Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,689 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 61 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-44793 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | MEDIUM 6.5EPSS 53.5% | 7 November 2022 |
| CVE-2022-44792 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in… | MEDIUM 6.5EPSS 52.1% | 7 November 2022 |
| CVE-2022-43568 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio. | MEDIUM 6.1EPSS 42.8% | 4 November 2022 |
| CVE-2022-43945 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. | HIGH 7.5EPSS 22.3% | 4 November 2022 |
| CVE-2022-43571 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component. | HIGH 8.8EPSS 13.8% | 3 November 2022 |
| CVE-2022-39323 | Time based attack using a SQL injection in api REST user_token. | CRITICAL 9.8EPSS 34.5% | 3 November 2022 |
| CVE-2022-39379 | A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. | CRITICAL 9.8EPSS 45.0% | 2 November 2022 |
| CVE-2022-38380 | An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface settings via the API. | MEDIUM 4.3EPSS 23.0% | 2 November 2022 |
| CVE-2022-3654 | Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 23.8% | 1 November 2022 |
| CVE-2022-3786 | Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. | HIGH 7.5EPSS 92.5% | 1 November 2022 |
| CVE-2022-3602 | Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. | HIGH 7.5EPSS 90.8% | 1 November 2022 |
| CVE-2022-3801 | A vulnerability, which was classified as critical, was found in IBAX go-ibax. | HIGH 8.8EPSS 30.1% | 1 November 2022 |
| CVE-2022-41772 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. | CRITICAL 9.8EPSS 24.9% | 31 October 2022 |
| CVE-2022-41657 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). | CRITICAL 9.8EPSS 20.9% | 31 October 2022 |
| CVE-2022-38142 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. | CRITICAL 9.8EPSS 18.2% | 31 October 2022 |
| CVE-2022-40471 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php | CRITICAL 9.8EPSS 21.8% | 31 October 2022 |
| CVE-2022-41702 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API. | MEDIUM 5.4EPSS 11.1% | 27 October 2022 |
| CVE-2022-41701 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API. | MEDIUM 5.4EPSS 11.1% | 27 October 2022 |
| CVE-2022-41651 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API. | MEDIUM 5.4EPSS 11.1% | 27 October 2022 |
| CVE-2022-41555 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API. | MEDIUM 5.4EPSS 11.1% | 27 October 2022 |
| CVE-2022-41133 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. | HIGH 8.8EPSS 26.6% | 27 October 2022 |
| CVE-2022-40965 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API. | MEDIUM 5.4EPSS 11.1% | 27 October 2022 |
| CVE-2022-3387 | Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. | MEDIUM 5.3EPSS 14.0% | 27 October 2022 |
| CVE-2022-31898 | gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters. | MEDIUM 6.8EPSS 15.8% | 27 October 2022 |
| CVE-2022-43775 | The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. | CRITICAL 9.8EPSS 20.6% | 26 October 2022 |
| CVE-2022-38181 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 13.6% | 25 October 2022 |
| CVE-2022-38580 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). | CRITICAL 9.8EPSS 11.5% | 25 October 2022 |
| CVE-2022-38108 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 68.9% | 20 October 2022 |
| CVE-2022-36958 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 8.8EPSS 82.7% | 20 October 2022 |
| CVE-2022-36957 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. | HIGH 7.2EPSS 12.8% | 20 October 2022 |
| CVE-2022-42233 | Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability. | CRITICAL 9.8EPSS 42.7% | 20 October 2022 |
| CVE-2016-20017 | D-Link DSL-2750B Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 65.2% | 19 October 2022 |
| CVE-2016-20016 | A remote unauthenticated attacker can execute arbitrary operating system commands as root. | CRITICAL 9.8EPSS 86.2% | 19 October 2022 |
| CVE-2022-39428 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). | CRITICAL 9.8EPSS 36.5% | 18 October 2022 |
| CVE-2022-21587 | Oracle E-Business Suite Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 18 October 2022 |
| CVE-2022-41544 | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. | CRITICAL 9.8EPSS 10.4% | 18 October 2022 |
| CVE-2022-40684 | Fortinet Multiple Products Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 18 October 2022 |
| CVE-2022-3552 | Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1. | HIGH 7.2EPSS 44.0% | 17 October 2022 |
| CVE-2022-2992 | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint. | CRITICAL 9.9EPSS 86.2% | 17 October 2022 |
| CVE-2022-2884 | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint | CRITICAL 9.9EPSS 75.7% | 17 October 2022 |
| CVE-2022-42341 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. | HIGH 7.5EPSS 35.5% | 14 October 2022 |
| CVE-2022-42340 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. | HIGH 7.5EPSS 33.8% | 14 October 2022 |
| CVE-2022-38424 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. | HIGH 7.2EPSS 45.2% | 14 October 2022 |
| CVE-2022-38423 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. | MEDIUM 4.9EPSS 45.0% | 14 October 2022 |
| CVE-2022-38422 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. | HIGH 7.5EPSS 44.3% | 14 October 2022 |
| CVE-2022-38421 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of… | HIGH 7.2EPSS 79.2% | 14 October 2022 |
| CVE-2022-38420 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. | HIGH 7.5EPSS 44.0% | 14 October 2022 |
| CVE-2022-38419 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. | HIGH 7.5EPSS 53.0% | 14 October 2022 |
| CVE-2022-38418 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of… | CRITICAL 9.8EPSS 80.0% | 14 October 2022 |
| CVE-2022-35712 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 36.8% | 14 October 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.