Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,881 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 62 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-35711 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 73.5% | 14 October 2022 |
| CVE-2022-35710 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 42.6% | 14 October 2022 |
| CVE-2022-35698 | Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. | MEDIUM 5.4EPSS 10.7% | 14 October 2022 |
| CVE-2022-35690 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 72.2% | 14 October 2022 |
| CVE-2022-42889 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. | CRITICAL 9.8EPSS 99.9% | 13 October 2022 |
| CVE-2022-24697 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. | CRITICAL 9.8EPSS 84.8% | 13 October 2022 |
| CVE-2022-40871 | Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. | CRITICAL 9.8EPSS 33.4% | 12 October 2022 |
| CVE-2022-41034 | Visual Studio Code Remote Code Execution Vulnerability | HIGH 7.8EPSS 67.5% | 11 October 2022 |
| CVE-2022-38053 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 76.4% | 11 October 2022 |
| CVE-2022-38044 | Windows CD-ROM File System Driver Remote Code Execution Vulnerability | HIGH 7.8EPSS 56.3% | 11 October 2022 |
| CVE-2022-38028 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 14.9% | 11 October 2022 |
| CVE-2022-37985 | Windows Graphics Component Information Disclosure Vulnerability | MEDIUM 5.5EPSS 38.6% | 11 October 2022 |
| CVE-2022-37974 | Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | MEDIUM 6.5EPSS 36.3% | 11 October 2022 |
| CVE-2022-35829 | Service Fabric Explorer Spoofing Vulnerability | MEDIUM 4.8EPSS 19.9% | 11 October 2022 |
| CVE-2022-34689 | Windows CryptoAPI Spoofing Vulnerability | HIGH 7.5EPSS 37.9% | 11 October 2022 |
| CVE-2022-32174 | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | CRITICAL 9.0EPSS 58.0% | 11 October 2022 |
| CVE-2022-39288 | Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. | HIGH 7.5EPSS 59.2% | 10 October 2022 |
| CVE-2022-36635 | ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. | HIGH 8.8EPSS 16.7% | 7 October 2022 |
| CVE-2022-31680 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). | CRITICAL 9.1EPSS 33.1% | 7 October 2022 |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 8.0EPSS 100.0% | 3 October 2022 |
| CVE-2022-41040 | Microsoft Exchange Server Server-Side Request Forgery Vulnerability | KEVHIGH 8.8EPSS 100.0% | 3 October 2022 |
| CVE-2022-20775 | Cisco SD-WAN Path Traversal Vulnerability | KEVHIGH 7.8EPSS 12.5% | 30 September 2022 |
| CVE-2022-36961 | A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution. | HIGH 8.8EPSS 75.2% | 30 September 2022 |
| CVE-2022-28851 | Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. | MEDIUM 5.4EPSS 36.8% | 30 September 2022 |
| CVE-2022-21826 | This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS. | MEDIUM 5.4EPSS 45.2% | 30 September 2022 |
| CVE-2022-31629 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications. | MEDIUM 6.5EPSS 49.3% | 28 September 2022 |
| CVE-2022-40878 | In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE). | HIGH 8.8EPSS 23.2% | 27 September 2022 |
| CVE-2022-3323 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. | HIGH 7.5EPSS 28.6% | 27 September 2022 |
| CVE-2022-3038 | Google Chromium Network Service Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 24.7% | 26 September 2022 |
| CVE-2022-2998 | Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 30.3% | 26 September 2022 |
| CVE-2022-3062 | The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting | MEDIUM 6.1EPSS 44.1% | 26 September 2022 |
| CVE-2022-41352 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | KEVCRITICAL 9.8EPSS 95.5% | 26 September 2022 |
| CVE-2022-38742 | Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. | CRITICAL 9.8EPSS 21.8% | 23 September 2022 |
| CVE-2022-40855 | Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. | CRITICAL 9.8EPSS 13.5% | 23 September 2022 |
| CVE-2022-3236 | Sophos Firewall Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 23 September 2022 |
| CVE-2022-39197 | Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 46.4% | 22 September 2022 |
| CVE-2022-29799 | A vulnerability was found in networkd-dispatcher. | MEDIUM 5.5EPSS 11.8% | 21 September 2022 |
| CVE-2022-37027 | Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. | HIGH 7.2EPSS 21.7% | 21 September 2022 |
| CVE-2022-38916 | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files | CRITICAL 9.8EPSS 17.6% | 20 September 2022 |
| CVE-2022-38545 | Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request. | CRITICAL 9.6EPSS 32.9% | 19 September 2022 |
| CVE-2022-3218 | Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution. | CRITICAL 9.8EPSS 74.0% | 19 September 2022 |
| CVE-2022-35914 | Teclib GLPI Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 19 September 2022 |
| CVE-2022-3142 | The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. | HIGH 8.8EPSS 11.4% | 19 September 2022 |
| CVE-2022-2840 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections | CRITICAL 9.8EPSS 10.5% | 19 September 2022 |
| CVE-2022-2754 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks | CRITICAL 9.8EPSS 37.7% | 19 September 2022 |
| CVE-2022-2753 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious… | MEDIUM 6.1EPSS 83.4% | 19 September 2022 |
| CVE-2022-39960 | This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI. | MEDIUM 5.3EPSS 25.7% | 17 September 2022 |
| CVE-2022-40300 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. | CRITICAL 9.8EPSS 99.1% | 16 September 2022 |
| CVE-2022-38621 | Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. | CRITICAL 9.8EPSS 24.5% | 16 September 2022 |
| CVE-2022-38828 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi | CRITICAL 9.8EPSS 19.7% | 16 September 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.