Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 59 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-4302 | The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | HIGH 7.2EPSS 17.7% | 2 January 2023 |
| CVE-2022-42475 | Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 2 January 2023 |
| CVE-2022-34324 | Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History. | HIGH 8.8EPSS 11.9% | 1 January 2023 |
| CVE-2023-0028 | Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+. | MEDIUM 5.4EPSS 56.0% | 1 January 2023 |
| CVE-2022-43396 | But there is a risk of being bypassed. | HIGH 8.8EPSS 55.3% | 30 December 2022 |
| CVE-2022-4855 | A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. | CRITICAL 9.8EPSS 24.6% | 30 December 2022 |
| CVE-2022-48194 | TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate. | HIGH 8.8EPSS 33.5% | 30 December 2022 |
| CVE-2022-4732 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | HIGH 7.2EPSS 38.2% | 27 December 2022 |
| CVE-2022-4120 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a… | CRITICAL 9.8EPSS 18.1% | 26 December 2022 |
| CVE-2021-45467 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts=… | CRITICAL 9.8EPSS 70.7% | 26 December 2022 |
| CVE-2021-45466 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder. | CRITICAL 9.8EPSS 55.3% | 26 December 2022 |
| CVE-2022-40005 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute. | HIGH 8.8EPSS 34.8% | 25 December 2022 |
| CVE-2022-47949 | The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. | CRITICAL 9.8EPSS 22.3% | 24 December 2022 |
| CVE-2022-47945 | ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). | CRITICAL 9.8EPSS 28.3% | 23 December 2022 |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. | HIGH 7.5EPSS 46.0% | 23 December 2022 |
| CVE-2022-45711 | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function. | CRITICAL 9.8EPSS 20.2% | 23 December 2022 |
| CVE-2022-47939 | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT. | CRITICAL 9.8EPSS 46.4% | 23 December 2022 |
| CVE-2022-47938 | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT. | MEDIUM 6.5EPSS 60.0% | 23 December 2022 |
| CVE-2022-43551 | A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. | HIGH 7.5EPSS 16.5% | 23 December 2022 |
| CVE-2022-23513 | In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. | MEDIUM 5.3EPSS 40.2% | 23 December 2022 |
| CVE-2022-2200 | If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. | HIGH 8.8EPSS 23.9% | 22 December 2022 |
| CVE-2022-26485 | Mozilla Firefox Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 14.3% | 22 December 2022 |
| CVE-2022-1802 | If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. | HIGH 8.8EPSS 26.7% | 22 December 2022 |
| CVE-2022-1529 | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. | HIGH 8.8EPSS 17.1% | 22 December 2022 |
| CVE-2022-41697 | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. | MEDIUM 5.3EPSS 20.0% | 22 December 2022 |
| CVE-2022-41654 | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. | MEDIUM 4.3EPSS 18.9% | 22 December 2022 |
| CVE-2022-3184 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the… | CRITICAL 9.8EPSS 11.6% | 21 December 2022 |
| CVE-2022-46020 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | CRITICAL 9.8EPSS 39.0% | 20 December 2022 |
| CVE-2022-40624 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | CRITICAL 9.8EPSS 17.1% | 20 December 2022 |
| CVE-2022-45942 | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. | HIGH 8.8EPSS 22.0% | 20 December 2022 |
| CVE-2022-44456 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. | CRITICAL 9.8EPSS 69.9% | 19 December 2022 |
| CVE-2022-4606 | PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. | CRITICAL 9.8EPSS 35.4% | 18 December 2022 |
| CVE-2022-46689 | A race condition was addressed with additional validation. | HIGH 7.0EPSS 44.7% | 15 December 2022 |
| CVE-2022-42867 | A use after free issue was addressed with improved memory management. | HIGH 8.8EPSS 34.8% | 15 December 2022 |
| CVE-2022-29517 | A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. | HIGH 8.8EPSS 57.6% | 15 December 2022 |
| CVE-2022-27498 | A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. | MEDIUM 6.5EPSS 38.3% | 15 December 2022 |
| CVE-2022-46768 | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. | MEDIUM 5.9EPSS 47.8% | 15 December 2022 |
| CVE-2022-38488 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | CRITICAL 9.8EPSS 14.2% | 14 December 2022 |
| CVE-2022-46443 | mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter. | HIGH 8.8EPSS 37.7% | 14 December 2022 |
| CVE-2022-42139 | Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL. | HIGH 8.8EPSS 18.2% | 14 December 2022 |
| CVE-2022-37155 | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. | HIGH 8.8EPSS 40.0% | 14 December 2022 |
| CVE-2022-44698 | Microsoft Defender SmartScreen Security Feature Bypass Vulnerability | KEVMEDIUM 5.4EPSS 76.3% | 13 December 2022 |
| CVE-2022-44690 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 82.1% | 13 December 2022 |
| CVE-2022-44666 | Windows Contacts Remote Code Execution Vulnerability | HIGH 7.8EPSS 41.4% | 13 December 2022 |
| CVE-2022-41076 | PowerShell Remote Code Execution Vulnerability | HIGH 8.5EPSS 60.5% | 13 December 2022 |
| CVE-2022-4223 | The utility is executed by the server to determine what PostgreSQL version it is from. | HIGH 8.8EPSS 80.1% | 13 December 2022 |
| CVE-2022-31698 | The vCenter Server contains a denial-of-service vulnerability in the content library service. | MEDIUM 5.3EPSS 47.8% | 13 December 2022 |
| CVE-2022-45275 | An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | HIGH 7.2EPSS 15.3% | 12 December 2022 |
| CVE-2022-3921 | The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE | CRITICAL 9.8EPSS 21.2% | 12 December 2022 |
| CVE-2022-3900 | The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability. | CRITICAL 9.8EPSS 19.0% | 12 December 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.