SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,881 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 62 of 348

CVESummaryPriorityPublished
CVE-2022-35711Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.8EPSS 73.5%14 October 2022
CVE-2022-35710Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.8EPSS 42.6%14 October 2022
CVE-2022-35698Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability.MEDIUM 5.4EPSS 10.7%14 October 2022
CVE-2022-35690Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.8EPSS 72.2%14 October 2022
CVE-2022-42889Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.CRITICAL 9.8EPSS 99.9%13 October 2022
CVE-2022-24697Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu.CRITICAL 9.8EPSS 84.8%13 October 2022
CVE-2022-40871Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection.CRITICAL 9.8EPSS 33.4%12 October 2022
CVE-2022-41034Visual Studio Code Remote Code Execution VulnerabilityHIGH 7.8EPSS 67.5%11 October 2022
CVE-2022-38053Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 76.4%11 October 2022
CVE-2022-38044Windows CD-ROM File System Driver Remote Code Execution VulnerabilityHIGH 7.8EPSS 56.3%11 October 2022
CVE-2022-38028Microsoft Windows Print Spooler Privilege Escalation Vulnerability KEVHIGH 7.8EPSS 14.9%11 October 2022
CVE-2022-37985Windows Graphics Component Information Disclosure VulnerabilityMEDIUM 5.5EPSS 38.6%11 October 2022
CVE-2022-37974Windows Mixed Reality Developer Tools Information Disclosure VulnerabilityMEDIUM 6.5EPSS 36.3%11 October 2022
CVE-2022-35829Service Fabric Explorer Spoofing VulnerabilityMEDIUM 4.8EPSS 19.9%11 October 2022
CVE-2022-34689Windows CryptoAPI Spoofing VulnerabilityHIGH 7.5EPSS 37.9%11 October 2022
CVE-2022-32174In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.CRITICAL 9.0EPSS 58.0%11 October 2022
CVE-2022-39288Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header.HIGH 7.5EPSS 59.2%10 October 2022
CVE-2022-36635ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.HIGH 8.8EPSS 16.7%7 October 2022
CVE-2022-31680The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller).CRITICAL 9.1EPSS 33.1%7 October 2022
CVE-2022-41082Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 8.0EPSS 100.0%3 October 2022
CVE-2022-41040Microsoft Exchange Server Server-Side Request Forgery VulnerabilityKEVHIGH 8.8EPSS 100.0%3 October 2022
CVE-2022-20775Cisco SD-WAN Path Traversal VulnerabilityKEVHIGH 7.8EPSS 12.5%30 September 2022
CVE-2022-36961A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.HIGH 8.8EPSS 75.2%30 September 2022
CVE-2022-28851Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.MEDIUM 5.4EPSS 36.8%30 September 2022
CVE-2022-21826This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.MEDIUM 5.4EPSS 45.2%30 September 2022
CVE-2022-31629In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.MEDIUM 6.5EPSS 49.3%28 September 2022
CVE-2022-40878In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).HIGH 8.8EPSS 23.2%27 September 2022
CVE-2022-3323An SQL injection vulnerability in Advantech iView 5.7.04.6469.HIGH 7.5EPSS 28.6%27 September 2022
CVE-2022-3038Google Chromium Network Service Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 24.7%26 September 2022
CVE-2022-2998Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 30.3%26 September 2022
CVE-2022-3062The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site ScriptingMEDIUM 6.1EPSS 44.1%26 September 2022
CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityKEVCRITICAL 9.8EPSS 95.5%26 September 2022
CVE-2022-38742Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow.CRITICAL 9.8EPSS 21.8%23 September 2022
CVE-2022-40855Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'.CRITICAL 9.8EPSS 13.5%23 September 2022
CVE-2022-3236Sophos Firewall Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.9%23 September 2022
CVE-2022-39197Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 46.4%22 September 2022
CVE-2022-29799A vulnerability was found in networkd-dispatcher.MEDIUM 5.5EPSS 11.8%21 September 2022
CVE-2022-37027Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options.HIGH 7.2EPSS 21.7%21 September 2022
CVE-2022-38916A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious filesCRITICAL 9.8EPSS 17.6%20 September 2022
CVE-2022-38545Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.CRITICAL 9.6EPSS 32.9%19 September 2022
CVE-2022-3218Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.CRITICAL 9.8EPSS 74.0%19 September 2022
CVE-2022-35914Teclib GLPI Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%19 September 2022
CVE-2022-3142The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections.HIGH 8.8EPSS 11.4%19 September 2022
CVE-2022-2840The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injectionsCRITICAL 9.8EPSS 10.5%19 September 2022
CVE-2022-2754The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacksCRITICAL 9.8EPSS 37.7%19 September 2022
CVE-2022-2753The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious…MEDIUM 6.1EPSS 83.4%19 September 2022
CVE-2022-39960This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.MEDIUM 5.3EPSS 25.7%17 September 2022
CVE-2022-40300Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.CRITICAL 9.8EPSS 99.1%16 September 2022
CVE-2022-38621Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page.CRITICAL 9.8EPSS 24.5%16 September 2022
CVE-2022-38828TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgiCRITICAL 9.8EPSS 19.7%16 September 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.