Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 68 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-31470 | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a… | MEDIUM 6.1EPSS 52.7% | 7 June 2022 |
| CVE-2021-37589 | Virtua Cobranca before 12R allows SQL Injection on the login page. | HIGH 7.5EPSS 32.7% | 7 June 2022 |
| CVE-2022-1680 | When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an… | HIGH 8.8EPSS 15.9% | 6 June 2022 |
| CVE-2022-30860 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. | HIGH 7.2EPSS 24.8% | 6 June 2022 |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 3 June 2022 |
| CVE-2021-42887 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. | CRITICAL 9.8EPSS 44.3% | 3 June 2022 |
| CVE-2022-30808 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | CRITICAL 9.8EPSS 17.5% | 2 June 2022 |
| CVE-2022-30521 | The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. | CRITICAL 9.8EPSS 15.1% | 2 June 2022 |
| CVE-2022-30425 | Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. | HIGH 8.8EPSS 20.0% | 2 June 2022 |
| CVE-2022-28799 | The TikTok application before 23.7.3 for Android allows account takeover. | HIGH 8.8EPSS 16.0% | 2 June 2022 |
| CVE-2022-25237 | Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. | CRITICAL 9.8EPSS 56.4% | 2 June 2022 |
| CVE-2022-1661 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | HIGH 7.5EPSS 15.9% | 2 June 2022 |
| CVE-2022-1660 | The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code. | CRITICAL 9.8EPSS 16.8% | 2 June 2022 |
| CVE-2021-44080 | A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the… | HIGH 7.2EPSS 24.9% | 2 June 2022 |
| CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.2% | 1 June 2022 |
| CVE-2022-31007 | Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. | HIGH 7.2EPSS 26.9% | 31 May 2022 |
| CVE-2022-1556 | The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection | CRITICAL 9.8EPSS 20.1% | 30 May 2022 |
| CVE-2022-29632 | An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file. | CRITICAL 9.8EPSS 17.5% | 26 May 2022 |
| CVE-2022-22675 | Apple macOS Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 12.5% | 26 May 2022 |
| CVE-2022-24422 | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. | CRITICAL 9.8EPSS 57.8% | 26 May 2022 |
| CVE-2022-29660 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | CRITICAL 9.8EPSS 12.0% | 26 May 2022 |
| CVE-2022-20821 | Cisco IOS XR Open Port Vulnerability | KEVMEDIUM 6.5EPSS 12.1% | 26 May 2022 |
| CVE-2022-26833 | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. | CRITICAL 9.4EPSS 37.6% | 25 May 2022 |
| CVE-2022-26082 | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. | CRITICAL 9.8EPSS 20.1% | 25 May 2022 |
| CVE-2022-29337 | C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. | CRITICAL 9.8EPSS 35.5% | 24 May 2022 |
| CVE-2021-32941 | Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user… | CRITICAL 9.8EPSS 14.6% | 23 May 2022 |
| CVE-2022-0781 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection | CRITICAL 9.8EPSS 13.1% | 23 May 2022 |
| CVE-2022-31268 | A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname). | HIGH 7.5EPSS 10.7% | 21 May 2022 |
| CVE-2022-31267 | Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext 'attacker@example.com\n\trole = "#admin"' value. | CRITICAL 9.8EPSS 17.5% | 21 May 2022 |
| CVE-2022-31259 | The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. | CRITICAL 9.8EPSS 22.2% | 21 May 2022 |
| CVE-2022-22972 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. | CRITICAL 9.8EPSS 56.3% | 20 May 2022 |
| CVE-2022-28531 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | CRITICAL 9.8EPSS 14.6% | 20 May 2022 |
| CVE-2022-30887 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. | CRITICAL 9.8EPSS 25.8% | 20 May 2022 |
| CVE-2022-28987 | Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login. | MEDIUM 5.3EPSS 10.3% | 20 May 2022 |
| CVE-2022-21500 | Vulnerability in Oracle E-Business Suite (component: Manage Proxies). | HIGH 7.5EPSS 71.7% | 20 May 2022 |
| CVE-2022-28927 | A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters. | CRITICAL 9.8EPSS 34.4% | 19 May 2022 |
| CVE-2022-22978 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. | CRITICAL 9.8EPSS 12.4% | 19 May 2022 |
| CVE-2022-28956 | An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload. | CRITICAL 9.8EPSS 22.7% | 18 May 2022 |
| CVE-2022-28955 | An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php. | HIGH 7.5EPSS 39.7% | 18 May 2022 |
| CVE-2022-1118 | Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. | HIGH 7.8EPSS 11.1% | 17 May 2022 |
| CVE-2022-24856 | FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. | HIGH 7.5EPSS 10.5% | 17 May 2022 |
| CVE-2022-24108 | The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting parameter, potentially resulting in the ability to write to files on the server, cause DoS, and achieve remote code… | CRITICAL 9.8EPSS 32.6% | 17 May 2022 |
| CVE-2022-30956 | Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads. | MEDIUM 5.4EPSS 73.3% | 17 May 2022 |
| CVE-2022-1386 | The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. | CRITICAL 9.8EPSS 71.4% | 16 May 2022 |
| CVE-2022-1103 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | HIGH 8.8EPSS 15.6% | 16 May 2022 |
| CVE-2022-0867 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users | CRITICAL 9.8EPSS 13.5% | 16 May 2022 |
| CVE-2022-30011 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. | CRITICAL 9.8EPSS 18.7% | 16 May 2022 |
| CVE-2022-30781 | Gitea before 1.16.7 does not escape git fetch remote. | HIGH 7.5EPSS 89.4% | 16 May 2022 |
| CVE-2022-29383 | NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi. | CRITICAL 9.8EPSS 48.5% | 13 May 2022 |
| CVE-2022-28818 | ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | MEDIUM 6.1EPSS 44.8% | 12 May 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.