Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 60 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-45957 | ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow. | HIGH 7.5EPSS 11.5% | 12 December 2022 |
| CVE-2021-3437 | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. | CRITICAL 9.8EPSS 15.6% | 12 December 2022 |
| CVE-2022-45504 | An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device. | HIGH 7.5EPSS 18.3% | 8 December 2022 |
| CVE-2022-46770 | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through… | HIGH 7.5EPSS 21.5% | 7 December 2022 |
| CVE-2022-41800 | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. | HIGH 8.7EPSS 76.9% | 7 December 2022 |
| CVE-2022-41622 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. | HIGH 8.8EPSS 92.3% | 7 December 2022 |
| CVE-2022-45025 | Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function. | CRITICAL 9.8EPSS 34.8% | 7 December 2022 |
| CVE-2022-45359 | Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | CRITICAL 9.8EPSS 13.5% | 6 December 2022 |
| CVE-2020-6627 | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a… | CRITICAL 9.8EPSS 12.5% | 6 December 2022 |
| CVE-2022-43548 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before… | HIGH 8.1EPSS 14.6% | 5 December 2022 |
| CVE-2022-46169 | Cacti Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 5 December 2022 |
| CVE-2022-46164 | This vulnerability has been patched in version 2.6.1. | CRITICAL 9.8EPSS 49.0% | 5 December 2022 |
| CVE-2022-4262 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 16.0% | 2 December 2022 |
| CVE-2022-4257 | A vulnerability was found in C-DATA Web Management System. | CRITICAL 9.8EPSS 43.9% | 1 December 2022 |
| CVE-2022-1471 | SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. | CRITICAL 9.8EPSS 99.6% | 1 December 2022 |
| CVE-2022-4178 | Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 23.9% | 30 November 2022 |
| CVE-2022-36964 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 8.8EPSS 16.8% | 29 November 2022 |
| CVE-2022-44635 | Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. | HIGH 8.8EPSS 68.8% | 29 November 2022 |
| CVE-2022-40799 | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | KEVHIGH 8.8EPSS 33.7% | 29 November 2022 |
| CVE-2022-38900 | decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. | HIGH 7.5EPSS 23.8% | 28 November 2022 |
| CVE-2022-45933 | KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. | CRITICAL 9.8EPSS 51.7% | 27 November 2022 |
| CVE-2022-24999 | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. | HIGH 7.5EPSS 15.1% | 26 November 2022 |
| CVE-2022-4135 | Google Chromium GPU Heap Buffer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 31.9% | 25 November 2022 |
| CVE-2021-43258 | CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. | HIGH 8.8EPSS 11.0% | 23 November 2022 |
| CVE-2022-40770 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. | HIGH 7.2EPSS 81.3% | 23 November 2022 |
| CVE-2020-23584 | Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that… | CRITICAL 9.8EPSS 41.4% | 23 November 2022 |
| CVE-2022-40303 | When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. | HIGH 7.5EPSS 22.8% | 23 November 2022 |
| CVE-2022-4116 | A vulnerability was found in quarkus. | CRITICAL 9.8EPSS 32.5% | 22 November 2022 |
| CVE-2022-39066 | There is a SQL injection vulnerability in ZTE MF286R. | HIGH 8.8EPSS 26.5% | 22 November 2022 |
| CVE-2022-41223 | Mitel MiVoice Connect Code Injection Vulnerability | KEVMEDIUM 6.8EPSS 10.6% | 22 November 2022 |
| CVE-2022-40765 | Mitel MiVoice Connect Command Injection Vulnerability | KEVMEDIUM 6.8EPSS 10.5% | 22 November 2022 |
| CVE-2022-4069 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. | MEDIUM 4.8EPSS 93.3% | 20 November 2022 |
| CVE-2022-4068 | This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account. | MEDIUM 5.4EPSS 34.8% | 20 November 2022 |
| CVE-2022-4067 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | MEDIUM 5.4EPSS 93.7% | 20 November 2022 |
| CVE-2022-3562 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | MEDIUM 5.4EPSS 94.2% | 20 November 2022 |
| CVE-2022-42904 | Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. | HIGH 7.2EPSS 83.1% | 18 November 2022 |
| CVE-2022-40881 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | CRITICAL 9.8EPSS 29.7% | 17 November 2022 |
| CVE-2022-43781 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. | CRITICAL 9.8EPSS 98.1% | 17 November 2022 |
| CVE-2022-45402 | In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. | MEDIUM 6.1EPSS 81.8% | 15 November 2022 |
| CVE-2022-40843 | The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. | MEDIUM 4.9EPSS 28.8% | 15 November 2022 |
| CVE-2022-37109 | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. | CRITICAL 9.8EPSS 49.5% | 14 November 2022 |
| CVE-2022-40127 | A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. | HIGH 8.8EPSS 85.7% | 14 November 2022 |
| CVE-2022-43672 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. | CRITICAL 9.8EPSS 67.1% | 12 November 2022 |
| CVE-2022-43671 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. | CRITICAL 9.8EPSS 74.8% | 12 November 2022 |
| CVE-2022-44088 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | CRITICAL 9.8EPSS 20.1% | 10 November 2022 |
| CVE-2022-39396 | Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. | CRITICAL 9.8EPSS 38.7% | 10 November 2022 |
| CVE-2022-3265 | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. | MEDIUM 5.4EPSS 86.3% | 9 November 2022 |
| CVE-2022-41128 | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 24.6% | 9 November 2022 |
| CVE-2022-41080 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 77.3% | 9 November 2022 |
| CVE-2022-31199 | Netwrix Auditor Insecure Object Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 36.0% | 8 November 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.