Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,882 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 65 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-2651 | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | CRITICAL 9.8EPSS 15.4% | 4 August 2022 |
| CVE-2022-28732 | A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. | MEDIUM 6.1EPSS 82.0% | 4 August 2022 |
| CVE-2022-28731 | A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the… | MEDIUM 6.5EPSS 56.9% | 4 August 2022 |
| CVE-2022-28730 | A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. | MEDIUM 6.1EPSS 85.4% | 4 August 2022 |
| CVE-2022-27166 | A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the… | MEDIUM 6.1EPSS 85.4% | 4 August 2022 |
| CVE-2022-35620 | D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main. | CRITICAL 9.8EPSS 31.9% | 3 August 2022 |
| CVE-2022-34974 | D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function. | CRITICAL 9.8EPSS 23.5% | 3 August 2022 |
| CVE-2022-34973 | D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp. | HIGH 7.5EPSS 15.1% | 3 August 2022 |
| CVE-2022-35737 | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. | HIGH 7.5EPSS 21.5% | 3 August 2022 |
| CVE-2022-35919 | Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. | LOW 2.7EPSS 52.3% | 1 August 2022 |
| CVE-2022-31188 | Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. | CRITICAL 9.8EPSS 48.6% | 1 August 2022 |
| CVE-2022-27255 | In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. | CRITICAL 9.8EPSS 37.1% | 1 August 2022 |
| CVE-2022-36799 | Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. | HIGH 7.2EPSS 45.3% | 1 August 2022 |
| CVE-2022-34531 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | CRITICAL 9.8EPSS 23.5% | 29 July 2022 |
| CVE-2022-2414 | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. | HIGH 7.5EPSS 85.6% | 29 July 2022 |
| CVE-2022-34555 | TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet. | CRITICAL 9.8EPSS 21.3% | 28 July 2022 |
| CVE-2022-30287 | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. | HIGH 8.0EPSS 70.7% | 28 July 2022 |
| CVE-2022-2564 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | CRITICAL 9.8EPSS 32.7% | 28 July 2022 |
| CVE-2022-2480 | Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 17.9% | 28 July 2022 |
| CVE-2022-2294 | WebRTC Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 70.5% | 28 July 2022 |
| CVE-2022-34120 | Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php. | HIGH 7.2EPSS 18.2% | 27 July 2022 |
| CVE-2022-2550 | OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. | HIGH 8.8EPSS 48.3% | 27 July 2022 |
| CVE-2022-1364 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 13.7% | 26 July 2022 |
| CVE-2022-34907 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. | CRITICAL 9.8EPSS 15.9% | 25 July 2022 |
| CVE-2022-34906 | A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. | HIGH 7.5EPSS 10.6% | 25 July 2022 |
| CVE-2022-35871 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). | HIGH 7.8EPSS 39.2% | 25 July 2022 |
| CVE-2022-35870 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). | HIGH 7.8EPSS 43.3% | 25 July 2022 |
| CVE-2022-35869 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). | CRITICAL 9.8EPSS 60.3% | 25 July 2022 |
| CVE-2022-35650 | The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. | HIGH 7.5EPSS 49.1% | 25 July 2022 |
| CVE-2022-1232 | Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 16.6% | 25 July 2022 |
| CVE-2022-36450 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. | CRITICAL 9.8EPSS 20.0% | 25 July 2022 |
| CVE-2022-36446 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | CRITICAL 9.8EPSS 96.0% | 25 July 2022 |
| CVE-2022-1096 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 24.2% | 23 July 2022 |
| CVE-2022-25759 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. | CRITICAL 9.8EPSS 11.2% | 22 July 2022 |
| CVE-2022-2143 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | CRITICAL 9.8EPSS 59.4% | 22 July 2022 |
| CVE-2022-2139 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. | CRITICAL 9.8EPSS 15.6% | 22 July 2022 |
| CVE-2022-2138 | The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition. | HIGH 7.5EPSS 11.3% | 22 July 2022 |
| CVE-2022-2135 | The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information. | HIGH 7.5EPSS 10.2% | 22 July 2022 |
| CVE-2022-0902 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100… | CRITICAL 9.8EPSS 16.5% | 21 July 2022 |
| CVE-2022-26138 | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 98.2% | 20 July 2022 |
| CVE-2022-34047 | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd]. | HIGH 7.5EPSS 21.8% | 20 July 2022 |
| CVE-2022-34046 | An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);]. | HIGH 7.5EPSS 20.8% | 20 July 2022 |
| CVE-2022-33318 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1,… | CRITICAL 9.8EPSS 48.1% | 20 July 2022 |
| CVE-2022-34607 | H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp. | CRITICAL 9.8EPSS 13.5% | 20 July 2022 |
| CVE-2022-2488 | A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. | CRITICAL 9.8EPSS 33.8% | 20 July 2022 |
| CVE-2022-2487 | A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. | CRITICAL 9.8EPSS 79.5% | 20 July 2022 |
| CVE-2022-2486 | A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. | CRITICAL 9.8EPSS 30.5% | 20 July 2022 |
| CVE-2022-21550 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). | MEDIUM 6.3EPSS 50.7% | 19 July 2022 |
| CVE-2022-34169 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. | HIGH 7.5EPSS 81.0% | 19 July 2022 |
| CVE-2022-35405 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 19 July 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.