Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,890 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 72 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-31805 | Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation. | CRITICAL 9.8EPSS 85.4% | 12 April 2022 |
| CVE-2022-24248 | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. | MEDIUM 6.5EPSS 21.0% | 12 April 2022 |
| CVE-2022-23450 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). | CRITICAL 9.8EPSS 35.7% | 12 April 2022 |
| CVE-2022-28346 | QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs. | CRITICAL 9.8EPSS 18.7% | 12 April 2022 |
| CVE-2022-24838 | SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:<BOOKING USER'S EMAIL> ` SMTP… | CRITICAL 9.8EPSS 33.0% | 11 April 2022 |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 11 April 2022 |
| CVE-2022-27115 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | CRITICAL 9.8EPSS 28.6% | 11 April 2022 |
| CVE-2021-46367 | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. | HIGH 7.2EPSS 29.7% | 8 April 2022 |
| CVE-2021-43421 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code. | CRITICAL 9.8EPSS 42.8% | 7 April 2022 |
| CVE-2021-46419 | An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts. | CRITICAL 9.1EPSS 71.4% | 7 April 2022 |
| CVE-2021-46418 | An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts. | HIGH 7.5EPSS 23.9% | 7 April 2022 |
| CVE-2021-46417 | Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580. | HIGH 7.5EPSS 59.8% | 7 April 2022 |
| CVE-2021-30497 | Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. | HIGH 7.5EPSS 96.6% | 6 April 2022 |
| CVE-2022-28219 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | CRITICAL 9.8EPSS 97.2% | 5 April 2022 |
| CVE-2022-26635 | PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. | CRITICAL 9.8EPSS 21.4% | 5 April 2022 |
| CVE-2021-43008 | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database. | HIGH 7.5EPSS 13.6% | 5 April 2022 |
| CVE-2022-0609 | Google Chromium Animation Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 22.9% | 5 April 2022 |
| CVE-2022-1190 | Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc. | MEDIUM 5.4EPSS 87.4% | 4 April 2022 |
| CVE-2022-1175 | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes. | MEDIUM 6.1EPSS 82.0% | 4 April 2022 |
| CVE-2022-1162 | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. | CRITICAL 9.8EPSS 76.2% | 4 April 2022 |
| CVE-2022-24785 | A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. | HIGH 7.5EPSS 13.9% | 4 April 2022 |
| CVE-2022-1026 | Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function. | HIGH 8.6EPSS 14.7% | 4 April 2022 |
| CVE-2021-44138 | There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request. | HIGH 7.5EPSS 12.3% | 4 April 2022 |
| CVE-2022-26233 | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. | HIGH 7.5EPSS 15.0% | 3 April 2022 |
| CVE-2022-28381 | Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932. | CRITICAL 9.8EPSS 70.4% | 3 April 2022 |
| CVE-2022-28379 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. | MEDIUM 4.8EPSS 71.2% | 3 April 2022 |
| CVE-2022-28368 | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file). | CRITICAL 9.8EPSS 82.4% | 3 April 2022 |
| CVE-2022-22965 | Spring Framework JDK 9+ Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 1 April 2022 |
| CVE-2022-22963 | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 1 April 2022 |
| CVE-2022-22950 | n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. | MEDIUM 6.5EPSS 36.1% | 1 April 2022 |
| CVE-2022-25017 | Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. | HIGH 8.8EPSS 29.1% | 1 April 2022 |
| CVE-2021-46009 | In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. | CRITICAL 9.8EPSS 12.5% | 30 March 2022 |
| CVE-2022-1181 | Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2. | MEDIUM 5.4EPSS 51.5% | 30 March 2022 |
| CVE-2022-1179 | Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | MEDIUM 5.4EPSS 76.9% | 30 March 2022 |
| CVE-2022-1178 | Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | MEDIUM 5.4EPSS 51.6% | 30 March 2022 |
| CVE-2022-26871 | Trend Micro Apex Central Arbitrary File Upload Vulnerability | KEVCRITICAL 9.8EPSS 19.6% | 29 March 2022 |
| CVE-2021-43118 | A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote… | CRITICAL 9.8EPSS 34.8% | 29 March 2022 |
| CVE-2022-22948 | VMware vCenter Server Incorrect Default File Permissions Vulnerability | KEVMEDIUM 6.5EPSS 13.3% | 29 March 2022 |
| CVE-2022-25347 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system. | HIGH 7.5EPSS 11.4% | 29 March 2022 |
| CVE-2022-0735 | An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands. | CRITICAL 9.8EPSS 13.2% | 28 March 2022 |
| CVE-2021-4191 | Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API. | MEDIUM 5.3EPSS 80.0% | 28 March 2022 |
| CVE-2022-0784 | The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | CRITICAL 9.8EPSS 10.1% | 28 March 2022 |
| CVE-2022-0679 | The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and… | CRITICAL 9.8EPSS 47.8% | 28 March 2022 |
| CVE-2022-0595 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue | MEDIUM 5.4EPSS 13.6% | 28 March 2022 |
| CVE-2022-0479 | The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to… | CRITICAL 9.8EPSS 43.8% | 28 March 2022 |
| CVE-2022-0342 | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions… | CRITICAL 9.8EPSS 94.9% | 28 March 2022 |
| CVE-2021-26599 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | CRITICAL 9.8EPSS 21.0% | 28 March 2022 |
| CVE-2021-26598 | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token). | MEDIUM 5.3EPSS 10.5% | 28 March 2022 |
| CVE-2022-26258 | D-Link DIR-820L Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 92.0% | 28 March 2022 |
| CVE-2022-26245 | Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. | CRITICAL 9.8EPSS 14.8% | 27 March 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.