Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,881 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 63 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-38827 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi | CRITICAL 9.8EPSS 12.2% | 16 September 2022 |
| CVE-2022-40152 | Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. | HIGH 7.5EPSS 19.7% | 16 September 2022 |
| CVE-2022-2863 | The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack | MEDIUM 4.9EPSS 25.3% | 16 September 2022 |
| CVE-2022-36534 | KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. | HIGH 8.8EPSS 52.1% | 16 September 2022 |
| CVE-2022-36533 | KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability. | MEDIUM 5.4EPSS 41.8% | 16 September 2022 |
| CVE-2022-36532 | Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution. | HIGH 8.8EPSS 23.8% | 16 September 2022 |
| CVE-2022-38352 | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. | CRITICAL 9.8EPSS 20.6% | 15 September 2022 |
| CVE-2022-38308 | TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. | CRITICAL 9.8EPSS 20.7% | 14 September 2022 |
| CVE-2022-37661 | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. | CRITICAL 9.8EPSS 33.9% | 14 September 2022 |
| CVE-2022-36667 | Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. | HIGH 8.8EPSS 24.4% | 14 September 2022 |
| CVE-2022-37190 | CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). | HIGH 8.8EPSS 45.8% | 13 September 2022 |
| CVE-2022-35413 | WAPPLES through 6.0 has a hardcoded systemi account. | CRITICAL 9.8EPSS 18.0% | 13 September 2022 |
| CVE-2022-37969 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 28.3% | 13 September 2022 |
| CVE-2022-37961 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 50.7% | 13 September 2022 |
| CVE-2022-37958 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | HIGH 8.1EPSS 86.0% | 13 September 2022 |
| CVE-2022-37957 | Windows Kernel Elevation of Privilege Vulnerability | HIGH 7.8EPSS 13.6% | 13 September 2022 |
| CVE-2022-37954 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | HIGH 7.8EPSS 44.9% | 13 September 2022 |
| CVE-2022-35823 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH 8.8EPSS 53.6% | 13 September 2022 |
| CVE-2022-35803 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH 7.8EPSS 23.8% | 13 September 2022 |
| CVE-2022-34729 | Windows GDI Elevation of Privilege Vulnerability | HIGH 7.8EPSS 10.5% | 13 September 2022 |
| CVE-2022-34721 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 78.9% | 13 September 2022 |
| CVE-2022-34718 | Windows TCP/IP Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 54.4% | 13 September 2022 |
| CVE-2022-33679 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH 8.1EPSS 11.1% | 13 September 2022 |
| CVE-2022-37860 | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability. | CRITICAL 9.8EPSS 80.0% | 12 September 2022 |
| CVE-2022-39810 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. | MEDIUM 6.1EPSS 57.3% | 9 September 2022 |
| CVE-2022-25765 | The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. | CRITICAL 9.8EPSS 43.0% | 9 September 2022 |
| CVE-2022-36100 | This allowed users with view rights on the document (default in a public wiki or for authenticated users on private wikis) to execute arbitrary Groovy, Python and Velocity code with programming rights. | HIGH 8.8EPSS 73.6% | 8 September 2022 |
| CVE-2022-36099 | Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the request (URL parameter) using the `XWikiServerClassSheet` if the user… | HIGH 8.8EPSS 75.9% | 8 September 2022 |
| CVE-2022-36098 | The stored code is executed by anyone visiting the page with the mention. | CRITICAL 9.0EPSS 71.0% | 8 September 2022 |
| CVE-2022-36097 | Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment. | MEDIUM 6.1EPSS 57.4% | 8 September 2022 |
| CVE-2022-36096 | Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. | CRITICAL 9.0EPSS 59.5% | 8 September 2022 |
| CVE-2022-36094 | Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. | CRITICAL 9.0EPSS 64.1% | 8 September 2022 |
| CVE-2022-30079 | Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter. | HIGH 8.8EPSS 24.7% | 8 September 2022 |
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Vulnerability | KEVCRITICAL 9.1EPSS 87.9% | 8 September 2022 |
| CVE-2022-36067 | In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. | CRITICAL 10.0EPSS 47.9% | 6 September 2022 |
| CVE-2022-2633 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. | HIGH 8.2EPSS 33.8% | 6 September 2022 |
| CVE-2022-31814 | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. | CRITICAL 9.8EPSS 91.9% | 5 September 2022 |
| CVE-2022-36642 | A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege… | CRITICAL 9.8EPSS 12.6% | 2 September 2022 |
| CVE-2022-25813 | In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. | HIGH 7.5EPSS 67.3% | 2 September 2022 |
| CVE-2022-37130 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a… | CRITICAL 9.8EPSS 26.3% | 31 August 2022 |
| CVE-2022-36620 | D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting. | HIGH 7.5EPSS 23.2% | 31 August 2022 |
| CVE-2022-37128 | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. | CRITICAL 9.8EPSS 21.2% | 31 August 2022 |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. | HIGH 7.5EPSS 23.1% | 31 August 2022 |
| CVE-2022-1552 | This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity. | HIGH 8.8EPSS 16.0% | 31 August 2022 |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. | CRITICAL 9.8EPSS 90.9% | 29 August 2022 |
| CVE-2022-38772 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in… | HIGH 8.8EPSS 78.0% | 29 August 2022 |
| CVE-2022-32548 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field. | CRITICAL 9.8EPSS 34.0% | 29 August 2022 |
| CVE-2022-22897 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data. | CRITICAL 9.8EPSS 14.4% | 29 August 2022 |
| CVE-2022-34668 | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and… | CRITICAL 9.8EPSS 10.9% | 29 August 2022 |
| CVE-2022-36572 | Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/. | CRITICAL 9.8EPSS 22.0% | 29 August 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.