SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,890 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 17 September 2026

17,380 results · page 70 of 348

CVESummaryPriorityPublished
CVE-2022-0592The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.CRITICAL 9.8EPSS 10.4%9 May 2022
CVE-2022-30286pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.HIGH 7.5EPSS 13.6%9 May 2022
CVE-2022-30333RARLAB UnRAR Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 99.1%9 May 2022
CVE-2020-19213SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.CRITICAL 9.8EPSS 15.9%6 May 2022
CVE-2022-30295uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning.MEDIUM 6.5EPSS 12.2%6 May 2022
CVE-2022-29535Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.CRITICAL 9.8EPSS 91.8%5 May 2022
CVE-2022-29592Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).CRITICAL 9.8EPSS 20.1%5 May 2022
CVE-2022-28080Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.HIGH 8.8EPSS 56.9%5 May 2022
CVE-2022-28079College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.HIGH 8.8EPSS 28.5%5 May 2022
CVE-2022-1388F5 BIG-IP Missing Authentication VulnerabilityKEVCRITICAL 9.8EPSS 100.0%5 May 2022
CVE-2022-29155In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query.CRITICAL 9.8EPSS 64.5%4 May 2022
CVE-2022-20780Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host…HIGH 7.4EPSS 11.2%4 May 2022
CVE-2022-20779Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host…HIGH 8.8EPSS 10.5%4 May 2022
CVE-2022-20777Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host…CRITICAL 9.9EPSS 11.1%4 May 2022
CVE-2022-28557There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command executionCRITICAL 9.8EPSS 22.6%4 May 2022
CVE-2022-28096Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.HIGH 7.2EPSS 20.6%4 May 2022
CVE-2021-42192Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.HIGH 8.8EPSS 10.1%4 May 2022
CVE-2021-43164A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.HIGH 8.8EPSS 35.0%4 May 2022
CVE-2022-28561There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router.CRITICAL 9.8EPSS 10.1%3 May 2022
CVE-2022-1292The c_rehash script does not properly sanitise shell metacharacters to prevent command injection.HIGH 7.3EPSS 82.6%3 May 2022
CVE-2022-28590A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.HIGH 7.2EPSS 23.8%3 May 2022
CVE-2021-42165MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".HIGH 8.8EPSS 14.1%3 May 2022
CVE-2022-20759A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate…HIGH 8.8EPSS 28.2%3 May 2022
CVE-2022-1378Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx.CRITICAL 9.8EPSS 19.3%2 May 2022
CVE-2022-1367Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx.CRITICAL 9.8EPSS 19.3%2 May 2022
CVE-2022-1366Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx.CRITICAL 9.8EPSS 19.3%2 May 2022
CVE-2022-1281The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.CRITICAL 9.8EPSS 43.0%2 May 2022
CVE-2022-0952The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin.HIGH 8.8EPSS 11.4%2 May 2022
CVE-2022-0773The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.CRITICAL 9.8EPSS 43.3%2 May 2022
CVE-2022-28573D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting.CRITICAL 9.8EPSS 28.2%2 May 2022
CVE-2022-28054Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.CRITICAL 9.8EPSS 31.9%2 May 2022
CVE-2021-40822GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.HIGH 7.5EPSS 19.3%2 May 2022
CVE-2022-25647The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.HIGH 7.5EPSS 12.2%1 May 2022
CVE-2022-28452Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.CRITICAL 9.8EPSS 17.1%29 April 2022
CVE-2021-44596Fone as of 2021-12-06 version is affected by Remote code execution.CRITICAL 9.8EPSS 22.9%29 April 2022
CVE-2021-44595Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control.HIGH 8.8EPSS 21.1%29 April 2022
CVE-2022-29904The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.CRITICAL 9.8EPSS 16.8%29 April 2022
CVE-2022-29081Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction.CRITICAL 9.8EPSS 83.5%28 April 2022
CVE-2022-28117A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.MEDIUM 4.9EPSS 22.9%28 April 2022
CVE-2022-27336Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.CRITICAL 9.8EPSS 20.5%27 April 2022
CVE-2021-46424Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.CRITICAL 9.1EPSS 36.5%27 April 2022
CVE-2021-46422Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.CRITICAL 9.8EPSS 94.3%27 April 2022
CVE-2021-46442In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.CRITICAL 9.8EPSS 55.5%27 April 2022
CVE-2021-46441In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.HIGH 8.8EPSS 32.6%27 April 2022
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource VulnerabilityKEVCRITICAL 9.8EPSS 92.5%26 April 2022
CVE-2022-29806ZoneMinder before 1.36.13 allows remote code execution via an invalid language.CRITICAL 9.8EPSS 67.1%26 April 2022
CVE-2022-29499Mitel MiVoice Connect Data Validation VulnerabilityKEVCRITICAL 9.8EPSS 55.6%26 April 2022
CVE-2021-35250A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3.HIGH 7.5EPSS 12.8%25 April 2022
CVE-2022-1392The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issuesHIGH 7.5EPSS 11.3%25 April 2022
CVE-2022-1391The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.CRITICAL 9.8EPSS 15.1%25 April 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.