Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,888 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 69 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-26085 | An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. | HIGH 8.8EPSS 12.8% | 12 May 2022 |
| CVE-2022-29307 | IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. | CRITICAL 9.8EPSS 18.3% | 12 May 2022 |
| CVE-2022-29303 | SolarView Compact Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 12 May 2022 |
| CVE-2022-29298 | SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. | HIGH 7.5EPSS 46.8% | 12 May 2022 |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 12 May 2022 |
| CVE-2022-29885 | The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. | HIGH 7.5EPSS 73.5% | 12 May 2022 |
| CVE-2022-30450 | A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php | CRITICAL 9.8EPSS 21.6% | 11 May 2022 |
| CVE-2022-30063 | ftcms <=2.1 was discovered to be vulnerable to code execution attacks . | CRITICAL 9.8EPSS 18.0% | 11 May 2022 |
| CVE-2022-30453 | ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | CRITICAL 9.8EPSS 15.7% | 11 May 2022 |
| CVE-2022-29847 | In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host. | HIGH 7.5EPSS 57.6% | 11 May 2022 |
| CVE-2022-28269 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of… | LOW 3.3EPSS 10.7% | 11 May 2022 |
| CVE-2022-28258 | Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated… | MEDIUM 5.5EPSS 10.1% | 11 May 2022 |
| CVE-2022-28246 | Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated… | MEDIUM 5.5EPSS 10.1% | 11 May 2022 |
| CVE-2022-28243 | Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated… | HIGH 7.8EPSS 11.0% | 11 May 2022 |
| CVE-2022-28240 | Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-28238 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context… | HIGH 7.8EPSS 11.9% | 11 May 2022 |
| CVE-2022-28236 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 11.6% | 11 May 2022 |
| CVE-2022-28233 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context… | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-28232 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the collab object that could result in arbitrary code execution in the… | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-28230 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the… | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-27799 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the… | HIGH 7.8EPSS 17.7% | 11 May 2022 |
| CVE-2022-27796 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the… | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-27794 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by the use of a variable that has not been initialized when processing of embedded fonts, potentially resulting in arbitrary… | HIGH 7.8EPSS 14.3% | 11 May 2022 |
| CVE-2022-27791 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbitrary code… | HIGH 7.8EPSS 17.8% | 11 May 2022 |
| CVE-2022-27790 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of… | HIGH 7.8EPSS 11.9% | 11 May 2022 |
| CVE-2022-27787 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 10.3% | 11 May 2022 |
| CVE-2022-27786 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of… | HIGH 7.8EPSS 12.1% | 11 May 2022 |
| CVE-2022-27785 | Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of… | HIGH 7.8EPSS 12.5% | 11 May 2022 |
| CVE-2022-24104 | Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 11.1% | 11 May 2022 |
| CVE-2022-24102 | Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 12.6% | 11 May 2022 |
| CVE-2022-29009 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. | CRITICAL 9.8EPSS 22.9% | 11 May 2022 |
| CVE-2022-29007 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication. | CRITICAL 9.8EPSS 19.3% | 11 May 2022 |
| CVE-2022-29006 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication. | CRITICAL 9.8EPSS 19.3% | 11 May 2022 |
| CVE-2022-30129 | Visual Studio Code Remote Code Execution Vulnerability | HIGH 8.8EPSS 41.3% | 10 May 2022 |
| CVE-2022-29108 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 11.9% | 10 May 2022 |
| CVE-2022-29104 | Windows Print Spooler Elevation of Privilege Vulnerability | HIGH 7.8EPSS 11.8% | 10 May 2022 |
| CVE-2022-26937 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 76.0% | 10 May 2022 |
| CVE-2022-26925 | Microsoft Windows LSA Spoofing Vulnerability | KEVMEDIUM 5.9EPSS 10.7% | 10 May 2022 |
| CVE-2022-26923 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 83.5% | 10 May 2022 |
| CVE-2022-23270 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | HIGH 8.1EPSS 70.3% | 10 May 2022 |
| CVE-2022-22017 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH 8.8EPSS 37.1% | 10 May 2022 |
| CVE-2022-21972 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | HIGH 8.1EPSS 79.3% | 10 May 2022 |
| CVE-2022-1476 | The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. | MEDIUM 6.5EPSS 47.9% | 10 May 2022 |
| CVE-2022-23677 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch… | HIGH 8.1EPSS 20.5% | 10 May 2022 |
| CVE-2022-23676 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch… | CRITICAL 9.8EPSS 23.0% | 10 May 2022 |
| CVE-2022-29329 | D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings. | CRITICAL 9.8EPSS 13.7% | 10 May 2022 |
| CVE-2022-29328 | D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade. | CRITICAL 9.8EPSS 13.7% | 10 May 2022 |
| CVE-2022-29322 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip. | CRITICAL 9.8EPSS 16.9% | 10 May 2022 |
| CVE-2022-1104 | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is… | MEDIUM 4.8EPSS 56.4% | 9 May 2022 |
| CVE-2022-0817 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users | CRITICAL 9.8EPSS 11.6% | 9 May 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.