SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,633 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 53 of 348

CVESummaryPriorityPublished
CVE-2022-38841Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.HIGH 8.8EPSS 10.7%16 April 2023
CVE-2023-2033Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 40.8%14 April 2023
CVE-2022-47501Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin.HIGH 7.5EPSS 10.2%14 April 2023
CVE-2023-29804WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.HIGH 8.8EPSS 17.5%14 April 2023
CVE-2023-2034Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.HIGH 8.8EPSS 71.4%14 April 2023
CVE-2023-29084Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.HIGH 7.2EPSS 98.2%13 April 2023
CVE-2023-20118Cisco Small Business RV Series Routers Command Injection VulnerabilityKEVHIGH 7.2EPSS 54.1%13 April 2023
CVE-2023-28121An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator.CRITICAL 9.8EPSS 86.5%12 April 2023
CVE-2023-27826SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.HIGH 8.8EPSS 11.8%12 April 2023
CVE-2023-28302Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityHIGH 7.5EPSS 92.6%11 April 2023
CVE-2023-28252Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 49.0%11 April 2023
CVE-2023-28231DHCP Server Service Remote Code Execution VulnerabilityHIGH 8.8EPSS 36.9%11 April 2023
CVE-2023-28220Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityHIGH 8.1EPSS 15.0%11 April 2023
CVE-2023-28219Layer 2 Tunneling Protocol Remote Code Execution VulnerabilityHIGH 8.1EPSS 15.0%11 April 2023
CVE-2023-28218Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityHIGH 7.0EPSS 12.3%11 April 2023
CVE-2023-21769Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityHIGH 7.5EPSS 88.7%11 April 2023
CVE-2023-21554Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 95.5%11 April 2023
CVE-2023-27179GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.HIGH 7.5EPSS 60.8%11 April 2023
CVE-2023-29186In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server.MEDIUM 6.5EPSS 23.0%11 April 2023
CVE-2023-28765An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file.CRITICAL 9.8EPSS 14.9%11 April 2023
CVE-2023-27267Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents.HIGH 8.1EPSS 14.2%11 April 2023
CVE-2023-28341Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.MEDIUM 6.1EPSS 98.7%11 April 2023
CVE-2023-27076Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.CRITICAL 9.8EPSS 22.9%10 April 2023
CVE-2023-26068Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).CRITICAL 9.8EPSS 11.6%10 April 2023
CVE-2023-26067Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).HIGH 8.1EPSS 37.8%10 April 2023
CVE-2023-28206Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write VulnerabilityKEVHIGH 8.6EPSS 23.0%10 April 2023
CVE-2023-28205Apple Multiple Products WebKit Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 27.1%10 April 2023
CVE-2023-0157The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that…MEDIUM 4.8EPSS 32.5%10 April 2023
CVE-2023-0156The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to…MEDIUM 4.9EPSS 19.9%10 April 2023
CVE-2023-29017A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.CRITICAL 9.8EPSS 63.2%6 April 2023
CVE-2023-28342Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.HIGH 7.5EPSS 78.3%5 April 2023
CVE-2023-20117Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system…HIGH 7.2EPSS 30.4%5 April 2023
CVE-2023-20128Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system…HIGH 7.2EPSS 30.4%5 April 2023
CVE-2023-20073A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device.CRITICAL 9.8EPSS 90.1%5 April 2023
CVE-2023-29374In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.CRITICAL 9.8EPSS 39.7%5 April 2023
CVE-2023-26775File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.HIGH 7.8EPSS 49.4%4 April 2023
CVE-2023-1671Sophos Web Appliance Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%4 April 2023
CVE-2023-26976Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.HIGH 7.5EPSS 15.9%4 April 2023
CVE-2022-43939Hitachi Vantara Pentaho BA Server Authorization Bypass VulnerabilityKEVCRITICAL 9.8EPSS 92.3%3 April 2023
CVE-2022-43938Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.HIGH 8.8EPSS 26.4%3 April 2023
CVE-2022-43771Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of…MEDIUM 6.5EPSS 23.9%3 April 2023
CVE-2022-43773Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.HIGH 8.8EPSS 22.2%3 April 2023
CVE-2022-43769Hitachi Vantara Pentaho BA Server Special Element Injection VulnerabilityKEVHIGH 7.2EPSS 97.7%3 April 2023
CVE-2022-27665Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0.MEDIUM 6.1EPSS 33.1%3 April 2023
CVE-2023-27159Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon.HIGH 7.5EPSS 36.4%31 March 2023
CVE-2022-43473A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168.MEDIUM 5.4EPSS 19.8%30 March 2023
CVE-2023-25076A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba).CRITICAL 9.8EPSS 65.8%30 March 2023
CVE-2023-28503Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged…CRITICAL 9.8EPSS 62.1%29 March 2023
CVE-2023-28502Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.CRITICAL 9.8EPSS 61.1%29 March 2023
CVE-2022-43650This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0.HIGH 7.1EPSS 23.0%29 March 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.