SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,890 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 72 of 348

CVESummaryPriorityPublished
CVE-2021-31805Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.CRITICAL 9.8EPSS 85.4%12 April 2022
CVE-2022-24248RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel.MEDIUM 6.5EPSS 21.0%12 April 2022
CVE-2022-23450A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1).CRITICAL 9.8EPSS 35.7%12 April 2022
CVE-2022-28346QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.CRITICAL 9.8EPSS 18.7%12 April 2022
CVE-2022-24838SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:<BOOKING USER'S EMAIL> ` SMTP…CRITICAL 9.8EPSS 33.0%11 April 2022
CVE-2022-22954VMware Workspace ONE Access and Identity Manager Server-Side Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%11 April 2022
CVE-2022-27115In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.CRITICAL 9.8EPSS 28.6%11 April 2022
CVE-2021-46367RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.HIGH 7.2EPSS 29.7%8 April 2022
CVE-2021-43421A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.CRITICAL 9.8EPSS 42.8%7 April 2022
CVE-2021-46419An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.CRITICAL 9.1EPSS 71.4%7 April 2022
CVE-2021-46418An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.HIGH 7.5EPSS 23.9%7 April 2022
CVE-2021-46417Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.HIGH 7.5EPSS 59.8%7 April 2022
CVE-2021-30497Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal.HIGH 7.5EPSS 96.6%6 April 2022
CVE-2022-28219Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.CRITICAL 9.8EPSS 97.2%5 April 2022
CVE-2022-26635PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection.CRITICAL 9.8EPSS 21.4%5 April 2022
CVE-2021-43008Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.HIGH 7.5EPSS 13.6%5 April 2022
CVE-2022-0609Google Chromium Animation Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 22.9%5 April 2022
CVE-2022-1190Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.MEDIUM 5.4EPSS 87.4%4 April 2022
CVE-2022-1175Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.MEDIUM 6.1EPSS 82.0%4 April 2022
CVE-2022-1162A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.CRITICAL 9.8EPSS 76.2%4 April 2022
CVE-2022-24785A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale.HIGH 7.5EPSS 13.9%4 April 2022
CVE-2022-1026Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.HIGH 8.6EPSS 14.7%4 April 2022
CVE-2021-44138There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.HIGH 7.5EPSS 12.3%4 April 2022
CVE-2022-26233Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components.HIGH 7.5EPSS 15.0%3 April 2022
CVE-2022-28381Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.CRITICAL 9.8EPSS 70.4%3 April 2022
CVE-2022-28379jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.MEDIUM 4.8EPSS 71.2%3 April 2022
CVE-2022-28368Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).CRITICAL 9.8EPSS 82.4%3 April 2022
CVE-2022-22965Spring Framework JDK 9+ Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.6%1 April 2022
CVE-2022-22963VMware Tanzu Spring Cloud Function Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%1 April 2022
CVE-2022-22950n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.MEDIUM 6.5EPSS 36.1%1 April 2022
CVE-2022-25017Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.HIGH 8.8EPSS 29.1%1 April 2022
CVE-2021-46009In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication.CRITICAL 9.8EPSS 12.5%30 March 2022
CVE-2022-1181Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.MEDIUM 5.4EPSS 51.5%30 March 2022
CVE-2022-1179Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.MEDIUM 5.4EPSS 76.9%30 March 2022
CVE-2022-1178Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.MEDIUM 5.4EPSS 51.6%30 March 2022
CVE-2022-26871Trend Micro Apex Central Arbitrary File Upload VulnerabilityKEVCRITICAL 9.8EPSS 19.6%29 March 2022
CVE-2021-43118A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote…CRITICAL 9.8EPSS 34.8%29 March 2022
CVE-2022-22948VMware vCenter Server Incorrect Default File Permissions Vulnerability KEVMEDIUM 6.5EPSS 13.3%29 March 2022
CVE-2022-25347Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.HIGH 7.5EPSS 11.4%29 March 2022
CVE-2022-0735An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.CRITICAL 9.8EPSS 13.2%28 March 2022
CVE-2021-4191Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.MEDIUM 5.3EPSS 80.0%28 March 2022
CVE-2022-0784The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injectionCRITICAL 9.8EPSS 10.1%28 March 2022
CVE-2022-0679The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and…CRITICAL 9.8EPSS 47.8%28 March 2022
CVE-2022-0595The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issueMEDIUM 5.4EPSS 13.6%28 March 2022
CVE-2022-0479The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to…CRITICAL 9.8EPSS 43.8%28 March 2022
CVE-2022-0342An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions…CRITICAL 9.8EPSS 94.9%28 March 2022
CVE-2021-26599ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.CRITICAL 9.8EPSS 21.0%28 March 2022
CVE-2021-26598ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).MEDIUM 5.3EPSS 10.5%28 March 2022
CVE-2022-26258D-Link DIR-820L Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 92.0%28 March 2022
CVE-2022-26245Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.CRITICAL 9.8EPSS 14.8%27 March 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.