Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,882 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 64 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-37056 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main, | CRITICAL 9.8EPSS 10.4% | 28 August 2022 |
| CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 55.5% | 28 August 2022 |
| CVE-2022-37057 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main. | CRITICAL 9.8EPSS 25.6% | 28 August 2022 |
| CVE-2022-36537 | ZK Framework AuUploader Unspecified Vulnerability | KEVHIGH 7.5EPSS 95.4% | 26 August 2022 |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. | CRITICAL 9.8EPSS 64.6% | 25 August 2022 |
| CVE-2022-37159 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | CRITICAL 9.8EPSS 25.9% | 25 August 2022 |
| CVE-2022-37070 | H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | CRITICAL 9.8EPSS 10.6% | 25 August 2022 |
| CVE-2022-36510 | H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | HIGH 7.8EPSS 11.2% | 25 August 2022 |
| CVE-2022-36509 | H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | HIGH 7.8EPSS 11.2% | 25 August 2022 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | KEVHIGH 8.8EPSS 99.2% | 25 August 2022 |
| CVE-2022-2234 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | HIGH 8.8EPSS 42.3% | 24 August 2022 |
| CVE-2022-36633 | Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. | HIGH 8.8EPSS 50.3% | 24 August 2022 |
| CVE-2022-37113 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | CRITICAL 9.8EPSS 15.0% | 23 August 2022 |
| CVE-2021-42627 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page. | CRITICAL 9.8EPSS 63.1% | 23 August 2022 |
| CVE-2022-32572 | An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. | HIGH 8.8EPSS 24.4% | 22 August 2022 |
| CVE-2022-30690 | A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. | MEDIUM 6.1EPSS 83.9% | 22 August 2022 |
| CVE-2022-30547 | A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. | CRITICAL 9.9EPSS 63.7% | 22 August 2022 |
| CVE-2022-30534 | An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. | HIGH 8.8EPSS 75.0% | 22 August 2022 |
| CVE-2022-35583 | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. | CRITICAL 9.8EPSS 15.4% | 22 August 2022 |
| CVE-2022-37134 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. | CRITICAL 9.8EPSS 21.7% | 22 August 2022 |
| CVE-2022-2552 | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site. | MEDIUM 5.3EPSS 11.3% | 22 August 2022 |
| CVE-2022-2551 | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the main installer endpoint of the plugin, if the installer script has been run once by an administrator, allowing download of the full… | HIGH 7.5EPSS 16.7% | 22 August 2022 |
| CVE-2022-29805 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload. | CRITICAL 9.8EPSS 27.6% | 19 August 2022 |
| CVE-2022-37061 | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. | CRITICAL 9.8EPSS 99.6% | 18 August 2022 |
| CVE-2022-37060 | FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. | HIGH 7.5EPSS 18.4% | 18 August 2022 |
| CVE-2022-23747 | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback. | CRITICAL 9.8EPSS 10.2% | 17 August 2022 |
| CVE-2022-2334 | If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22. | HIGH 7.2EPSS 12.3% | 17 August 2022 |
| CVE-2022-1373 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. | HIGH 7.2EPSS 12.8% | 17 August 2022 |
| CVE-2022-1401 | Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. | HIGH 7.5EPSS 18.4% | 17 August 2022 |
| CVE-2022-34258 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into… | MEDIUM 4.8EPSS 68.5% | 16 August 2022 |
| CVE-2020-14321 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | HIGH 8.8EPSS 16.2% | 16 August 2022 |
| CVE-2022-36309 | Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. | HIGH 8.8EPSS 24.6% | 16 August 2022 |
| CVE-2022-2314 | The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. | CRITICAL 9.8EPSS 16.5% | 15 August 2022 |
| CVE-2022-37042 | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 12 August 2022 |
| CVE-2022-35559 | A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. | CRITICAL 9.8EPSS 11.4% | 12 August 2022 |
| CVE-2022-35555 | A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution. | CRITICAL 9.8EPSS 26.0% | 12 August 2022 |
| CVE-2022-38130 | An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored. | CRITICAL 9.8EPSS 54.1% | 10 August 2022 |
| CVE-2022-38129 | A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). | CRITICAL 9.8EPSS 18.9% | 10 August 2022 |
| CVE-2022-37024 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that… | HIGH 8.8EPSS 79.1% | 10 August 2022 |
| CVE-2022-32429 | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to… | CRITICAL 9.8EPSS 75.6% | 10 August 2022 |
| CVE-2022-20866 | A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. | HIGH 7.5EPSS 17.4% | 10 August 2022 |
| CVE-2022-36801 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. | MEDIUM 6.1EPSS 65.5% | 10 August 2022 |
| CVE-2022-34715 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 80.4% | 9 August 2022 |
| CVE-2022-34713 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 67.8% | 9 August 2022 |
| CVE-2022-2733 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | MEDIUM 6.1EPSS 95.8% | 9 August 2022 |
| CVE-2022-36267 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. | CRITICAL 9.8EPSS 54.5% | 8 August 2022 |
| CVE-2022-31656 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. | CRITICAL 9.8EPSS 22.9% | 5 August 2022 |
| CVE-2022-37434 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. | CRITICAL 9.8EPSS 17.9% | 5 August 2022 |
| CVE-2022-21186 | The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input. | CRITICAL 9.8EPSS 25.4% | 5 August 2022 |
| CVE-2022-31793 | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. | HIGH 7.5EPSS 15.9% | 4 August 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.