Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,890 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 73 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-22274 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall. | CRITICAL 9.8EPSS 75.5% | 25 March 2022 |
| CVE-2022-0435 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. | HIGH 8.8EPSS 68.0% | 25 March 2022 |
| CVE-2021-20323 | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. | MEDIUM 6.1EPSS 37.2% | 25 March 2022 |
| CVE-2022-26263 | Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. | MEDIUM 6.1EPSS 41.7% | 25 March 2022 |
| CVE-2022-1040 | Sophos Firewall Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 25 March 2022 |
| CVE-2018-25032 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | HIGH 7.5EPSS 51.7% | 25 March 2022 |
| CVE-2022-26272 | A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php. | CRITICAL 9.8EPSS 22.5% | 24 March 2022 |
| CVE-2022-21820 | NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both… | MEDIUM 6.3EPSS 16.5% | 24 March 2022 |
| CVE-2022-1058 | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | MEDIUM 6.1EPSS 53.2% | 24 March 2022 |
| CVE-2022-24934 | wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry. | CRITICAL 9.8EPSS 20.5% | 23 March 2022 |
| CVE-2022-23881 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | CRITICAL 9.8EPSS 56.5% | 23 March 2022 |
| CVE-2022-22951 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. | CRITICAL 9.1EPSS 20.3% | 23 March 2022 |
| CVE-2022-0888 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for… | CRITICAL 9.8EPSS 39.4% | 23 March 2022 |
| CVE-2022-26187 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function. | CRITICAL 9.8EPSS 19.6% | 22 March 2022 |
| CVE-2022-27228 | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | CRITICAL 9.8EPSS 20.8% | 22 March 2022 |
| CVE-2022-26148 | When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address. | CRITICAL 9.8EPSS 53.4% | 21 March 2022 |
| CVE-2022-23347 | BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. | HIGH 7.5EPSS 13.5% | 21 March 2022 |
| CVE-2022-0760 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an… | CRITICAL 9.8EPSS 10.8% | 21 March 2022 |
| CVE-2022-0747 | The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an… | CRITICAL 9.8EPSS 14.9% | 21 March 2022 |
| CVE-2022-0739 | The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated… | CRITICAL 9.8EPSS 37.2% | 21 March 2022 |
| CVE-2022-0591 | The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users | CRITICAL 9.1EPSS 20.2% | 21 March 2022 |
| CVE-2022-0364 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | MEDIUM 5.4EPSS 69.6% | 21 March 2022 |
| CVE-2022-25766 | The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. | HIGH 8.8EPSS 34.3% | 21 March 2022 |
| CVE-2022-24237 | The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. | HIGH 8.8EPSS 25.3% | 21 March 2022 |
| CVE-2022-26960 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. | CRITICAL 9.1EPSS 51.0% | 21 March 2022 |
| CVE-2022-0415 | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. | HIGH 8.8EPSS 65.2% | 21 March 2022 |
| CVE-2022-27226 | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. | HIGH 8.8EPSS 33.7% | 19 March 2022 |
| CVE-2022-26265 | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | CRITICAL 9.8EPSS 30.4% | 18 March 2022 |
| CVE-2022-25450 | Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. | CRITICAL 9.8EPSS 11.6% | 18 March 2022 |
| CVE-2022-22620 | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 16.3% | 18 March 2022 |
| CVE-2022-22587 | Apple Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 11.6% | 18 March 2022 |
| CVE-2022-24637 | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. | CRITICAL 9.8EPSS 99.1% | 18 March 2022 |
| CVE-2022-26965 | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. | HIGH 7.2EPSS 36.3% | 18 March 2022 |
| CVE-2021-45968 | An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394. | HIGH 7.5EPSS 10.4% | 18 March 2022 |
| CVE-2021-45967 | A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. | CRITICAL 9.8EPSS 20.8% | 18 March 2022 |
| CVE-2021-44261 | A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. | MEDIUM 5.3EPSS 20.3% | 17 March 2022 |
| CVE-2022-0811 | This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed. | HIGH 8.8EPSS 19.0% | 16 March 2022 |
| CVE-2021-41987 | In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. | HIGH 8.1EPSS 16.2% | 16 March 2022 |
| CVE-2022-26213 | Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. | CRITICAL 9.8EPSS 25.6% | 15 March 2022 |
| CVE-2022-25487 | Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. | CRITICAL 9.8EPSS 53.8% | 15 March 2022 |
| CVE-2022-0778 | Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. | HIGH 7.5EPSS 73.2% | 15 March 2022 |
| CVE-2021-45010 | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution. | HIGH 8.8EPSS 70.1% | 15 March 2022 |
| CVE-2022-0169 | The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated… | CRITICAL 9.8EPSS 74.6% | 14 March 2022 |
| CVE-2021-25003 | The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE | CRITICAL 9.8EPSS 56.1% | 14 March 2022 |
| CVE-2022-23943 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. | CRITICAL 9.8EPSS 50.4% | 14 March 2022 |
| CVE-2022-22721 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. | CRITICAL 9.1EPSS 41.9% | 14 March 2022 |
| CVE-2022-22720 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | CRITICAL 9.8EPSS 28.2% | 14 March 2022 |
| CVE-2022-22719 | A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. | HIGH 7.5EPSS 69.8% | 14 March 2022 |
| CVE-2022-24760 | In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. | CRITICAL 10.0EPSS 49.1% | 12 March 2022 |
| CVE-2022-25216 | An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to… | HIGH 7.5EPSS 13.5% | 11 March 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.