SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 59 of 348

CVESummaryPriorityPublished
CVE-2022-4302The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.HIGH 7.2EPSS 17.7%2 January 2023
CVE-2022-42475Fortinet FortiOS Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 99.5%2 January 2023
CVE-2022-34324Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History.HIGH 8.8EPSS 11.9%1 January 2023
CVE-2023-0028Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.MEDIUM 5.4EPSS 56.0%1 January 2023
CVE-2022-43396But there is a risk of being bypassed.HIGH 8.8EPSS 55.3%30 December 2022
CVE-2022-4855A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0.CRITICAL 9.8EPSS 24.6%30 December 2022
CVE-2022-48194TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.HIGH 8.8EPSS 33.5%30 December 2022
CVE-2022-4732Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.HIGH 7.2EPSS 38.2%27 December 2022
CVE-2022-4120The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a…CRITICAL 9.8EPSS 18.1%26 December 2022
CVE-2021-45467In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts=…CRITICAL 9.8EPSS 70.7%26 December 2022
CVE-2021-45466In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.CRITICAL 9.8EPSS 55.3%26 December 2022
CVE-2022-40005Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.HIGH 8.8EPSS 34.8%25 December 2022
CVE-2022-47949The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn.CRITICAL 9.8EPSS 22.3%24 December 2022
CVE-2022-47945ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true).CRITICAL 9.8EPSS 28.3%23 December 2022
CVE-2022-23854AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.HIGH 7.5EPSS 46.0%23 December 2022
CVE-2022-45711IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.CRITICAL 9.8EPSS 20.2%23 December 2022
CVE-2022-47939An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.CRITICAL 9.8EPSS 46.4%23 December 2022
CVE-2022-47938An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT.MEDIUM 6.5EPSS 60.0%23 December 2022
CVE-2022-43551A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP.HIGH 7.5EPSS 16.5%23 December 2022
CVE-2022-23513In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint.MEDIUM 5.3EPSS 40.2%23 December 2022
CVE-2022-2200If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution.HIGH 8.8EPSS 23.9%22 December 2022
CVE-2022-26485Mozilla Firefox Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 14.3%22 December 2022
CVE-2022-1802If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context.HIGH 8.8EPSS 26.7%22 December 2022
CVE-2022-1529An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process.HIGH 8.8EPSS 17.1%22 December 2022
CVE-2022-41697A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4.MEDIUM 5.3EPSS 20.0%22 December 2022
CVE-2022-41654An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4.MEDIUM 4.3EPSS 18.9%22 December 2022
CVE-2022-3184Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the…CRITICAL 9.8EPSS 11.6%21 December 2022
CVE-2022-46020WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.CRITICAL 9.8EPSS 39.0%20 December 2022
CVE-2022-40624pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.CRITICAL 9.8EPSS 17.1%20 December 2022
CVE-2022-45942A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.HIGH 8.8EPSS 22.0%20 December 2022
CVE-2022-44456CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.CRITICAL 9.8EPSS 69.9%19 December 2022
CVE-2022-4606PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.CRITICAL 9.8EPSS 35.4%18 December 2022
CVE-2022-46689A race condition was addressed with additional validation.HIGH 7.0EPSS 44.7%15 December 2022
CVE-2022-42867A use after free issue was addressed with improved memory management.HIGH 8.8EPSS 34.8%15 December 2022
CVE-2022-29517A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0.HIGH 8.8EPSS 57.6%15 December 2022
CVE-2022-27498A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0.MEDIUM 6.5EPSS 38.3%15 December 2022
CVE-2022-46768Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053.MEDIUM 5.9EPSS 47.8%15 December 2022
CVE-2022-38488logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.CRITICAL 9.8EPSS 14.2%14 December 2022
CVE-2022-46443mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.HIGH 8.8EPSS 37.7%14 December 2022
CVE-2022-42139Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.HIGH 8.8EPSS 18.2%14 December 2022
CVE-2022-37155RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.HIGH 8.8EPSS 40.0%14 December 2022
CVE-2022-44698Microsoft Defender SmartScreen Security Feature Bypass VulnerabilityKEVMEDIUM 5.4EPSS 76.3%13 December 2022
CVE-2022-44690Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 82.1%13 December 2022
CVE-2022-44666Windows Contacts Remote Code Execution VulnerabilityHIGH 7.8EPSS 41.4%13 December 2022
CVE-2022-41076PowerShell Remote Code Execution VulnerabilityHIGH 8.5EPSS 60.5%13 December 2022
CVE-2022-4223The utility is executed by the server to determine what PostgreSQL version it is from.HIGH 8.8EPSS 80.1%13 December 2022
CVE-2022-31698The vCenter Server contains a denial-of-service vulnerability in the content library service.MEDIUM 5.3EPSS 47.8%13 December 2022
CVE-2022-45275An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.HIGH 7.2EPSS 15.3%12 December 2022
CVE-2022-3921The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCECRITICAL 9.8EPSS 21.2%12 December 2022
CVE-2022-3900The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.CRITICAL 9.8EPSS 19.0%12 December 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.