Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 67 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-32532 | Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. | CRITICAL 9.8EPSS 26.2% | 29 June 2022 |
| CVE-2022-31885 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | CRITICAL 9.8EPSS 32.8% | 28 June 2022 |
| CVE-2022-31061 | In affected versions there is a SQL injection vulnerability which is possible on login page. | CRITICAL 9.8EPSS 51.4% | 28 June 2022 |
| CVE-2022-32995 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. | CRITICAL 9.8EPSS 17.6% | 27 June 2022 |
| CVE-2022-32994 | Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. | CRITICAL 9.8EPSS 18.5% | 27 June 2022 |
| CVE-2022-31101 | In affected versions an authenticated customer can perform SQL injection. | HIGH 8.8EPSS 23.5% | 27 June 2022 |
| CVE-2022-28171 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. | CRITICAL 9.8EPSS 51.6% | 27 June 2022 |
| CVE-2022-1574 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server | CRITICAL 9.8EPSS 12.2% | 27 June 2022 |
| CVE-2022-20828 | A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA… | HIGH 7.2EPSS 49.3% | 24 June 2022 |
| CVE-2022-32209 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected:… | MEDIUM 6.1EPSS 30.2% | 24 June 2022 |
| CVE-2013-1916 | This backdoor can be called (executed) even if the photo has not been yet approved. | HIGH 8.8EPSS 12.8% | 24 June 2022 |
| CVE-2022-34176 | Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission. | MEDIUM 5.4EPSS 78.0% | 23 June 2022 |
| CVE-2022-31362 | Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. | HIGH 8.8EPSS 18.3% | 23 June 2022 |
| CVE-2022-22980 | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized. | CRITICAL 9.8EPSS 17.8% | 23 June 2022 |
| CVE-2022-2068 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. | HIGH 7.3EPSS 95.4% | 21 June 2022 |
| CVE-2022-29775 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. | CRITICAL 9.8EPSS 60.3% | 21 June 2022 |
| CVE-2022-25772 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript | MEDIUM 6.1EPSS 62.3% | 20 June 2022 |
| CVE-2022-1905 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | CRITICAL 9.8EPSS 37.1% | 20 June 2022 |
| CVE-2022-31874 | ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. | CRITICAL 9.8EPSS 20.0% | 17 June 2022 |
| CVE-2022-27511 | Corruption of the system by a remote, unauthenticated user. | HIGH 8.1EPSS 12.4% | 16 June 2022 |
| CVE-2022-24562 | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and… | CRITICAL 9.8EPSS 54.5% | 16 June 2022 |
| CVE-2022-30023 | Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. | HIGH 8.8EPSS 39.2% | 16 June 2022 |
| CVE-2022-31626 | In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can… | HIGH 8.8EPSS 58.1% | 16 June 2022 |
| CVE-2022-30136 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 73.2% | 15 June 2022 |
| CVE-2021-41403 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | CRITICAL 9.8EPSS 19.1% | 15 June 2022 |
| CVE-2022-24436 | Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access. | MEDIUM 6.5EPSS 12.3% | 15 June 2022 |
| CVE-2022-2086 | A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. | HIGH 8.8EPSS 19.6% | 15 June 2022 |
| CVE-2022-29034 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). | MEDIUM 6.1EPSS 28.7% | 14 June 2022 |
| CVE-2022-31446 | Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | CRITICAL 9.8EPSS 34.8% | 14 June 2022 |
| CVE-2022-33174 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. | HIGH 7.5EPSS 14.1% | 13 June 2022 |
| CVE-2022-29455 | DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions. | MEDIUM 6.1EPSS 23.7% | 13 June 2022 |
| CVE-2022-1768 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. | HIGH 7.5EPSS 12.9% | 13 June 2022 |
| CVE-2022-1707 | The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including… | MEDIUM 6.1EPSS 89.3% | 13 June 2022 |
| CVE-2022-0863 | The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution. | HIGH 7.2EPSS 23.8% | 13 June 2022 |
| CVE-2022-0786 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users | CRITICAL 9.8EPSS 13.3% | 13 June 2022 |
| CVE-2021-41749 | In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution. | CRITICAL 9.8EPSS 18.1% | 12 June 2022 |
| CVE-2022-30780 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. | HIGH 7.5EPSS 56.9% | 11 June 2022 |
| CVE-2022-25845 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. | CRITICAL 9.8EPSS 18.7% | 10 June 2022 |
| CVE-2022-31788 | IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname. | CRITICAL 9.8EPSS 14.7% | 10 June 2022 |
| CVE-2017-20029 | A vulnerability was found in PHPList 3.2.6 and classified as critical. | CRITICAL 9.8EPSS 21.0% | 10 June 2022 |
| CVE-2022-30522 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | HIGH 7.5EPSS 89.5% | 9 June 2022 |
| CVE-2022-26377 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. | HIGH 7.5EPSS 21.1% | 9 June 2022 |
| CVE-2022-1993 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | HIGH 8.1EPSS 36.3% | 9 June 2022 |
| CVE-2022-31830 | Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php. | CRITICAL 9.1EPSS 16.2% | 9 June 2022 |
| CVE-2022-31827 | MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php. | CRITICAL 9.1EPSS 21.7% | 9 June 2022 |
| CVE-2022-30075 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation. | HIGH 8.8EPSS 33.8% | 9 June 2022 |
| CVE-2022-29014 | A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files. | HIGH 7.5EPSS 11.8% | 9 June 2022 |
| CVE-2022-29013 | A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request. | CRITICAL 9.8EPSS 76.9% | 9 June 2022 |
| CVE-2022-1692 | The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to… | CRITICAL 9.8EPSS 10.6% | 8 June 2022 |
| CVE-2022-1703 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service… | HIGH 8.8EPSS 12.3% | 8 June 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.