SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 55 of 348

CVESummaryPriorityPublished
CVE-2023-24880Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVMEDIUM 4.4EPSS 78.2%14 March 2023
CVE-2023-23397Microsoft Office Outlook Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 97.4%14 March 2023
CVE-2023-23383Service Fabric Explorer Spoofing VulnerabilityMEDIUM 4.7EPSS 11.7%14 March 2023
CVE-2022-39214Combodo iTop is an open source, web-based IT service management platform.HIGH 7.5EPSS 25.6%14 March 2023
CVE-2023-25279OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.CRITICAL 9.8EPSS 31.0%13 March 2023
CVE-2022-31474Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.HIGH 7.5EPSS 63.8%13 March 2023
CVE-2023-24033The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.CRITICAL 9.8EPSS 33.2%13 March 2023
CVE-2023-27532Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function VulnerabilityKEVHIGH 7.5EPSS 77.6%10 March 2023
CVE-2022-44574An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.HIGH 7.5EPSS 64.8%10 March 2023
CVE-2023-27853NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.CRITICAL 9.8EPSS 19.7%10 March 2023
CVE-2023-0050A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.MEDIUM 5.4EPSS 92.4%9 March 2023
CVE-2023-25573In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication.HIGH 7.5EPSS 51.6%9 March 2023
CVE-2023-27482A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered.CRITICAL 10.0EPSS 72.0%8 March 2023
CVE-2023-24775Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.CRITICAL 9.8EPSS 19.8%7 March 2023
CVE-2022-41328Fortinet FortiOS Path Traversal VulnerabilityKEVHIGH 7.1EPSS 10.7%7 March 2023
CVE-2023-25690Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.CRITICAL 9.8EPSS 84.5%7 March 2023
CVE-2023-26601Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).HIGH 7.5EPSS 34.1%6 March 2023
CVE-2023-24734An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.CRITICAL 9.8EPSS 20.7%6 March 2023
CVE-2021-36393In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.CRITICAL 9.8EPSS 52.3%6 March 2023
CVE-2023-20079Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.HIGH 7.5EPSS 10.3%3 March 2023
CVE-2023-20078Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.CRITICAL 9.8EPSS 10.4%3 March 2023
CVE-2022-45551An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.CRITICAL 9.8EPSS 23.6%3 March 2023
CVE-2023-1162** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5.HIGH 8.8EPSS 26.0%3 March 2023
CVE-2023-0656A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.HIGH 7.5EPSS 41.3%2 March 2023
CVE-2023-26475Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context.HIGH 8.8EPSS 63.6%2 March 2023
CVE-2023-0084The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping.MEDIUM 6.1EPSS 28.6%2 March 2023
CVE-2023-26477Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional parameters.CRITICAL 9.8EPSS 74.8%2 March 2023
CVE-2023-0507Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.MEDIUM 5.4EPSS 15.5%1 March 2023
CVE-2022-36021Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time.MEDIUM 5.5EPSS 60.5%1 March 2023
CVE-2023-20032On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an…CRITICAL 9.8EPSS 29.3%1 March 2023
CVE-2022-47075An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.HIGH 7.5EPSS 59.4%28 February 2023
CVE-2023-27372SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled.CRITICAL 9.8EPSS 99.7%28 February 2023
CVE-2023-27293Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission.MEDIUM 6.1EPSS 57.0%28 February 2023
CVE-2023-26256An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira.HIGH 7.5EPSS 11.6%28 February 2023
CVE-2023-26255An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira.HIGH 7.5EPSS 47.2%28 February 2023
CVE-2022-22582A local user may be able to write arbitrary files.MEDIUM 5.5EPSS 17.7%27 February 2023
CVE-2023-25235Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.HIGH 7.5EPSS 11.1%27 February 2023
CVE-2023-25234Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.CRITICAL 9.8EPSS 16.6%27 February 2023
CVE-2023-0552The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerabilityMEDIUM 5.4EPSS 24.3%27 February 2023
CVE-2023-26609ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.HIGH 7.2EPSS 38.7%27 February 2023
CVE-2023-26602ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.CRITICAL 9.8EPSS 17.4%26 February 2023
CVE-2022-2024OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.CRITICAL 9.8EPSS 97.8%25 February 2023
CVE-2023-26035Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization.CRITICAL 9.8EPSS 80.5%25 February 2023
CVE-2023-1034Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.HIGH 8.8EPSS 28.1%25 February 2023
CVE-2023-1009** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5.MEDIUM 5.5EPSS 15.7%24 February 2023
CVE-2023-0755The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.CRITICAL 9.8EPSS 11.8%23 February 2023
CVE-2022-48343In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.MEDIUM 6.1EPSS 59.5%23 February 2023
CVE-2023-0104The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.HIGH 7.8EPSS 21.8%22 February 2023
CVE-2022-29273pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.MEDIUM 6.1EPSS 59.6%22 February 2023
CVE-2023-20858VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability.HIGH 7.2EPSS 16.9%22 February 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.