SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 68 of 348

CVESummaryPriorityPublished
CVE-2022-31470An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a…MEDIUM 6.1EPSS 52.7%7 June 2022
CVE-2021-37589Virtua Cobranca before 12R allows SQL Injection on the login page.HIGH 7.5EPSS 32.7%7 June 2022
CVE-2022-1680When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an…HIGH 8.8EPSS 15.9%6 June 2022
CVE-2022-30860FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.HIGH 7.2EPSS 24.8%6 June 2022
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%3 June 2022
CVE-2021-42887In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.CRITICAL 9.8EPSS 44.3%3 June 2022
CVE-2022-30808elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.CRITICAL 9.8EPSS 17.5%2 June 2022
CVE-2022-30521The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions.CRITICAL 9.8EPSS 15.1%2 June 2022
CVE-2022-30425Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters.HIGH 8.8EPSS 20.0%2 June 2022
CVE-2022-28799The TikTok application before 23.7.3 for Android allows account takeover.HIGH 8.8EPSS 16.0%2 June 2022
CVE-2022-25237Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter.CRITICAL 9.8EPSS 56.4%2 June 2022
CVE-2022-1661The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.HIGH 7.5EPSS 15.9%2 June 2022
CVE-2022-1660The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.CRITICAL 9.8EPSS 16.8%2 June 2022
CVE-2021-44080A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the…HIGH 7.2EPSS 24.9%2 June 2022
CVE-2022-30190Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 99.2%1 June 2022
CVE-2022-31007Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account.HIGH 7.2EPSS 26.9%31 May 2022
CVE-2022-1556The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL InjectionCRITICAL 9.8EPSS 20.1%30 May 2022
CVE-2022-29632An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.CRITICAL 9.8EPSS 17.5%26 May 2022
CVE-2022-22675Apple macOS Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 12.5%26 May 2022
CVE-2022-24422Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.CRITICAL 9.8EPSS 57.8%26 May 2022
CVE-2022-29660CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.CRITICAL 9.8EPSS 12.0%26 May 2022
CVE-2022-20821Cisco IOS XR Open Port VulnerabilityKEVMEDIUM 6.5EPSS 12.1%26 May 2022
CVE-2022-26833An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121.CRITICAL 9.4EPSS 37.6%25 May 2022
CVE-2022-26082A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112.CRITICAL 9.8EPSS 20.1%25 May 2022
CVE-2022-29337C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6.CRITICAL 9.8EPSS 35.5%24 May 2022
CVE-2021-32941Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user…CRITICAL 9.8EPSS 14.6%23 May 2022
CVE-2022-0781The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injectionCRITICAL 9.8EPSS 13.1%23 May 2022
CVE-2022-31268A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).HIGH 7.5EPSS 10.7%21 May 2022
CVE-2022-31267Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext 'attacker@example.com\n\trole = "#admin"' value.CRITICAL 9.8EPSS 17.5%21 May 2022
CVE-2022-31259The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control.CRITICAL 9.8EPSS 22.2%21 May 2022
CVE-2022-22972VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.CRITICAL 9.8EPSS 56.3%20 May 2022
CVE-2022-28531Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.CRITICAL 9.8EPSS 14.6%20 May 2022
CVE-2022-30887Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php.CRITICAL 9.8EPSS 25.8%20 May 2022
CVE-2022-28987Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.MEDIUM 5.3EPSS 10.3%20 May 2022
CVE-2022-21500Vulnerability in Oracle E-Business Suite (component: Manage Proxies).HIGH 7.5EPSS 71.7%20 May 2022
CVE-2022-28927A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters.CRITICAL 9.8EPSS 34.4%19 May 2022
CVE-2022-22978In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers.CRITICAL 9.8EPSS 12.4%19 May 2022
CVE-2022-28956An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.CRITICAL 9.8EPSS 22.7%18 May 2022
CVE-2022-28955An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.HIGH 7.5EPSS 39.7%18 May 2022
CVE-2022-1118Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized.HIGH 7.8EPSS 11.1%17 May 2022
CVE-2022-24856FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet.HIGH 7.5EPSS 10.5%17 May 2022
CVE-2022-24108The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code…CRITICAL 9.8EPSS 32.6%17 May 2022
CVE-2022-30956Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.MEDIUM 5.4EPSS 73.3%17 May 2022
CVE-2022-1386The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests.CRITICAL 9.8EPSS 71.4%16 May 2022
CVE-2022-1103The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCEHIGH 8.8EPSS 15.6%16 May 2022
CVE-2022-0867The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated usersCRITICAL 9.8EPSS 13.5%16 May 2022
CVE-2022-30011In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.CRITICAL 9.8EPSS 18.7%16 May 2022
CVE-2022-30781Gitea before 1.16.7 does not escape git fetch remote.HIGH 7.5EPSS 89.4%16 May 2022
CVE-2022-29383NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.CRITICAL 9.8EPSS 48.5%13 May 2022
CVE-2022-28818ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability.MEDIUM 6.1EPSS 44.8%12 May 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.