SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,890 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 73 of 348

CVESummaryPriorityPublished
CVE-2022-22274A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.CRITICAL 9.8EPSS 75.5%25 March 2022
CVE-2022-0435A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed.HIGH 8.8EPSS 68.0%25 March 2022
CVE-2021-20323A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.MEDIUM 6.1EPSS 37.2%25 March 2022
CVE-2022-26263Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.MEDIUM 6.1EPSS 41.7%25 March 2022
CVE-2022-1040Sophos Firewall Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.8%25 March 2022
CVE-2018-25032zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.HIGH 7.5EPSS 51.7%25 March 2022
CVE-2022-26272A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.CRITICAL 9.8EPSS 22.5%24 March 2022
CVE-2022-21820NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both…MEDIUM 6.3EPSS 16.5%24 March 2022
CVE-2022-1058Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.MEDIUM 6.1EPSS 53.2%24 March 2022
CVE-2022-24934wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.CRITICAL 9.8EPSS 20.5%23 March 2022
CVE-2022-23881ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.CRITICAL 9.8EPSS 56.5%23 March 2022
CVE-2022-22951VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability.CRITICAL 9.1EPSS 20.3%23 March 2022
CVE-2022-0888The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for…CRITICAL 9.8EPSS 39.4%23 March 2022
CVE-2022-26187TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.CRITICAL 9.8EPSS 19.6%22 March 2022
CVE-2022-27228In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.CRITICAL 9.8EPSS 20.8%22 March 2022
CVE-2022-26148When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.CRITICAL 9.8EPSS 53.4%21 March 2022
CVE-2022-23347BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.HIGH 7.5EPSS 13.5%21 March 2022
CVE-2022-0760The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an…CRITICAL 9.8EPSS 10.8%21 March 2022
CVE-2022-0747The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an…CRITICAL 9.8EPSS 14.9%21 March 2022
CVE-2022-0739The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated…CRITICAL 9.8EPSS 37.2%21 March 2022
CVE-2022-0591The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated usersCRITICAL 9.1EPSS 20.2%21 March 2022
CVE-2022-0364The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacksMEDIUM 5.4EPSS 69.6%21 March 2022
CVE-2022-25766The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection.HIGH 8.8EPSS 34.3%21 March 2022
CVE-2022-24237The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability.HIGH 8.8EPSS 25.3%21 March 2022
CVE-2022-26960connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.CRITICAL 9.1EPSS 51.0%21 March 2022
CVE-2022-0415Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.HIGH 8.8EPSS 65.2%21 March 2022
CVE-2022-27226A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel.HIGH 8.8EPSS 33.7%19 March 2022
CVE-2022-26265Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.CRITICAL 9.8EPSS 30.4%18 March 2022
CVE-2022-25450Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.CRITICAL 9.8EPSS 11.6%18 March 2022
CVE-2022-22620Apple iOS, iPadOS, and macOS Webkit Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 16.3%18 March 2022
CVE-2022-22587Apple Memory Corruption VulnerabilityKEVCRITICAL 9.8EPSS 11.6%18 March 2022
CVE-2022-24637Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.CRITICAL 9.8EPSS 99.1%18 March 2022
CVE-2022-26965In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.HIGH 7.2EPSS 36.3%18 March 2022
CVE-2021-45968An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.HIGH 7.5EPSS 10.4%18 March 2022
CVE-2021-45967A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.CRITICAL 9.8EPSS 20.8%18 March 2022
CVE-2021-44261A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication.MEDIUM 5.3EPSS 20.3%17 March 2022
CVE-2022-0811This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.HIGH 8.8EPSS 19.0%16 March 2022
CVE-2021-41987In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution.HIGH 8.1EPSS 16.2%16 March 2022
CVE-2022-26213Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters.CRITICAL 9.8EPSS 25.6%15 March 2022
CVE-2022-25487Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.CRITICAL 9.8EPSS 53.8%15 March 2022
CVE-2022-0778Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack.HIGH 7.5EPSS 73.2%15 March 2022
CVE-2021-45010A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.HIGH 8.8EPSS 70.1%15 March 2022
CVE-2022-0169The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated…CRITICAL 9.8EPSS 74.6%14 March 2022
CVE-2021-25003The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCECRITICAL 9.8EPSS 56.1%14 March 2022
CVE-2022-23943Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data.CRITICAL 9.8EPSS 50.4%14 March 2022
CVE-2022-22721If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes.CRITICAL 9.1EPSS 41.9%14 March 2022
CVE-2022-22720Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request SmugglingCRITICAL 9.8EPSS 28.2%14 March 2022
CVE-2022-22719A carefully crafted request body can cause a read to a random memory area which could cause the process to crash.HIGH 7.5EPSS 69.8%14 March 2022
CVE-2022-24760In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server.CRITICAL 10.0EPSS 49.1%12 March 2022
CVE-2022-25216An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to…HIGH 7.5EPSS 13.5%11 March 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.