SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 54 of 348

CVESummaryPriorityPublished
CVE-2022-43634This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.CRITICAL 9.8EPSS 18.9%29 March 2023
CVE-2022-42429This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.HIGH 8.8EPSS 76.1%29 March 2023
CVE-2022-42427This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.HIGH 8.8EPSS 76.1%29 March 2023
CVE-2022-42425This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.HIGH 8.8EPSS 76.1%29 March 2023
CVE-2022-42424This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.HIGH 8.8EPSS 76.1%29 March 2023
CVE-2022-36982This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101.HIGH 7.5EPSS 73.8%29 March 2023
CVE-2022-36981This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101.CRITICAL 9.8EPSS 83.4%29 March 2023
CVE-2022-36980This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490.HIGH 8.1EPSS 83.1%29 March 2023
CVE-2022-36974This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490.CRITICAL 9.8EPSS 84.5%29 March 2023
CVE-2022-36971This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490.HIGH 8.8EPSS 15.0%29 March 2023
CVE-2022-36969This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000).HIGH 7.1EPSS 13.8%29 March 2023
CVE-2022-28685This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000).HIGH 7.8EPSS 17.2%29 March 2023
CVE-2022-2560This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server.CRITICAL 9.1EPSS 77.7%29 March 2023
CVE-2022-27643This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.HIGH 8.8EPSS 25.1%29 March 2023
CVE-2023-27394Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability.CRITICAL 9.8EPSS 17.6%28 March 2023
CVE-2023-0210A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.HIGH 7.5EPSS 71.7%27 March 2023
CVE-2023-22249Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields.MEDIUM 4.8EPSS 57.4%27 March 2023
CVE-2023-1380This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.HIGH 7.1EPSS 16.5%27 March 2023
CVE-2022-48428In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possibleMEDIUM 5.4EPSS 68.0%27 March 2023
CVE-2023-1133Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default.CRITICAL 9.8EPSS 50.0%27 March 2023
CVE-2023-26802An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.CRITICAL 9.8EPSS 48.7%26 March 2023
CVE-2023-26801LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.CRITICAL 9.8EPSS 69.7%26 March 2023
CVE-2023-1177Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.CRITICAL 9.8EPSS 69.7%24 March 2023
CVE-2023-27034PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.CRITICAL 9.8EPSS 58.7%23 March 2023
CVE-2023-26361Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read.MEDIUM 4.9EPSS 58.7%23 March 2023
CVE-2023-26360Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.6EPSS 97.3%23 March 2023
CVE-2023-26359Adobe ColdFusion Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 17.0%23 March 2023
CVE-2023-26496Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.CRITICAL 9.8EPSS 22.6%23 March 2023
CVE-2023-26498Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.CRITICAL 9.8EPSS 22.6%23 March 2023
CVE-2023-28662The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.CRITICAL 9.8EPSS 42.2%22 March 2023
CVE-2023-28432MinIO Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 84.0%22 March 2023
CVE-2023-1578SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.HIGH 8.8EPSS 62.8%22 March 2023
CVE-2023-27857An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.HIGH 7.5EPSS 18.3%22 March 2023
CVE-2023-28725General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka…CRITICAL 9.1EPSS 20.6%22 March 2023
CVE-2023-27856In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer.HIGH 7.5EPSS 77.2%22 March 2023
CVE-2023-27855In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer.CRITICAL 9.8EPSS 13.5%22 March 2023
CVE-2023-24709An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.HIGH 7.5EPSS 44.2%21 March 2023
CVE-2023-26497Memory corruption can occur when processing Session Description Negotiation for Video Configuration Attribute.CRITICAL 9.8EPSS 22.6%21 March 2023
CVE-2022-45124An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05.HIGH 7.5EPSS 13.4%20 March 2023
CVE-2022-43663An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05.CRITICAL 9.8EPSS 14.0%20 March 2023
CVE-2023-28425Redis is an in-memory database that persists on disk.MEDIUM 5.5EPSS 55.0%20 March 2023
CVE-2023-0631The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.HIGH 8.8EPSS 60.5%20 March 2023
CVE-2023-27253A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.HIGH 8.8EPSS 89.5%17 March 2023
CVE-2023-1454A vulnerability classified as critical has been found in jeecg-boot 3.5.0.CRITICAL 9.8EPSS 35.8%17 March 2023
CVE-2022-43605An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c.CRITICAL 9.8EPSS 14.4%16 March 2023
CVE-2022-43604An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c.CRITICAL 9.8EPSS 14.4%16 March 2023
CVE-2023-25280D-Link DIR-820 Router OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 97.9%16 March 2023
CVE-2023-28461Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 68.1%15 March 2023
CVE-2023-1389TP-Link Archer AX-21 Command Injection VulnerabilityKEVHIGH 8.8EPSS 100.0%15 March 2023
CVE-2023-28343OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.CRITICAL 9.8EPSS 84.8%14 March 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.