Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 58 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-35326 | SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value. | CRITICAL 9.8EPSS 13.6% | 18 January 2023 |
| CVE-2022-47966 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 18 January 2023 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. | HIGH 7.8EPSS 55.4% | 18 January 2023 |
| CVE-2021-33959 | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service. | HIGH 7.5EPSS 15.0% | 18 January 2023 |
| CVE-2023-21887 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). | MEDIUM 4.9EPSS 43.4% | 18 January 2023 |
| CVE-2023-21839 | Oracle WebLogic Server Unspecified Vulnerability | KEVHIGH 7.5EPSS 99.9% | 18 January 2023 |
| CVE-2022-41903 | Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. | CRITICAL 9.8EPSS 44.3% | 17 January 2023 |
| CVE-2022-23521 | Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. | CRITICAL 9.8EPSS 56.3% | 17 January 2023 |
| CVE-2021-32837 | mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. | HIGH 7.5EPSS 28.9% | 17 January 2023 |
| CVE-2022-37436 | Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. | MEDIUM 5.3EPSS 61.0% | 17 January 2023 |
| CVE-2022-4101 | The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack. | CRITICAL 9.1EPSS 29.4% | 16 January 2023 |
| CVE-2022-4060 | The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it. | CRITICAL 9.8EPSS 42.7% | 16 January 2023 |
| CVE-2023-0324 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. | CRITICAL 9.8EPSS 18.8% | 16 January 2023 |
| CVE-2023-0315 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | HIGH 8.8EPSS 97.7% | 16 January 2023 |
| CVE-2023-23590 | Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request. | HIGH 7.5EPSS 26.4% | 15 January 2023 |
| CVE-2022-1812 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. | CRITICAL 9.8EPSS 30.8% | 14 January 2023 |
| CVE-2023-0297 | Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. | CRITICAL 9.8EPSS 95.9% | 14 January 2023 |
| CVE-2023-22496 | An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. | CRITICAL 9.8EPSS 36.2% | 14 January 2023 |
| CVE-2023-22480 | In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. | CRITICAL 9.8EPSS 66.8% | 14 January 2023 |
| CVE-2022-46502 | Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php. | CRITICAL 9.8EPSS 13.7% | 13 January 2023 |
| CVE-2022-25026 | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy. | HIGH 7.5EPSS 24.4% | 12 January 2023 |
| CVE-2022-4874 | Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. | HIGH 7.5EPSS 11.0% | 11 January 2023 |
| CVE-2023-22952 | Multiple SugarCRM Products Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 80.1% | 11 January 2023 |
| CVE-2023-22959 | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). | HIGH 8.8EPSS 13.7% | 11 January 2023 |
| CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH 7.8EPSS 65.4% | 10 January 2023 |
| CVE-2023-21758 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | HIGH 7.5EPSS 92.5% | 10 January 2023 |
| CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 55.8% | 10 January 2023 |
| CVE-2023-21674 | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 41.8% | 10 January 2023 |
| CVE-2023-21547 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | HIGH 7.5EPSS 89.3% | 10 January 2023 |
| CVE-2022-38393 | A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. | HIGH 7.5EPSS 18.8% | 10 January 2023 |
| CVE-2022-35401 | An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. | HIGH 8.1EPSS 20.8% | 10 January 2023 |
| CVE-2022-47083 | A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application. | HIGH 8.8EPSS 18.2% | 10 January 2023 |
| CVE-2022-46610 | 72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. | HIGH 8.8EPSS 18.1% | 10 January 2023 |
| CVE-2022-3792 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. | CRITICAL 9.8EPSS 14.2% | 10 January 2023 |
| CVE-2022-45092 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). | HIGH 8.8EPSS 31.4% | 10 January 2023 |
| CVE-2023-0017 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized… | CRITICAL 9.8EPSS 15.7% | 10 January 2023 |
| CVE-2022-4043 | The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | HIGH 7.2EPSS 17.7% | 9 January 2023 |
| CVE-2022-3416 | The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | HIGH 7.2EPSS 17.3% | 9 January 2023 |
| CVE-2022-43970 | A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. | HIGH 7.2EPSS 19.3% | 9 January 2023 |
| CVE-2022-44149 | The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. | HIGH 8.8EPSS 64.4% | 6 January 2023 |
| CVE-2022-42979 | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link. | HIGH 8.8EPSS 24.3% | 6 January 2023 |
| CVE-2022-44877 | CWP Control Web Panel OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 January 2023 |
| CVE-2022-47523 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. | CRITICAL 9.8EPSS 70.6% | 5 January 2023 |
| CVE-2023-22463 | The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. | CRITICAL 9.8EPSS 69.7% | 4 January 2023 |
| CVE-2023-22457 | Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. | HIGH 8.8EPSS 18.7% | 4 January 2023 |
| CVE-2023-0048 | Code Injection in GitHub repository lirantal/daloradius prior to master-branch. | HIGH 8.8EPSS 32.3% | 4 January 2023 |
| CVE-2022-43931 | Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors. | CRITICAL 10.0EPSS 16.8% | 3 January 2023 |
| CVE-2022-3842 | Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | HIGH 7.5EPSS 18.3% | 2 January 2023 |
| CVE-2021-30558 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. | HIGH 8.8EPSS 11.5% | 2 January 2023 |
| CVE-2022-4324 | The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a… | HIGH 7.2EPSS 17.7% | 2 January 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.