Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 66 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-24082 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying… | CRITICAL 9.8EPSS 12.3% | 19 July 2022 |
| CVE-2022-23745 | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). | HIGH 7.5EPSS 16.5% | 18 July 2022 |
| CVE-2022-1565 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. | HIGH 7.2EPSS 15.4% | 18 July 2022 |
| CVE-2022-33891 | Apache Spark Command Injection Vulnerability | KEVHIGH 8.8EPSS 93.1% | 18 July 2022 |
| CVE-2022-26482 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin. | HIGH 7.2EPSS 22.8% | 17 July 2022 |
| CVE-2022-26352 | dotCMS Unrestricted Upload of File Vulnerability | KEVCRITICAL 9.8EPSS 91.6% | 17 July 2022 |
| CVE-2021-36711 | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. | CRITICAL 9.8EPSS 16.1% | 16 July 2022 |
| CVE-2022-31161 | Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. | CRITICAL 9.8EPSS 28.4% | 15 July 2022 |
| CVE-2022-34221 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code… | HIGH 7.8EPSS 11.1% | 15 July 2022 |
| CVE-2022-31097 | Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. | HIGH 8.7EPSS 68.6% | 15 July 2022 |
| CVE-2022-2419 | A vulnerability was found in URVE Web Manager. | HIGH 8.0EPSS 12.8% | 15 July 2022 |
| CVE-2022-32417 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | CRITICAL 9.8EPSS 35.6% | 14 July 2022 |
| CVE-2022-32409 | A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request. | CRITICAL 9.8EPSS 13.4% | 14 July 2022 |
| CVE-2022-32215 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. | MEDIUM 6.5EPSS 68.8% | 14 July 2022 |
| CVE-2022-32214 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. | MEDIUM 6.5EPSS 82.5% | 14 July 2022 |
| CVE-2022-32213 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | MEDIUM 6.5EPSS 44.1% | 14 July 2022 |
| CVE-2022-29593 | relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request. | MEDIUM 5.9EPSS 14.0% | 14 July 2022 |
| CVE-2022-34753 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. | HIGH 8.8EPSS 71.3% | 13 July 2022 |
| CVE-2022-35628 | A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. | CRITICAL 9.8EPSS 26.1% | 12 July 2022 |
| CVE-2022-30216 | Windows Server Service Tampering Vulnerability | HIGH 8.8EPSS 88.9% | 12 July 2022 |
| CVE-2022-22047 | Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.8% | 12 July 2022 |
| CVE-2022-22025 | Windows Internet Information Services Cachuri Module Denial of Service Vulnerability | HIGH 7.5EPSS 31.9% | 12 July 2022 |
| CVE-2022-1952 | The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. | CRITICAL 9.8EPSS 24.9% | 11 July 2022 |
| CVE-2022-31137 | Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. | CRITICAL 9.8EPSS 90.4% | 8 July 2022 |
| CVE-2022-35411 | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. | CRITICAL 9.8EPSS 46.1% | 8 July 2022 |
| CVE-2022-33098 | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. | MEDIUM 6.1EPSS 52.7% | 7 July 2022 |
| CVE-2022-32449 | TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. | CRITICAL 9.8EPSS 18.8% | 7 July 2022 |
| CVE-2022-32054 | Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter. | CRITICAL 9.8EPSS 34.0% | 7 July 2022 |
| CVE-2022-32206 | The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end… | MEDIUM 6.5EPSS 32.2% | 7 July 2022 |
| CVE-2022-32205 | A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. | MEDIUM 4.3EPSS 27.1% | 7 July 2022 |
| CVE-2022-31854 | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. | HIGH 7.2EPSS 32.8% | 7 July 2022 |
| CVE-2022-25048 | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. | HIGH 8.8EPSS 19.3% | 7 July 2022 |
| CVE-2022-25046 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | CRITICAL 9.8EPSS 57.8% | 7 July 2022 |
| CVE-2022-31126 | A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. | CRITICAL 9.8EPSS 52.1% | 6 July 2022 |
| CVE-2022-31125 | A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. | CRITICAL 9.8EPSS 20.6% | 6 July 2022 |
| CVE-2022-33980 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. | CRITICAL 9.8EPSS 45.1% | 6 July 2022 |
| CVE-2022-34265 | The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. | CRITICAL 9.8EPSS 73.3% | 4 July 2022 |
| CVE-2022-33171 | When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. | CRITICAL 9.8EPSS 20.3% | 4 July 2022 |
| CVE-2022-32420 | College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. | HIGH 8.8EPSS 20.4% | 1 July 2022 |
| CVE-2022-32035 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng. | HIGH 7.5EPSS 14.4% | 1 July 2022 |
| CVE-2022-32032 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule. | CRITICAL 9.8EPSS 10.1% | 1 July 2022 |
| CVE-2022-2230 | A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab… | MEDIUM 4.8EPSS 56.5% | 1 July 2022 |
| CVE-2022-2185 | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted… | HIGH 8.8EPSS 76.9% | 1 July 2022 |
| CVE-2022-2274 | This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. | CRITICAL 9.8EPSS 47.0% | 1 July 2022 |
| CVE-2022-28127 | A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. | CRITICAL 9.1EPSS 37.0% | 30 June 2022 |
| CVE-2022-34783 | Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | MEDIUM 5.4EPSS 80.9% | 30 June 2022 |
| CVE-2022-34777 | Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | MEDIUM 5.4EPSS 72.4% | 30 June 2022 |
| CVE-2022-26135 | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. | MEDIUM 6.5EPSS 71.2% | 30 June 2022 |
| CVE-2022-2073 | Code Injection in GitHub repository getgrav/grav prior to 1.7.34. | HIGH 7.2EPSS 10.9% | 29 June 2022 |
| CVE-2022-33107 | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. | CRITICAL 9.8EPSS 23.9% | 29 June 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.