SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 61 of 348

CVESummaryPriorityPublished
CVE-2022-44793handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.MEDIUM 6.5EPSS 53.5%7 November 2022
CVE-2022-44792handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in…MEDIUM 6.5EPSS 52.1%7 November 2022
CVE-2022-43568In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.MEDIUM 6.1EPSS 42.8%4 November 2022
CVE-2022-43945The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow.HIGH 7.5EPSS 22.3%4 November 2022
CVE-2022-43571In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.HIGH 8.8EPSS 13.8%3 November 2022
CVE-2022-39323Time based attack using a SQL injection in api REST user_token.CRITICAL 9.8EPSS 34.5%3 November 2022
CVE-2022-39379A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads.CRITICAL 9.8EPSS 45.0%2 November 2022
CVE-2022-38380An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API.MEDIUM 4.3EPSS 23.0%2 November 2022
CVE-2022-3654Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 23.8%1 November 2022
CVE-2022-3786Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer.HIGH 7.5EPSS 92.5%1 November 2022
CVE-2022-3602Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.HIGH 7.5EPSS 90.8%1 November 2022
CVE-2022-3801A vulnerability, which was classified as critical, was found in IBAX go-ibax.HIGH 8.8EPSS 30.1%1 November 2022
CVE-2022-41772Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal.CRITICAL 9.8EPSS 24.9%31 October 2022
CVE-2022-41657Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs).CRITICAL 9.8EPSS 20.9%31 October 2022
CVE-2022-38142Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification.CRITICAL 9.8EPSS 18.2%31 October 2022
CVE-2022-40471Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.phpCRITICAL 9.8EPSS 21.8%31 October 2022
CVE-2022-41702The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.MEDIUM 5.4EPSS 11.1%27 October 2022
CVE-2022-41701The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.MEDIUM 5.4EPSS 11.1%27 October 2022
CVE-2022-41651The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.MEDIUM 5.4EPSS 11.1%27 October 2022
CVE-2022-41555The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.MEDIUM 5.4EPSS 11.1%27 October 2022
CVE-2022-41133The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters.HIGH 8.8EPSS 26.6%27 October 2022
CVE-2022-40965The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.MEDIUM 5.4EPSS 11.1%27 October 2022
CVE-2022-3387Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks.MEDIUM 5.3EPSS 14.0%27 October 2022
CVE-2022-31898gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.MEDIUM 6.8EPSS 15.8%27 October 2022
CVE-2022-43775The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.CRITICAL 9.8EPSS 20.6%26 October 2022
CVE-2022-38181Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 13.6%25 October 2022
CVE-2022-38580Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).CRITICAL 9.8EPSS 11.5%25 October 2022
CVE-2022-38108SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 68.9%20 October 2022
CVE-2022-36958SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 8.8EPSS 82.7%20 October 2022
CVE-2022-36957SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.HIGH 7.2EPSS 12.8%20 October 2022
CVE-2022-42233Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.CRITICAL 9.8EPSS 42.7%20 October 2022
CVE-2016-20017D-Link DSL-2750B Devices Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 65.2%19 October 2022
CVE-2016-20016A remote unauthenticated attacker can execute arbitrary operating system commands as root.CRITICAL 9.8EPSS 86.2%19 October 2022
CVE-2022-39428Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).CRITICAL 9.8EPSS 36.5%18 October 2022
CVE-2022-21587Oracle E-Business Suite Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 98.3%18 October 2022
CVE-2022-41544GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.CRITICAL 9.8EPSS 10.4%18 October 2022
CVE-2022-40684Fortinet Multiple Products Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%18 October 2022
CVE-2022-3552Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.HIGH 7.2EPSS 44.0%17 October 2022
CVE-2022-2992A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.CRITICAL 9.9EPSS 86.2%17 October 2022
CVE-2022-2884A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpointCRITICAL 9.9EPSS 75.7%17 October 2022
CVE-2022-42341Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read.HIGH 7.5EPSS 35.5%14 October 2022
CVE-2022-42340Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read.HIGH 7.5EPSS 33.8%14 October 2022
CVE-2022-38424Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write.HIGH 7.2EPSS 45.2%14 October 2022
CVE-2022-38423Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure.MEDIUM 4.9EPSS 45.0%14 October 2022
CVE-2022-38422Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure.HIGH 7.5EPSS 44.3%14 October 2022
CVE-2022-38421Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of…HIGH 7.2EPSS 79.2%14 October 2022
CVE-2022-38420Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services.HIGH 7.5EPSS 44.0%14 October 2022
CVE-2022-38419Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read.HIGH 7.5EPSS 53.0%14 October 2022
CVE-2022-38418Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of…CRITICAL 9.8EPSS 80.0%14 October 2022
CVE-2022-35712Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.8EPSS 36.8%14 October 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.