Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,890 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 17 September 2026
17,380 results · page 71 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-1390 | The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte… | CRITICAL 9.8EPSS 21.9% | 25 April 2022 |
| CVE-2021-25094 | By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. | HIGH 8.1EPSS 83.4% | 25 April 2022 |
| CVE-2022-29078 | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. | CRITICAL 9.8EPSS 32.8% | 25 April 2022 |
| CVE-2021-45837 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del. | CRITICAL 9.8EPSS 16.0% | 25 April 2022 |
| CVE-2022-1429 | SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. | HIGH 7.5EPSS 63.9% | 22 April 2022 |
| CVE-2022-28021 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | CRITICAL 9.8EPSS 24.3% | 21 April 2022 |
| CVE-2022-27478 | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. | HIGH 8.8EPSS 20.0% | 21 April 2022 |
| CVE-2022-29548 | A reflected XSS issue exists in the Management Console of several WSO2 products. | MEDIUM 6.1EPSS 41.1% | 21 April 2022 |
| CVE-2022-27926 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 17.6% | 21 April 2022 |
| CVE-2022-27925 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | KEVHIGH 7.2EPSS 98.7% | 21 April 2022 |
| CVE-2022-27924 | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability | KEVHIGH 7.5EPSS 85.4% | 21 April 2022 |
| CVE-2022-26133 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated… | CRITICAL 9.8EPSS 70.4% | 20 April 2022 |
| CVE-2022-0540 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. | CRITICAL 9.8EPSS 88.1% | 20 April 2022 |
| CVE-2022-21490 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). | MEDIUM 6.3EPSS 78.7% | 19 April 2022 |
| CVE-2022-21489 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). | MEDIUM 6.3EPSS 78.9% | 19 April 2022 |
| CVE-2022-21449 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). | HIGH 7.5EPSS 60.3% | 19 April 2022 |
| CVE-2022-21445 | Oracle ADF Faces Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 62.5% | 19 April 2022 |
| CVE-2022-1329 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site… | HIGH 8.8EPSS 92.7% | 19 April 2022 |
| CVE-2022-1119 | The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file… | HIGH 7.5EPSS 20.0% | 19 April 2022 |
| CVE-2022-27927 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. | CRITICAL 9.8EPSS 13.8% | 19 April 2022 |
| CVE-2022-28108 | Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain. | HIGH 8.8EPSS 11.7% | 19 April 2022 |
| CVE-2022-29464 | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 18 April 2022 |
| CVE-2022-1020 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does… | CRITICAL 9.8EPSS 25.9% | 18 April 2022 |
| CVE-2022-0661 | The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading… | HIGH 7.2EPSS 40.2% | 18 April 2022 |
| CVE-2022-25226 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. | CRITICAL 10.0EPSS 11.0% | 18 April 2022 |
| CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | KEVMEDIUM 6.8EPSS 71.0% | 18 April 2022 |
| CVE-2022-27908 | Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. | HIGH 8.8EPSS 36.5% | 18 April 2022 |
| CVE-2022-26809 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 91.0% | 15 April 2022 |
| CVE-2022-24500 | Windows SMB Remote Code Execution Vulnerability | HIGH 8.8EPSS 38.0% | 15 April 2022 |
| CVE-2022-24497 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 34.6% | 15 April 2022 |
| CVE-2022-24491 | Windows Network File System Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 33.5% | 15 April 2022 |
| CVE-2022-24481 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH 7.8EPSS 16.6% | 15 April 2022 |
| CVE-2022-20695 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This… | CRITICAL 10.0EPSS 19.8% | 15 April 2022 |
| CVE-2022-27474 | SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. | HIGH 7.2EPSS 23.1% | 15 April 2022 |
| CVE-2022-26498 | An issue was discovered in Asterisk through 19.x. | HIGH 7.5EPSS 16.7% | 15 April 2022 |
| CVE-2022-22149 | A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. | HIGH 8.8EPSS 72.6% | 14 April 2022 |
| CVE-2022-21234 | An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. | HIGH 8.8EPSS 72.6% | 14 April 2022 |
| CVE-2022-21210 | An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. | HIGH 8.8EPSS 71.2% | 14 April 2022 |
| CVE-2022-21145 | A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. | MEDIUM 4.8EPSS 77.8% | 14 April 2022 |
| CVE-2021-43287 | The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers. | HIGH 7.5EPSS 28.0% | 14 April 2022 |
| CVE-2022-24816 | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 98.5% | 13 April 2022 |
| CVE-2022-22960 | VMware Multiple Products Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 35.8% | 13 April 2022 |
| CVE-2022-22957 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). | HIGH 7.2EPSS 23.9% | 13 April 2022 |
| CVE-2022-22956 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. | CRITICAL 9.8EPSS 49.8% | 13 April 2022 |
| CVE-2021-22797 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation… | HIGH 7.8EPSS 26.1% | 13 April 2022 |
| CVE-2022-29036 | Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a… | MEDIUM 5.4EPSS 79.0% | 12 April 2022 |
| CVE-2022-28213 | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the… | HIGH 8.1EPSS 12.5% | 12 April 2022 |
| CVE-2021-31805 | Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation. | CRITICAL 9.8EPSS 85.4% | 12 April 2022 |
| CVE-2022-24248 | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. | MEDIUM 6.5EPSS 21.0% | 12 April 2022 |
| CVE-2022-23450 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). | CRITICAL 9.8EPSS 35.7% | 12 April 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.