SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 60 of 348

CVESummaryPriorityPublished
CVE-2022-45957ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.HIGH 7.5EPSS 11.5%12 December 2022
CVE-2021-3437Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service.CRITICAL 9.8EPSS 15.6%12 December 2022
CVE-2022-45504An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.HIGH 7.5EPSS 18.3%8 December 2022
CVE-2022-46770qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through…HIGH 7.5EPSS 21.5%7 December 2022
CVE-2022-41800In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.HIGH 8.7EPSS 76.9%7 December 2022
CVE-2022-41622In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.HIGH 8.8EPSS 92.3%7 December 2022
CVE-2022-45025Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.CRITICAL 9.8EPSS 34.8%7 December 2022
CVE-2022-45359Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.CRITICAL 9.8EPSS 13.5%6 December 2022
CVE-2020-6627The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a…CRITICAL 9.8EPSS 12.5%6 December 2022
CVE-2022-43548A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before…HIGH 8.1EPSS 14.6%5 December 2022
CVE-2022-46169Cacti Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.8%5 December 2022
CVE-2022-46164This vulnerability has been patched in version 2.6.1.CRITICAL 9.8EPSS 49.0%5 December 2022
CVE-2022-4262Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 16.0%2 December 2022
CVE-2022-4257A vulnerability was found in C-DATA Web Management System.CRITICAL 9.8EPSS 43.9%1 December 2022
CVE-2022-1471SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization.CRITICAL 9.8EPSS 99.6%1 December 2022
CVE-2022-4178Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 23.9%30 November 2022
CVE-2022-36964SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 8.8EPSS 16.8%29 November 2022
CVE-2022-44635Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code.HIGH 8.8EPSS 68.8%29 November 2022
CVE-2022-40799D-Link DNR-322L Download of Code Without Integrity Check VulnerabilityKEVHIGH 8.8EPSS 33.7%29 November 2022
CVE-2022-38900decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.HIGH 7.5EPSS 23.8%28 November 2022
CVE-2022-45933KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin.CRITICAL 9.8EPSS 51.7%27 November 2022
CVE-2022-24999qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used.HIGH 7.5EPSS 15.1%26 November 2022
CVE-2022-4135Google Chromium GPU Heap Buffer Overflow VulnerabilityKEVCRITICAL 9.6EPSS 31.9%25 November 2022
CVE-2021-43258CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads.HIGH 8.8EPSS 11.0%23 November 2022
CVE-2022-40770Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection.HIGH 7.2EPSS 81.3%23 November 2022
CVE-2020-23584Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that…CRITICAL 9.8EPSS 41.4%23 November 2022
CVE-2022-40303When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow.HIGH 7.5EPSS 22.8%23 November 2022
CVE-2022-4116A vulnerability was found in quarkus.CRITICAL 9.8EPSS 32.5%22 November 2022
CVE-2022-39066There is a SQL injection vulnerability in ZTE MF286R.HIGH 8.8EPSS 26.5%22 November 2022
CVE-2022-41223Mitel MiVoice Connect Code Injection VulnerabilityKEVMEDIUM 6.8EPSS 10.6%22 November 2022
CVE-2022-40765Mitel MiVoice Connect Command Injection VulnerabilityKEVMEDIUM 6.8EPSS 10.5%22 November 2022
CVE-2022-4069Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.MEDIUM 4.8EPSS 93.3%20 November 2022
CVE-2022-4068This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.MEDIUM 5.4EPSS 34.8%20 November 2022
CVE-2022-4067Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.MEDIUM 5.4EPSS 93.7%20 November 2022
CVE-2022-3562Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.MEDIUM 5.4EPSS 94.2%20 November 2022
CVE-2022-42904Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.HIGH 7.2EPSS 83.1%18 November 2022
CVE-2022-40881SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpCRITICAL 9.8EPSS 29.7%17 November 2022
CVE-2022-43781There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.CRITICAL 9.8EPSS 98.1%17 November 2022
CVE-2022-45402In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.MEDIUM 6.1EPSS 81.8%15 November 2022
CVE-2022-40843The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed.MEDIUM 4.9EPSS 28.8%15 November 2022
CVE-2022-37109patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.CRITICAL 9.8EPSS 49.5%14 November 2022
CVE-2022-40127A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter.HIGH 8.8EPSS 85.7%14 November 2022
CVE-2022-43672Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.CRITICAL 9.8EPSS 67.1%12 November 2022
CVE-2022-43671Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.CRITICAL 9.8EPSS 74.8%12 November 2022
CVE-2022-44088ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.CRITICAL 9.8EPSS 20.1%10 November 2022
CVE-2022-39396Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution.CRITICAL 9.8EPSS 38.7%10 November 2022
CVE-2022-3265A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.MEDIUM 5.4EPSS 86.3%9 November 2022
CVE-2022-41128Microsoft Windows Scripting Languages Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 24.6%9 November 2022
CVE-2022-41080Microsoft Exchange Server Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 77.3%9 November 2022
CVE-2022-31199Netwrix Auditor Insecure Object Deserialization VulnerabilityKEVCRITICAL 9.8EPSS 36.0%8 November 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.