Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,633 CVEs1,711 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 53 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-38841 | Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. | HIGH 8.8EPSS 10.7% | 16 April 2023 |
| CVE-2023-2033 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 40.8% | 14 April 2023 |
| CVE-2022-47501 | Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. | HIGH 7.5EPSS 10.2% | 14 April 2023 |
| CVE-2023-29804 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | HIGH 8.8EPSS 17.5% | 14 April 2023 |
| CVE-2023-2034 | Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. | HIGH 8.8EPSS 71.4% | 14 April 2023 |
| CVE-2023-29084 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | HIGH 7.2EPSS 98.2% | 13 April 2023 |
| CVE-2023-20118 | Cisco Small Business RV Series Routers Command Injection Vulnerability | KEVHIGH 7.2EPSS 54.1% | 13 April 2023 |
| CVE-2023-28121 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. | CRITICAL 9.8EPSS 86.5% | 12 April 2023 |
| CVE-2023-27826 | SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function. | HIGH 8.8EPSS 11.8% | 12 April 2023 |
| CVE-2023-28302 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH 7.5EPSS 92.6% | 11 April 2023 |
| CVE-2023-28252 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 49.0% | 11 April 2023 |
| CVE-2023-28231 | DHCP Server Service Remote Code Execution Vulnerability | HIGH 8.8EPSS 36.9% | 11 April 2023 |
| CVE-2023-28220 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH 8.1EPSS 15.0% | 11 April 2023 |
| CVE-2023-28219 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | HIGH 8.1EPSS 15.0% | 11 April 2023 |
| CVE-2023-28218 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH 7.0EPSS 12.3% | 11 April 2023 |
| CVE-2023-21769 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH 7.5EPSS 88.7% | 11 April 2023 |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 95.5% | 11 April 2023 |
| CVE-2023-27179 | GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php. | HIGH 7.5EPSS 60.8% | 11 April 2023 |
| CVE-2023-29186 | In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. | MEDIUM 6.5EPSS 23.0% | 11 April 2023 |
| CVE-2023-28765 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. | CRITICAL 9.8EPSS 14.9% | 11 April 2023 |
| CVE-2023-27267 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. | HIGH 8.1EPSS 14.2% | 11 April 2023 |
| CVE-2023-28341 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | MEDIUM 6.1EPSS 98.7% | 11 April 2023 |
| CVE-2023-27076 | Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. | CRITICAL 9.8EPSS 22.9% | 10 April 2023 |
| CVE-2023-26068 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). | CRITICAL 9.8EPSS 11.6% | 10 April 2023 |
| CVE-2023-26067 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | HIGH 8.1EPSS 37.8% | 10 April 2023 |
| CVE-2023-28206 | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | KEVHIGH 8.6EPSS 23.0% | 10 April 2023 |
| CVE-2023-28205 | Apple Multiple Products WebKit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 27.1% | 10 April 2023 |
| CVE-2023-0157 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that… | MEDIUM 4.8EPSS 32.5% | 10 April 2023 |
| CVE-2023-0156 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to… | MEDIUM 4.9EPSS 19.9% | 10 April 2023 |
| CVE-2023-29017 | A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. | CRITICAL 9.8EPSS 63.2% | 6 April 2023 |
| CVE-2023-28342 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | HIGH 7.5EPSS 78.3% | 5 April 2023 |
| CVE-2023-20117 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system… | HIGH 7.2EPSS 30.4% | 5 April 2023 |
| CVE-2023-20128 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system… | HIGH 7.2EPSS 30.4% | 5 April 2023 |
| CVE-2023-20073 | A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. | CRITICAL 9.8EPSS 90.1% | 5 April 2023 |
| CVE-2023-29374 | In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. | CRITICAL 9.8EPSS 39.7% | 5 April 2023 |
| CVE-2023-26775 | File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint. | HIGH 7.8EPSS 49.4% | 4 April 2023 |
| CVE-2023-1671 | Sophos Web Appliance Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 April 2023 |
| CVE-2023-26976 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | HIGH 7.5EPSS 15.9% | 4 April 2023 |
| CVE-2022-43939 | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability | KEVCRITICAL 9.8EPSS 92.3% | 3 April 2023 |
| CVE-2022-43938 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. | HIGH 8.8EPSS 26.4% | 3 April 2023 |
| CVE-2022-43771 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of… | MEDIUM 6.5EPSS 23.9% | 3 April 2023 |
| CVE-2022-43773 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled. | HIGH 8.8EPSS 22.2% | 3 April 2023 |
| CVE-2022-43769 | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability | KEVHIGH 7.2EPSS 97.7% | 3 April 2023 |
| CVE-2022-27665 | Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. | MEDIUM 6.1EPSS 33.1% | 3 April 2023 |
| CVE-2023-27159 | Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. | HIGH 7.5EPSS 36.4% | 31 March 2023 |
| CVE-2022-43473 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. | MEDIUM 5.4EPSS 19.8% | 30 March 2023 |
| CVE-2023-25076 | A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). | CRITICAL 9.8EPSS 65.8% | 30 March 2023 |
| CVE-2023-28503 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged… | CRITICAL 9.8EPSS 62.1% | 29 March 2023 |
| CVE-2023-28502 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. | CRITICAL 9.8EPSS 61.1% | 29 March 2023 |
| CVE-2022-43650 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. | HIGH 7.1EPSS 23.0% | 29 March 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.