SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,890 CVEs1,713 in CISA KEV17,380 with EPSS ≥ 10%Updated 17 September 2026

17,380 results · page 71 of 348

CVESummaryPriorityPublished
CVE-2022-1390The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte…CRITICAL 9.8EPSS 21.9%25 April 2022
CVE-2021-25094By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.HIGH 8.1EPSS 83.4%25 April 2022
CVE-2022-29078The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName].CRITICAL 9.8EPSS 32.8%25 April 2022
CVE-2021-45837It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.CRITICAL 9.8EPSS 16.0%25 April 2022
CVE-2022-1429SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6.HIGH 7.5EPSS 63.9%22 April 2022
CVE-2022-28021Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.CRITICAL 9.8EPSS 24.3%21 April 2022
CVE-2022-27478Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.HIGH 8.8EPSS 20.0%21 April 2022
CVE-2022-29548A reflected XSS issue exists in the Management Console of several WSO2 products.MEDIUM 6.1EPSS 41.1%21 April 2022
CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 17.6%21 April 2022
CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityKEVHIGH 7.2EPSS 98.7%21 April 2022
CVE-2022-27924Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityKEVHIGH 7.5EPSS 85.4%21 April 2022
CVE-2022-26133SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated…CRITICAL 9.8EPSS 70.4%20 April 2022
CVE-2022-0540A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request.CRITICAL 9.8EPSS 88.1%20 April 2022
CVE-2022-21490Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).MEDIUM 6.3EPSS 78.7%19 April 2022
CVE-2022-21489Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).MEDIUM 6.3EPSS 78.9%19 April 2022
CVE-2022-21449Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).HIGH 7.5EPSS 60.3%19 April 2022
CVE-2022-21445Oracle ADF Faces Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 62.5%19 April 2022
CVE-2022-1329The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site…HIGH 8.8EPSS 92.7%19 April 2022
CVE-2022-1119The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file…HIGH 7.5EPSS 20.0%19 April 2022
CVE-2022-27927A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database.CRITICAL 9.8EPSS 13.8%19 April 2022
CVE-2022-28108Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.HIGH 8.8EPSS 11.7%19 April 2022
CVE-2022-29464WSO2 Multiple Products Unrestrictive Upload of File VulnerabilityKEVCRITICAL 9.8EPSS 100.0%18 April 2022
CVE-2022-1020The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does…CRITICAL 9.8EPSS 25.9%18 April 2022
CVE-2022-0661The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading…HIGH 7.2EPSS 40.2%18 April 2022
CVE-2022-25226ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication.CRITICAL 10.0EPSS 11.0%18 April 2022
CVE-2022-28810Zoho ManageEngine ADSelfService Plus Remote Code Execution VulnerabilityKEVMEDIUM 6.8EPSS 71.0%18 April 2022
CVE-2022-27908Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.HIGH 8.8EPSS 36.5%18 April 2022
CVE-2022-26809Remote Procedure Call Runtime Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 91.0%15 April 2022
CVE-2022-24500Windows SMB Remote Code Execution VulnerabilityHIGH 8.8EPSS 38.0%15 April 2022
CVE-2022-24497Windows Network File System Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 34.6%15 April 2022
CVE-2022-24491Windows Network File System Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 33.5%15 April 2022
CVE-2022-24481Windows Common Log File System Driver Elevation of Privilege VulnerabilityHIGH 7.8EPSS 16.6%15 April 2022
CVE-2022-20695A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This…CRITICAL 10.0EPSS 19.8%15 April 2022
CVE-2022-27474SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.HIGH 7.2EPSS 23.1%15 April 2022
CVE-2022-26498An issue was discovered in Asterisk through 19.x.HIGH 7.5EPSS 16.7%15 April 2022
CVE-2022-22149A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.HIGH 8.8EPSS 72.6%14 April 2022
CVE-2022-21234An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2.HIGH 8.8EPSS 72.6%14 April 2022
CVE-2022-21210An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.HIGH 8.8EPSS 71.2%14 April 2022
CVE-2022-21145A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2.MEDIUM 4.8EPSS 77.8%14 April 2022
CVE-2021-43287The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.HIGH 7.5EPSS 28.0%14 April 2022
CVE-2022-24816OSGeo GeoServer JAI-EXT Code Injection VulnerabilityKEVCRITICAL 10.0EPSS 98.5%13 April 2022
CVE-2022-22960VMware Multiple Products Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 35.8%13 April 2022
CVE-2022-22957VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958).HIGH 7.2EPSS 23.9%13 April 2022
CVE-2022-22956VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework.CRITICAL 9.8EPSS 49.8%13 April 2022
CVE-2021-22797A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation…HIGH 7.8EPSS 26.1%13 April 2022
CVE-2022-29036Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a…MEDIUM 5.4EPSS 79.0%12 April 2022
CVE-2022-28213When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the…HIGH 8.1EPSS 12.5%12 April 2022
CVE-2021-31805Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.CRITICAL 9.8EPSS 85.4%12 April 2022
CVE-2022-24248RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.MEDIUM 6.5EPSS 21.0%12 April 2022
CVE-2022-23450A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1).CRITICAL 9.8EPSS 35.7%12 April 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.