SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,634 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 57 of 348

CVESummaryPriorityPublished
CVE-2022-44268ImageMagick 7.1.0-49 is vulnerable to Information Disclosure.MEDIUM 6.5EPSS 89.9%6 February 2023
CVE-2022-44267ImageMagick 7.1.0-49 is vulnerable to Denial of Service.MEDIUM 6.5EPSS 76.6%6 February 2023
CVE-2023-0669Fortra GoAnywhere MFT Remote Code Execution VulnerabilityKEVHIGH 7.2EPSS 100.0%6 February 2023
CVE-2023-0234The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.HIGH 8.8EPSS 18.0%6 February 2023
CVE-2022-47071In NVS365 V01, the background network test function can trigger command execution.CRITICAL 9.8EPSS 25.9%6 February 2023
CVE-2023-0678Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.MEDIUM 5.3EPSS 37.3%4 February 2023
CVE-2023-25136OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.MEDIUM 6.5EPSS 89.7%3 February 2023
CVE-2023-25135vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization.CRITICAL 9.8EPSS 23.9%3 February 2023
CVE-2022-46552D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter.HIGH 8.8EPSS 10.5%2 February 2023
CVE-2023-23076OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.CRITICAL 9.8EPSS 74.3%1 February 2023
CVE-2023-23074Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.MEDIUM 6.1EPSS 83.6%1 February 2023
CVE-2023-23969This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.HIGH 7.5EPSS 47.4%1 February 2023
CVE-2023-22501An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access…CRITICAL 9.1EPSS 15.5%1 February 2023
CVE-2023-22374A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code.HIGH 8.5EPSS 72.6%1 February 2023
CVE-2023-0587A file upload vulnerability in exists in Trend Micro Apex One server build 11110.CRITICAL 9.1EPSS 59.6%1 February 2023
CVE-2022-4395The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.CRITICAL 9.8EPSS 17.6%30 January 2023
CVE-2023-0563A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0.MEDIUM 4.8EPSS 37.6%28 January 2023
CVE-2023-0562A vulnerability was found in PHPGurukul Bank Locker Management System 1.0.CRITICAL 9.8EPSS 44.3%28 January 2023
CVE-2023-0448The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.MEDIUM 6.1EPSS 42.9%26 January 2023
CVE-2022-4510A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included.HIGH 7.8EPSS 22.0%26 January 2023
CVE-2022-3924This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero.HIGH 7.5EPSS 16.1%26 January 2023
CVE-2022-3736BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query.HIGH 7.5EPSS 48.7%26 January 2023
CVE-2022-3488Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the…HIGH 7.5EPSS 19.2%26 January 2023
CVE-2022-3094The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes.HIGH 7.5EPSS 13.2%26 January 2023
CVE-2022-31711VMware vRealize Log Insight contains an Information Disclosure Vulnerability.MEDIUM 5.3EPSS 21.7%26 January 2023
CVE-2022-31706The vRealize Log Insight contains a Directory Traversal Vulnerability.CRITICAL 9.8EPSS 87.1%26 January 2023
CVE-2022-31704The vRealize Log Insight contains a broken access control vulnerability.CRITICAL 9.8EPSS 81.0%26 January 2023
CVE-2022-29844A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files.CRITICAL 9.8EPSS 36.4%26 January 2023
CVE-2022-41142This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.HIGH 8.8EPSS 85.0%26 January 2023
CVE-2023-23560In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.CRITICAL 9.8EPSS 13.9%23 January 2023
CVE-2023-22960Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.HIGH 7.5EPSS 27.8%23 January 2023
CVE-2022-4305The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.CRITICAL 9.8EPSS 38.6%23 January 2023
CVE-2022-4230The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks.HIGH 8.8EPSS 35.7%23 January 2023
CVE-2023-22884Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1;…CRITICAL 9.8EPSS 11.1%21 January 2023
CVE-2023-23492The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.HIGH 8.8EPSS 57.1%20 January 2023
CVE-2023-22458Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure.MEDIUM 5.5EPSS 72.0%20 January 2023
CVE-2022-35977Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic.MEDIUM 5.5EPSS 13.5%20 January 2023
CVE-2023-23489The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.CRITICAL 9.8EPSS 11.2%20 January 2023
CVE-2023-23488The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.CRITICAL 9.8EPSS 92.5%20 January 2023
CVE-2023-23596jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection.HIGH 8.8EPSS 15.2%20 January 2023
CVE-2022-20966A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface.MEDIUM 5.4EPSS 27.6%20 January 2023
CVE-2022-20964A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.HIGH 8.8EPSS 30.6%20 January 2023
CVE-2022-46476D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.CRITICAL 9.8EPSS 41.1%19 January 2023
CVE-2023-0126Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.HIGH 7.5EPSS 72.7%19 January 2023
CVE-2022-46889A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php.MEDIUM 5.4EPSS 60.1%19 January 2023
CVE-2022-46887Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.CRITICAL 9.8EPSS 19.4%19 January 2023
CVE-2022-47745ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.HIGH 8.8EPSS 15.4%19 January 2023
CVE-2022-45926The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.HIGH 8.8EPSS 17.0%18 January 2023
CVE-2022-45925If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.HIGH 7.5EPSS 16.9%18 January 2023
CVE-2023-21608Adobe Acrobat and Reader Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 61.5%18 January 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.