SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,881 CVEs1,712 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 63 of 348

CVESummaryPriorityPublished
CVE-2022-38827TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgiCRITICAL 9.8EPSS 12.2%16 September 2022
CVE-2022-40152Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled.HIGH 7.5EPSS 19.7%16 September 2022
CVE-2022-2863The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attackMEDIUM 4.9EPSS 25.3%16 September 2022
CVE-2022-36534KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.HIGH 8.8EPSS 52.1%16 September 2022
CVE-2022-36533KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.MEDIUM 5.4EPSS 41.8%16 September 2022
CVE-2022-36532Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.HIGH 8.8EPSS 23.8%16 September 2022
CVE-2022-38352ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.CRITICAL 9.8EPSS 20.6%15 September 2022
CVE-2022-38308TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem.CRITICAL 9.8EPSS 20.7%14 September 2022
CVE-2022-37661SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.CRITICAL 9.8EPSS 33.9%14 September 2022
CVE-2022-36667Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function.HIGH 8.8EPSS 24.4%14 September 2022
CVE-2022-37190CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE).HIGH 8.8EPSS 45.8%13 September 2022
CVE-2022-35413WAPPLES through 6.0 has a hardcoded systemi account.CRITICAL 9.8EPSS 18.0%13 September 2022
CVE-2022-37969Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 28.3%13 September 2022
CVE-2022-37961Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 50.7%13 September 2022
CVE-2022-37958SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution VulnerabilityHIGH 8.1EPSS 86.0%13 September 2022
CVE-2022-37957Windows Kernel Elevation of Privilege VulnerabilityHIGH 7.8EPSS 13.6%13 September 2022
CVE-2022-37954DirectX Graphics Kernel Elevation of Privilege VulnerabilityHIGH 7.8EPSS 44.9%13 September 2022
CVE-2022-35823Microsoft SharePoint Remote Code Execution VulnerabilityHIGH 8.8EPSS 53.6%13 September 2022
CVE-2022-35803Windows Common Log File System Driver Elevation of Privilege VulnerabilityHIGH 7.8EPSS 23.8%13 September 2022
CVE-2022-34729Windows GDI Elevation of Privilege VulnerabilityHIGH 7.8EPSS 10.5%13 September 2022
CVE-2022-34721Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 78.9%13 September 2022
CVE-2022-34718Windows TCP/IP Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 54.4%13 September 2022
CVE-2022-33679Windows Kerberos Elevation of Privilege VulnerabilityHIGH 8.1EPSS 11.1%13 September 2022
CVE-2022-37860The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.CRITICAL 9.8EPSS 80.0%12 September 2022
CVE-2022-39810A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter.MEDIUM 6.1EPSS 57.3%9 September 2022
CVE-2022-25765The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.CRITICAL 9.8EPSS 43.0%9 September 2022
CVE-2022-36100This allowed users with view rights on the document (default in a public wiki or for authenticated users on private wikis) to execute arbitrary Groovy, Python and Velocity code with programming rights.HIGH 8.8EPSS 73.6%8 September 2022
CVE-2022-36099Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the request (URL parameter) using the `XWikiServerClassSheet` if the user…HIGH 8.8EPSS 75.9%8 September 2022
CVE-2022-36098The stored code is executed by anyone visiting the page with the mention.CRITICAL 9.0EPSS 71.0%8 September 2022
CVE-2022-36097Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone trying to move the corresponding attachment.MEDIUM 6.1EPSS 57.4%8 September 2022
CVE-2022-36096Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name.CRITICAL 9.0EPSS 59.5%8 September 2022
CVE-2022-36094Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name.CRITICAL 9.0EPSS 64.1%8 September 2022
CVE-2022-30079Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.HIGH 8.8EPSS 24.7%8 September 2022
CVE-2022-27593QNAP Photo Station Externally Controlled Reference VulnerabilityKEVCRITICAL 9.1EPSS 87.9%8 September 2022
CVE-2022-36067In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.CRITICAL 10.0EPSS 47.9%6 September 2022
CVE-2022-2633The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0.HIGH 8.2EPSS 33.8%6 September 2022
CVE-2022-31814pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header.CRITICAL 9.8EPSS 91.9%5 September 2022
CVE-2022-36642A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege…CRITICAL 9.8EPSS 12.6%2 September 2022
CVE-2022-25813In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page.HIGH 7.5EPSS 67.3%2 September 2022
CVE-2022-37130In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a…CRITICAL 9.8EPSS 26.3%31 August 2022
CVE-2022-36620D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.HIGH 7.5EPSS 23.2%31 August 2022
CVE-2022-37128In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.CRITICAL 9.8EPSS 21.2%31 August 2022
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability.HIGH 7.5EPSS 23.1%31 August 2022
CVE-2022-1552This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.HIGH 8.8EPSS 16.0%31 August 2022
CVE-2022-36553Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.CRITICAL 9.8EPSS 90.9%29 August 2022
CVE-2022-38772Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in…HIGH 8.8EPSS 78.0%29 August 2022
CVE-2022-32548An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.CRITICAL 9.8EPSS 34.0%29 August 2022
CVE-2022-22897A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.CRITICAL 9.8EPSS 14.4%29 August 2022
CVE-2022-34668NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and…CRITICAL 9.8EPSS 10.9%29 August 2022
CVE-2022-36572Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.CRITICAL 9.8EPSS 22.0%29 August 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.