Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 54 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-43634 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. | CRITICAL 9.8EPSS 18.9% | 29 March 2023 |
| CVE-2022-42429 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. | HIGH 8.8EPSS 76.1% | 29 March 2023 |
| CVE-2022-42427 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. | HIGH 8.8EPSS 76.1% | 29 March 2023 |
| CVE-2022-42425 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. | HIGH 8.8EPSS 76.1% | 29 March 2023 |
| CVE-2022-42424 | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. | HIGH 8.8EPSS 76.1% | 29 March 2023 |
| CVE-2022-36982 | This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. | HIGH 7.5EPSS 73.8% | 29 March 2023 |
| CVE-2022-36981 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. | CRITICAL 9.8EPSS 83.4% | 29 March 2023 |
| CVE-2022-36980 | This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. | HIGH 8.1EPSS 83.1% | 29 March 2023 |
| CVE-2022-36974 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. | CRITICAL 9.8EPSS 84.5% | 29 March 2023 |
| CVE-2022-36971 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. | HIGH 8.8EPSS 15.0% | 29 March 2023 |
| CVE-2022-36969 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). | HIGH 7.1EPSS 13.8% | 29 March 2023 |
| CVE-2022-28685 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). | HIGH 7.8EPSS 17.2% | 29 March 2023 |
| CVE-2022-2560 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. | CRITICAL 9.1EPSS 77.7% | 29 March 2023 |
| CVE-2022-27643 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. | HIGH 8.8EPSS 25.1% | 29 March 2023 |
| CVE-2023-27394 | Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. | CRITICAL 9.8EPSS 17.6% | 28 March 2023 |
| CVE-2023-0210 | A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems. | HIGH 7.5EPSS 71.7% | 27 March 2023 |
| CVE-2023-22249 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. | MEDIUM 4.8EPSS 57.4% | 27 March 2023 |
| CVE-2023-1380 | This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service. | HIGH 7.1EPSS 16.5% | 27 March 2023 |
| CVE-2022-48428 | In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible | MEDIUM 5.4EPSS 68.0% | 27 March 2023 |
| CVE-2023-1133 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. | CRITICAL 9.8EPSS 50.0% | 27 March 2023 |
| CVE-2023-26802 | An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request. | CRITICAL 9.8EPSS 48.7% | 26 March 2023 |
| CVE-2023-26801 | LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg. | CRITICAL 9.8EPSS 69.7% | 26 March 2023 |
| CVE-2023-1177 | Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. | CRITICAL 9.8EPSS 69.7% | 24 March 2023 |
| CVE-2023-27034 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | CRITICAL 9.8EPSS 58.7% | 23 March 2023 |
| CVE-2023-26361 | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. | MEDIUM 4.9EPSS 58.7% | 23 March 2023 |
| CVE-2023-26360 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.6EPSS 97.3% | 23 March 2023 |
| CVE-2023-26359 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 17.0% | 23 March 2023 |
| CVE-2023-26496 | Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module. | CRITICAL 9.8EPSS 22.6% | 23 March 2023 |
| CVE-2023-26498 | Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module. | CRITICAL 9.8EPSS 22.6% | 23 March 2023 |
| CVE-2023-28662 | The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action. | CRITICAL 9.8EPSS 42.2% | 22 March 2023 |
| CVE-2023-28432 | MinIO Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 84.0% | 22 March 2023 |
| CVE-2023-1578 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. | HIGH 8.8EPSS 62.8% | 22 March 2023 |
| CVE-2023-27857 | An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation. | HIGH 7.5EPSS 18.3% | 22 March 2023 |
| CVE-2023-28725 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka… | CRITICAL 9.1EPSS 20.6% | 22 March 2023 |
| CVE-2023-27856 | In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. | HIGH 7.5EPSS 77.2% | 22 March 2023 |
| CVE-2023-27855 | In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. | CRITICAL 9.8EPSS 13.5% | 22 March 2023 |
| CVE-2023-24709 | An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters. | HIGH 7.5EPSS 44.2% | 21 March 2023 |
| CVE-2023-26497 | Memory corruption can occur when processing Session Description Negotiation for Video Configuration Attribute. | CRITICAL 9.8EPSS 22.6% | 21 March 2023 |
| CVE-2022-45124 | An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. | HIGH 7.5EPSS 13.4% | 20 March 2023 |
| CVE-2022-43663 | An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. | CRITICAL 9.8EPSS 14.0% | 20 March 2023 |
| CVE-2023-28425 | Redis is an in-memory database that persists on disk. | MEDIUM 5.5EPSS 55.0% | 20 March 2023 |
| CVE-2023-0631 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. | HIGH 8.8EPSS 60.5% | 20 March 2023 |
| CVE-2023-27253 | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml. | HIGH 8.8EPSS 89.5% | 17 March 2023 |
| CVE-2023-1454 | A vulnerability classified as critical has been found in jeecg-boot 3.5.0. | CRITICAL 9.8EPSS 35.8% | 17 March 2023 |
| CVE-2022-43605 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. | CRITICAL 9.8EPSS 14.4% | 16 March 2023 |
| CVE-2022-43604 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. | CRITICAL 9.8EPSS 14.4% | 16 March 2023 |
| CVE-2023-25280 | D-Link DIR-820 Router OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 16 March 2023 |
| CVE-2023-28461 | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 68.1% | 15 March 2023 |
| CVE-2023-1389 | TP-Link Archer AX-21 Command Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 15 March 2023 |
| CVE-2023-28343 | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. | CRITICAL 9.8EPSS 84.8% | 14 March 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.