SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 66 of 348

CVESummaryPriorityPublished
CVE-2022-24082If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying…CRITICAL 9.8EPSS 12.3%19 July 2022
CVE-2022-23745A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).HIGH 7.5EPSS 16.5%18 July 2022
CVE-2022-1565The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7.HIGH 7.2EPSS 15.4%18 July 2022
CVE-2022-33891Apache Spark Command Injection VulnerabilityKEVHIGH 8.8EPSS 93.1%18 July 2022
CVE-2022-26482An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.HIGH 7.2EPSS 22.8%17 July 2022
CVE-2022-26352dotCMS Unrestricted Upload of File VulnerabilityKEVCRITICAL 9.8EPSS 91.6%17 July 2022
CVE-2021-36711WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.CRITICAL 9.8EPSS 16.1%16 July 2022
CVE-2022-31161Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file.CRITICAL 9.8EPSS 28.4%15 July 2022
CVE-2022-34221Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code…HIGH 7.8EPSS 11.1%15 July 2022
CVE-2022-31097Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana.HIGH 8.7EPSS 68.6%15 July 2022
CVE-2022-2419A vulnerability was found in URVE Web Manager.HIGH 8.0EPSS 12.8%15 July 2022
CVE-2022-32417PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.CRITICAL 9.8EPSS 35.6%14 July 2022
CVE-2022-32409A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.CRITICAL 9.8EPSS 13.4%14 July 2022
CVE-2022-32215The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers.MEDIUM 6.5EPSS 68.8%14 July 2022
CVE-2022-32214The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests.MEDIUM 6.5EPSS 82.5%14 July 2022
CVE-2022-32213The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).MEDIUM 6.5EPSS 44.1%14 July 2022
CVE-2022-29593relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.MEDIUM 5.9EPSS 14.0%14 July 2022
CVE-2022-34753A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised.HIGH 8.8EPSS 71.3%13 July 2022
CVE-2022-35628A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.CRITICAL 9.8EPSS 26.1%12 July 2022
CVE-2022-30216Windows Server Service Tampering VulnerabilityHIGH 8.8EPSS 88.9%12 July 2022
CVE-2022-22047Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 18.8%12 July 2022
CVE-2022-22025Windows Internet Information Services Cachuri Module Denial of Service VulnerabilityHIGH 7.5EPSS 31.9%12 July 2022
CVE-2022-1952The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution.CRITICAL 9.8EPSS 24.9%11 July 2022
CVE-2022-31137Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability.CRITICAL 9.8EPSS 90.4%8 July 2022
CVE-2022-35411rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.CRITICAL 9.8EPSS 46.1%8 July 2022
CVE-2022-33098Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.MEDIUM 6.1EPSS 52.7%7 July 2022
CVE-2022-32449TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.CRITICAL 9.8EPSS 18.8%7 July 2022
CVE-2022-32054Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.CRITICAL 9.8EPSS 34.0%7 July 2022
CVE-2022-32206The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end…MEDIUM 6.5EPSS 32.2%7 July 2022
CVE-2022-32205A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them.MEDIUM 4.3EPSS 27.1%7 July 2022
CVE-2022-31854Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.HIGH 7.2EPSS 32.8%7 July 2022
CVE-2022-25048Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.HIGH 8.8EPSS 19.3%7 July 2022
CVE-2022-25046A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.CRITICAL 9.8EPSS 57.8%7 July 2022
CVE-2022-31126A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file.CRITICAL 9.8EPSS 52.1%6 July 2022
CVE-2022-31125A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request.CRITICAL 9.8EPSS 20.6%6 July 2022
CVE-2022-33980Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded.CRITICAL 9.8EPSS 45.1%6 July 2022
CVE-2022-34265The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value.CRITICAL 9.8EPSS 73.3%4 July 2022
CVE-2022-33171When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection.CRITICAL 9.8EPSS 20.3%4 July 2022
CVE-2022-32420College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php.HIGH 8.8EPSS 20.4%1 July 2022
CVE-2022-32035Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.HIGH 7.5EPSS 14.4%1 July 2022
CVE-2022-32032Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.CRITICAL 9.8EPSS 10.1%1 July 2022
CVE-2022-2230A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab…MEDIUM 4.8EPSS 56.5%1 July 2022
CVE-2022-2185A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted…HIGH 8.8EPSS 76.9%1 July 2022
CVE-2022-2274This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation.CRITICAL 9.8EPSS 47.0%1 July 2022
CVE-2022-28127A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0.CRITICAL 9.1EPSS 37.0%30 June 2022
CVE-2022-34783Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.MEDIUM 5.4EPSS 80.9%30 June 2022
CVE-2022-34777Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.MEDIUM 5.4EPSS 72.4%30 June 2022
CVE-2022-26135A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.MEDIUM 6.5EPSS 71.2%30 June 2022
CVE-2022-2073Code Injection in GitHub repository getgrav/grav prior to 1.7.34.HIGH 7.2EPSS 10.9%29 June 2022
CVE-2022-33107ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php.CRITICAL 9.8EPSS 23.9%29 June 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.