7.5EPSS 78.1% | 20 April 2023 |
| CVE-2023-27350 | PaperCut MF/NG Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 20 April 2023 |
| CVE-2023-22621 | Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. | HIGH 7.2EPSS 76.8% | 19 April 2023 |
| CVE-2023-29525 | Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint. | HIGH 8.8EPSS 77.8% | 19 April 2023 |
| CVE-2023-29524 | It's possible to execute anything with the right of the Scheduler Application sheet page. | HIGH 8.8EPSS 75.7% | 19 April 2023 |
| CVE-2023-29516 | Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. | HIGH 8.8EPSS 65.9% | 19 April 2023 |
| CVE-2023-21932 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). | HIGH 7.2EPSS 44.7% | 18 April 2023 |
| CVE-2023-21931 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | HIGH 7.5EPSS 82.3% | 18 April 2023 |
| CVE-2023-30547 | There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. | CRITICAL 10.0EPSS 72.1% | 17 April 2023 |
| CVE-2023-29509 | Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. | HIGH 8.8EPSS 75.7% | 16 April 2023 |
| CVE-2021-33990 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. | CRITICAL 9.8EPSS 11.9% | 16 April 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.