Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 56 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-25157 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | CRITICAL 9.8EPSS 85.2% | 21 February 2023 |
| CVE-2023-24998 | Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. | HIGH 7.5EPSS 48.8% | 20 February 2023 |
| CVE-2023-22232 | Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | MEDIUM 5.3EPSS 81.9% | 17 February 2023 |
| CVE-2022-47986 | IBM Aspera Faspex Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 17 February 2023 |
| CVE-2023-24329 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | HIGH 7.5EPSS 20.5% | 17 February 2023 |
| CVE-2022-45701 | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. | HIGH 8.8EPSS 42.6% | 17 February 2023 |
| CVE-2022-40032 | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information. | CRITICAL 9.8EPSS 20.7% | 17 February 2023 |
| CVE-2023-24078 | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | HIGH 8.8EPSS 53.0% | 17 February 2023 |
| CVE-2022-39952 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to… | CRITICAL 9.8EPSS 99.8% | 16 February 2023 |
| CVE-2021-42756 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to… | CRITICAL 9.8EPSS 35.0% | 16 February 2023 |
| CVE-2023-23752 | Joomla! Improper Access Control Vulnerability | KEVMEDIUM 5.3EPSS 99.8% | 16 February 2023 |
| CVE-2023-0861 | NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. | HIGH 8.8EPSS 28.7% | 16 February 2023 |
| CVE-2023-22855 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. | CRITICAL 9.8EPSS 14.8% | 15 February 2023 |
| CVE-2023-23836 | SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 80.3% | 15 February 2023 |
| CVE-2022-47504 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 25.1% | 15 February 2023 |
| CVE-2022-47503 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 24.4% | 15 February 2023 |
| CVE-2022-38111 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 84.8% | 15 February 2023 |
| CVE-2023-25762 | Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job… | MEDIUM 5.4EPSS 81.4% | 15 February 2023 |
| CVE-2023-24580 | Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack. | HIGH 7.5EPSS 62.6% | 15 February 2023 |
| CVE-2023-23376 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 10.9% | 14 February 2023 |
| CVE-2023-22629 | The move-file function has a path traversal vulnerability in the newPath parameter. | HIGH 8.8EPSS 12.3% | 14 February 2023 |
| CVE-2023-21819 | Windows Secure Channel Denial of Service Vulnerability | HIGH 7.5EPSS 30.8% | 14 February 2023 |
| CVE-2023-21818 | Windows Secure Channel Denial of Service Vulnerability | HIGH 7.5EPSS 43.2% | 14 February 2023 |
| CVE-2023-21716 | Microsoft Word Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 82.3% | 14 February 2023 |
| CVE-2023-21715 | Microsoft Office Publisher Security Feature Bypass Vulnerability | KEVHIGH 7.3EPSS 12.0% | 14 February 2023 |
| CVE-2023-21707 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 82.0% | 14 February 2023 |
| CVE-2023-21692 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 21.2% | 14 February 2023 |
| CVE-2023-21690 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 27.5% | 14 February 2023 |
| CVE-2023-21689 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 26.5% | 14 February 2023 |
| CVE-2023-21529 | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 62.1% | 14 February 2023 |
| CVE-2023-0830 | A vulnerability classified as critical has been found in EasyNAS 1.1.0. | MEDIUM 5.3EPSS 20.9% | 14 February 2023 |
| CVE-2023-25717 | Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | KEVCRITICAL 9.8EPSS 98.1% | 13 February 2023 |
| CVE-2023-0159 | The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary… | HIGH 7.5EPSS 55.5% | 13 February 2023 |
| CVE-2022-4830 | The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site… | MEDIUM 5.4EPSS 65.0% | 13 February 2023 |
| CVE-2022-40022 | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. | CRITICAL 9.8EPSS 92.5% | 13 February 2023 |
| CVE-2022-48323 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. | CRITICAL 9.8EPSS 56.8% | 13 February 2023 |
| CVE-2023-0777 | Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | CRITICAL 9.8EPSS 15.2% | 10 February 2023 |
| CVE-2022-46650 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page. | MEDIUM 4.9EPSS 12.3% | 10 February 2023 |
| CVE-2022-45699 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. | CRITICAL 9.8EPSS 76.6% | 10 February 2023 |
| CVE-2023-24322 | A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters. | MEDIUM 6.1EPSS 31.7% | 9 February 2023 |
| CVE-2023-21434 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page. | MEDIUM 6.1EPSS 12.9% | 9 February 2023 |
| CVE-2023-0286 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. | HIGH 7.4EPSS 59.5% | 8 February 2023 |
| CVE-2022-4450 | This will most likely lead to a crash. | HIGH 7.5EPSS 20.4% | 8 February 2023 |
| CVE-2022-4304 | To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. | MEDIUM 5.9EPSS 16.2% | 8 February 2023 |
| CVE-2022-45768 | Command Injection vulnerability in Edimax Technology Co., Ltd. | HIGH 8.8EPSS 28.7% | 7 February 2023 |
| CVE-2023-25194 | A possible security vulnerability has been identified in Apache Kafka Connect API. | HIGH 8.8EPSS 95.8% | 7 February 2023 |
| CVE-2022-24990 | TerraMaster OS Remote Command Execution Vulnerability | KEVHIGH 7.5EPSS 83.6% | 7 February 2023 |
| CVE-2022-40224 | A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. | HIGH 7.5EPSS 64.7% | 7 February 2023 |
| CVE-2022-3229 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage… | CRITICAL 9.8EPSS 66.4% | 6 February 2023 |
| CVE-2023-23333 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | CRITICAL 9.8EPSS 99.3% | 6 February 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.