Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,890 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 17 September 2026
17,380 results · page 70 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-0592 | The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users. | CRITICAL 9.8EPSS 10.4% | 9 May 2022 |
| CVE-2022-30286 | pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code. | HIGH 7.5EPSS 13.6% | 9 May 2022 |
| CVE-2022-30333 | RARLAB UnRAR Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 99.1% | 9 May 2022 |
| CVE-2020-19213 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. | CRITICAL 9.8EPSS 15.9% | 6 May 2022 |
| CVE-2022-30295 | uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. | MEDIUM 6.5EPSS 12.2% | 6 May 2022 |
| CVE-2022-29535 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | CRITICAL 9.8EPSS 91.8% | 5 May 2022 |
| CVE-2022-29592 | Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). | CRITICAL 9.8EPSS 20.1% | 5 May 2022 |
| CVE-2022-28080 | Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | HIGH 8.8EPSS 56.9% | 5 May 2022 |
| CVE-2022-28079 | College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | HIGH 8.8EPSS 28.5% | 5 May 2022 |
| CVE-2022-1388 | F5 BIG-IP Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 May 2022 |
| CVE-2022-29155 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. | CRITICAL 9.8EPSS 64.5% | 4 May 2022 |
| CVE-2022-20780 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host… | HIGH 7.4EPSS 11.2% | 4 May 2022 |
| CVE-2022-20779 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host… | HIGH 8.8EPSS 10.5% | 4 May 2022 |
| CVE-2022-20777 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host… | CRITICAL 9.9EPSS 11.1% | 4 May 2022 |
| CVE-2022-28557 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | CRITICAL 9.8EPSS 22.6% | 4 May 2022 |
| CVE-2022-28096 | Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php. | HIGH 7.2EPSS 20.6% | 4 May 2022 |
| CVE-2021-42192 | Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. | HIGH 8.8EPSS 10.1% | 4 May 2022 |
| CVE-2021-43164 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless. | HIGH 8.8EPSS 35.0% | 4 May 2022 |
| CVE-2022-28561 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. | CRITICAL 9.8EPSS 10.1% | 3 May 2022 |
| CVE-2022-1292 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. | HIGH 7.3EPSS 82.6% | 3 May 2022 |
| CVE-2022-28590 | A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme. | HIGH 7.2EPSS 23.8% | 3 May 2022 |
| CVE-2021-42165 | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path". | HIGH 8.8EPSS 14.1% | 3 May 2022 |
| CVE-2022-20759 | A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate… | HIGH 8.8EPSS 28.2% | 3 May 2022 |
| CVE-2022-1378 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. | CRITICAL 9.8EPSS 19.3% | 2 May 2022 |
| CVE-2022-1367 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. | CRITICAL 9.8EPSS 19.3% | 2 May 2022 |
| CVE-2022-1366 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. | CRITICAL 9.8EPSS 19.3% | 2 May 2022 |
| CVE-2022-1281 | The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible. | CRITICAL 9.8EPSS 43.0% | 2 May 2022 |
| CVE-2022-0952 | The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. | HIGH 8.8EPSS 11.4% | 2 May 2022 |
| CVE-2022-0773 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users. | CRITICAL 9.8EPSS 43.3% | 2 May 2022 |
| CVE-2022-28573 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. | CRITICAL 9.8EPSS 28.2% | 2 May 2022 |
| CVE-2022-28054 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | CRITICAL 9.8EPSS 31.9% | 2 May 2022 |
| CVE-2021-40822 | GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. | HIGH 7.5EPSS 19.3% | 2 May 2022 |
| CVE-2022-25647 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. | HIGH 7.5EPSS 12.2% | 1 May 2022 |
| CVE-2022-28452 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | CRITICAL 9.8EPSS 17.1% | 29 April 2022 |
| CVE-2021-44596 | Fone as of 2021-12-06 version is affected by Remote code execution. | CRITICAL 9.8EPSS 22.9% | 29 April 2022 |
| CVE-2021-44595 | Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. | HIGH 8.8EPSS 21.1% | 29 April 2022 |
| CVE-2022-29904 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | CRITICAL 9.8EPSS 16.8% | 29 April 2022 |
| CVE-2022-29081 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. | CRITICAL 9.8EPSS 83.5% | 28 April 2022 |
| CVE-2022-28117 | A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter. | MEDIUM 4.9EPSS 22.9% | 28 April 2022 |
| CVE-2022-27336 | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. | CRITICAL 9.8EPSS 20.5% | 27 April 2022 |
| CVE-2021-46424 | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request. | CRITICAL 9.1EPSS 36.5% | 27 April 2022 |
| CVE-2021-46422 | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. | CRITICAL 9.8EPSS 94.3% | 27 April 2022 |
| CVE-2021-46442 | In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization. | CRITICAL 9.8EPSS 55.5% | 27 April 2022 |
| CVE-2021-46441 | In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization. | HIGH 8.8EPSS 32.6% | 27 April 2022 |
| CVE-2022-24706 | Apache CouchDB Insecure Default Initialization of Resource Vulnerability | KEVCRITICAL 9.8EPSS 92.5% | 26 April 2022 |
| CVE-2022-29806 | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. | CRITICAL 9.8EPSS 67.1% | 26 April 2022 |
| CVE-2022-29499 | Mitel MiVoice Connect Data Validation Vulnerability | KEVCRITICAL 9.8EPSS 55.6% | 26 April 2022 |
| CVE-2021-35250 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. | HIGH 7.5EPSS 12.8% | 25 April 2022 |
| CVE-2022-1392 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | HIGH 7.5EPSS 11.3% | 25 April 2022 |
| CVE-2022-1391 | The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues. | CRITICAL 9.8EPSS 15.1% | 25 April 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.