SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 56 of 348

CVESummaryPriorityPublished
CVE-2023-25157GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.CRITICAL 9.8EPSS 85.2%21 February 2023
CVE-2023-24998Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.HIGH 7.5EPSS 48.8%20 February 2023
CVE-2023-22232Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.MEDIUM 5.3EPSS 81.9%17 February 2023
CVE-2022-47986IBM Aspera Faspex Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%17 February 2023
CVE-2023-24329An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.HIGH 7.5EPSS 20.5%17 February 2023
CVE-2022-45701Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.HIGH 8.8EPSS 42.6%17 February 2023
CVE-2022-40032SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.CRITICAL 9.8EPSS 20.7%17 February 2023
CVE-2023-24078Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.HIGH 8.8EPSS 53.0%17 February 2023
CVE-2022-39952A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to…CRITICAL 9.8EPSS 99.8%16 February 2023
CVE-2021-42756Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to…CRITICAL 9.8EPSS 35.0%16 February 2023
CVE-2023-23752Joomla! Improper Access Control VulnerabilityKEVMEDIUM 5.3EPSS 99.8%16 February 2023
CVE-2023-0861NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input.HIGH 8.8EPSS 28.7%16 February 2023
CVE-2023-22855Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution.CRITICAL 9.8EPSS 14.8%15 February 2023
CVE-2023-23836SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 80.3%15 February 2023
CVE-2022-47504SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 25.1%15 February 2023
CVE-2022-47503SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 24.4%15 February 2023
CVE-2022-38111SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 84.8%15 February 2023
CVE-2023-25762Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job…MEDIUM 5.4EPSS 81.4%15 February 2023
CVE-2023-24580Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.HIGH 7.5EPSS 62.6%15 February 2023
CVE-2023-23376Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 10.9%14 February 2023
CVE-2023-22629The move-file function has a path traversal vulnerability in the newPath parameter.HIGH 8.8EPSS 12.3%14 February 2023
CVE-2023-21819Windows Secure Channel Denial of Service VulnerabilityHIGH 7.5EPSS 30.8%14 February 2023
CVE-2023-21818Windows Secure Channel Denial of Service VulnerabilityHIGH 7.5EPSS 43.2%14 February 2023
CVE-2023-21716Microsoft Word Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 82.3%14 February 2023
CVE-2023-21715Microsoft Office Publisher Security Feature Bypass VulnerabilityKEVHIGH 7.3EPSS 12.0%14 February 2023
CVE-2023-21707Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 82.0%14 February 2023
CVE-2023-21692Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 21.2%14 February 2023
CVE-2023-21690Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 27.5%14 February 2023
CVE-2023-21689Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 26.5%14 February 2023
CVE-2023-21529Microsoft Exchange Server Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 62.1%14 February 2023
CVE-2023-0830A vulnerability classified as critical has been found in EasyNAS 1.1.0.MEDIUM 5.3EPSS 20.9%14 February 2023
CVE-2023-25717Multiple Ruckus Wireless Products CSRF and RCE VulnerabilityKEVCRITICAL 9.8EPSS 98.1%13 February 2023
CVE-2023-0159The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary…HIGH 7.5EPSS 55.5%13 February 2023
CVE-2022-4830The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site…MEDIUM 5.4EPSS 65.0%13 February 2023
CVE-2022-40022Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.CRITICAL 9.8EPSS 92.5%13 February 2023
CVE-2022-48323Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue.CRITICAL 9.8EPSS 56.8%13 February 2023
CVE-2023-0777Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.CRITICAL 9.8EPSS 15.2%10 February 2023
CVE-2022-46650Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.MEDIUM 4.9EPSS 12.3%10 February 2023
CVE-2022-45699Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.CRITICAL 9.8EPSS 76.6%10 February 2023
CVE-2023-24322A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.MEDIUM 6.1EPSS 31.7%9 February 2023
CVE-2023-21434Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.MEDIUM 6.1EPSS 12.9%9 February 2023
CVE-2023-0286There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName.HIGH 7.4EPSS 59.5%8 February 2023
CVE-2022-4450This will most likely lead to a crash.HIGH 7.5EPSS 20.4%8 February 2023
CVE-2022-4304To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption.MEDIUM 5.9EPSS 16.2%8 February 2023
CVE-2022-45768Command Injection vulnerability in Edimax Technology Co., Ltd.HIGH 8.8EPSS 28.7%7 February 2023
CVE-2023-25194A possible security vulnerability has been identified in Apache Kafka Connect API.HIGH 8.8EPSS 95.8%7 February 2023
CVE-2022-24990TerraMaster OS Remote Command Execution VulnerabilityKEVHIGH 7.5EPSS 83.6%7 February 2023
CVE-2022-40224A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1.HIGH 7.5EPSS 64.7%7 February 2023
CVE-2022-3229Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage…CRITICAL 9.8EPSS 66.4%6 February 2023
CVE-2023-23333There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.CRITICAL 9.8EPSS 99.3%6 February 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.