SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 69 of 348

CVESummaryPriorityPublished
CVE-2022-26085An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4.HIGH 8.8EPSS 12.8%12 May 2022
CVE-2022-29307IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.CRITICAL 9.8EPSS 18.3%12 May 2022
CVE-2022-29303SolarView Compact Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.0%12 May 2022
CVE-2022-29298SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.HIGH 7.5EPSS 46.8%12 May 2022
CVE-2022-30525Zyxel Multiple Firewalls OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.9%12 May 2022
CVE-2022-29885The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network.HIGH 7.5EPSS 73.5%12 May 2022
CVE-2022-30450A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.phpCRITICAL 9.8EPSS 21.6%11 May 2022
CVE-2022-30063ftcms <=2.1 was discovered to be vulnerable to code execution attacks .CRITICAL 9.8EPSS 18.0%11 May 2022
CVE-2022-30453ShopWind <= 3.4.2 has a RCE vulnerability in Database.phpCRITICAL 9.8EPSS 15.7%11 May 2022
CVE-2022-29847In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.HIGH 7.5EPSS 57.6%11 May 2022
CVE-2022-28269Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of…LOW 3.3EPSS 10.7%11 May 2022
CVE-2022-28258Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated…MEDIUM 5.5EPSS 10.1%11 May 2022
CVE-2022-28246Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated…MEDIUM 5.5EPSS 10.1%11 May 2022
CVE-2022-28243Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated…HIGH 7.8EPSS 11.0%11 May 2022
CVE-2022-28240Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-28238Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context…HIGH 7.8EPSS 11.9%11 May 2022
CVE-2022-28236Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 11.6%11 May 2022
CVE-2022-28233Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context…HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-28232Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the collab object that could result in arbitrary code execution in the…HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-28230Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the…HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-27799Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the…HIGH 7.8EPSS 17.7%11 May 2022
CVE-2022-27796Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the…HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-27794Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by the use of a variable that has not been initialized when processing of embedded fonts, potentially resulting in arbitrary…HIGH 7.8EPSS 14.3%11 May 2022
CVE-2022-27791Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbitrary code…HIGH 7.8EPSS 17.8%11 May 2022
CVE-2022-27790Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of…HIGH 7.8EPSS 11.9%11 May 2022
CVE-2022-27787Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 10.3%11 May 2022
CVE-2022-27786Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of…HIGH 7.8EPSS 12.1%11 May 2022
CVE-2022-27785Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of…HIGH 7.8EPSS 12.5%11 May 2022
CVE-2022-24104Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 11.1%11 May 2022
CVE-2022-24102Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 12.6%11 May 2022
CVE-2022-29009Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.CRITICAL 9.8EPSS 22.9%11 May 2022
CVE-2022-29007Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.CRITICAL 9.8EPSS 19.3%11 May 2022
CVE-2022-29006Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.CRITICAL 9.8EPSS 19.3%11 May 2022
CVE-2022-30129Visual Studio Code Remote Code Execution VulnerabilityHIGH 8.8EPSS 41.3%10 May 2022
CVE-2022-29108Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 11.9%10 May 2022
CVE-2022-29104Windows Print Spooler Elevation of Privilege VulnerabilityHIGH 7.8EPSS 11.8%10 May 2022
CVE-2022-26937Windows Network File System Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 76.0%10 May 2022
CVE-2022-26925Microsoft Windows LSA Spoofing VulnerabilityKEVMEDIUM 5.9EPSS 10.7%10 May 2022
CVE-2022-26923Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 83.5%10 May 2022
CVE-2022-23270Windows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityHIGH 8.1EPSS 70.3%10 May 2022
CVE-2022-22017Remote Desktop Client Remote Code Execution VulnerabilityHIGH 8.8EPSS 37.1%10 May 2022
CVE-2022-21972Windows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityHIGH 8.1EPSS 79.3%10 May 2022
CVE-2022-1476The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58.MEDIUM 6.5EPSS 47.9%10 May 2022
CVE-2022-23677A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch…HIGH 8.1EPSS 20.5%10 May 2022
CVE-2022-23676A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch…CRITICAL 9.8EPSS 23.0%10 May 2022
CVE-2022-29329D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.CRITICAL 9.8EPSS 13.7%10 May 2022
CVE-2022-29328D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.CRITICAL 9.8EPSS 13.7%10 May 2022
CVE-2022-29322D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.CRITICAL 9.8EPSS 16.9%10 May 2022
CVE-2022-1104The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…MEDIUM 4.8EPSS 56.4%9 May 2022
CVE-2022-0817The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated usersCRITICAL 9.8EPSS 11.6%9 May 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.