SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 74 of 348

CVESummaryPriorityPublished
CVE-2018-25031Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.MEDIUM 4.3EPSS 42.3%11 March 2022
CVE-2022-26143MiCollab, MiVoice Business Express Access Control VulnerabilityKEVCRITICAL 9.8EPSS 87.2%10 March 2022
CVE-2022-25546Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS.HIGH 7.5EPSS 12.3%10 March 2022
CVE-2022-25090Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.HIGH 8.1EPSS 11.1%10 March 2022
CVE-2022-24995Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime.CRITICAL 9.8EPSS 13.6%10 March 2022
CVE-2022-23940SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution.HIGH 8.8EPSS 53.2%10 March 2022
CVE-2022-22835An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.MEDIUM 6.5EPSS 14.5%10 March 2022
CVE-2022-0847Linux Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 89.7%10 March 2022
CVE-2021-4045TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root.CRITICAL 9.8EPSS 72.4%10 March 2022
CVE-2022-24734In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages.HIGH 7.2EPSS 77.8%9 March 2022
CVE-2022-22806A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent.CRITICAL 9.8EPSS 12.5%9 March 2022
CVE-2022-22805A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled.CRITICAL 9.8EPSS 11.9%9 March 2022
CVE-2022-24502Windows HTML Platforms Security Feature Bypass VulnerabilityMEDIUM 4.3EPSS 33.1%9 March 2022
CVE-2022-24463Microsoft Exchange Server Spoofing VulnerabilityMEDIUM 6.5EPSS 31.8%9 March 2022
CVE-2022-23285Remote Desktop Client Remote Code Execution VulnerabilityHIGH 8.8EPSS 25.6%9 March 2022
CVE-2022-23277Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 42.0%9 March 2022
CVE-2022-23253Windows Point-to-Point Tunneling Protocol Denial of Service VulnerabilityMEDIUM 6.5EPSS 56.4%9 March 2022
CVE-2022-21990Remote Desktop Client Remote Code Execution VulnerabilityHIGH 8.8EPSS 18.8%9 March 2022
CVE-2022-0482Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.CRITICAL 9.1EPSS 43.7%9 March 2022
CVE-2022-24716Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials.HIGH 7.5EPSS 89.4%8 March 2022
CVE-2022-24715Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code.HIGH 8.8EPSS 14.7%8 March 2022
CVE-2022-24713The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes.HIGH 7.5EPSS 14.5%8 March 2022
CVE-2022-0441The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an adminCRITICAL 9.8EPSS 85.3%7 March 2022
CVE-2022-0434As a result, unauthenticated attackers could perform SQL injection attacksCRITICAL 9.8EPSS 14.8%7 March 2022
CVE-2022-0349The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL InjectionCRITICAL 9.8EPSS 34.4%7 March 2022
CVE-2021-46704In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts).CRITICAL 9.8EPSS 21.9%6 March 2022
CVE-2021-44827There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root…HIGH 8.8EPSS 54.0%4 March 2022
CVE-2021-3737An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time.HIGH 7.5EPSS 11.6%4 March 2022
CVE-2022-26318WatchGuard Firebox and XTM Appliances Arbitrary Code ExecutionKEVCRITICAL 9.8EPSS 78.2%4 March 2022
CVE-2021-46381Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].HIGH 7.5EPSS 58.9%4 March 2022
CVE-2021-46379DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.MEDIUM 6.1EPSS 15.8%4 March 2022
CVE-2021-46378DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.HIGH 7.5EPSS 31.9%4 March 2022
CVE-2022-0832Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.MEDIUM 5.4EPSS 66.6%4 March 2022
CVE-2021-46393There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN.CRITICAL 9.8EPSS 15.9%4 March 2022
CVE-2022-0848OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.CRITICAL 9.8EPSS 35.4%4 March 2022
CVE-2022-22947VMware Spring Cloud Gateway Code Injection VulnerabilityKEVCRITICAL 10.0EPSS 98.3%3 March 2022
CVE-2022-23648A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files…HIGH 7.5EPSS 27.4%3 March 2022
CVE-2022-25089Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.CRITICAL 9.8EPSS 18.4%3 March 2022
CVE-2022-22909HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.HIGH 8.8EPSS 45.4%3 March 2022
CVE-2021-3654A vulnerability was found in openstack-nova's console proxy, noVNC.MEDIUM 6.1EPSS 26.8%2 March 2022
CVE-2022-0711This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition.HIGH 7.5EPSS 16.6%2 March 2022
CVE-2022-0819Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.HIGH 8.8EPSS 41.0%2 March 2022
CVE-2022-23779Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone.MEDIUM 5.3EPSS 15.1%2 March 2022
CVE-2022-0824Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.HIGH 8.8EPSS 97.0%2 March 2022
CVE-2021-41282diag_routes.php in pfSense 2.5.2 allows sed data injection.HIGH 8.8EPSS 87.1%1 March 2022
CVE-2021-46387ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS).MEDIUM 6.1EPSS 21.0%1 March 2022
CVE-2021-4039A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.CRITICAL 9.8EPSS 71.0%1 March 2022
CVE-2022-0412The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint,…CRITICAL 9.8EPSS 74.0%28 February 2022
CVE-2022-26159The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters…MEDIUM 5.3EPSS 13.4%28 February 2022
CVE-2022-25359On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.CRITICAL 9.1EPSS 37.3%26 February 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.