Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 74 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-25031 | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. | MEDIUM 4.3EPSS 42.3% | 11 March 2022 |
| CVE-2022-26143 | MiCollab, MiVoice Business Express Access Control Vulnerability | KEVCRITICAL 9.8EPSS 87.2% | 10 March 2022 |
| CVE-2022-25546 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. | HIGH 7.5EPSS 12.3% | 10 March 2022 |
| CVE-2022-25090 | Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition. | HIGH 8.1EPSS 11.1% | 10 March 2022 |
| CVE-2022-24995 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. | CRITICAL 9.8EPSS 13.6% | 10 March 2022 |
| CVE-2022-23940 | SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. | HIGH 8.8EPSS 53.2% | 10 March 2022 |
| CVE-2022-22835 | An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem. | MEDIUM 6.5EPSS 14.5% | 10 March 2022 |
| CVE-2022-0847 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 89.7% | 10 March 2022 |
| CVE-2021-4045 | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. | CRITICAL 9.8EPSS 72.4% | 10 March 2022 |
| CVE-2022-24734 | In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. | HIGH 7.2EPSS 77.8% | 9 March 2022 |
| CVE-2022-22806 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. | CRITICAL 9.8EPSS 12.5% | 9 March 2022 |
| CVE-2022-22805 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. | CRITICAL 9.8EPSS 11.9% | 9 March 2022 |
| CVE-2022-24502 | Windows HTML Platforms Security Feature Bypass Vulnerability | MEDIUM 4.3EPSS 33.1% | 9 March 2022 |
| CVE-2022-24463 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM 6.5EPSS 31.8% | 9 March 2022 |
| CVE-2022-23285 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH 8.8EPSS 25.6% | 9 March 2022 |
| CVE-2022-23277 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 42.0% | 9 March 2022 |
| CVE-2022-23253 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | MEDIUM 6.5EPSS 56.4% | 9 March 2022 |
| CVE-2022-21990 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH 8.8EPSS 18.8% | 9 March 2022 |
| CVE-2022-0482 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | CRITICAL 9.1EPSS 43.7% | 9 March 2022 |
| CVE-2022-24716 | Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. | HIGH 7.5EPSS 89.4% | 8 March 2022 |
| CVE-2022-24715 | Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. | HIGH 8.8EPSS 14.7% | 8 March 2022 |
| CVE-2022-24713 | The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. | HIGH 7.5EPSS 14.5% | 8 March 2022 |
| CVE-2022-0441 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | CRITICAL 9.8EPSS 85.3% | 7 March 2022 |
| CVE-2022-0434 | As a result, unauthenticated attackers could perform SQL injection attacks | CRITICAL 9.8EPSS 14.8% | 7 March 2022 |
| CVE-2022-0349 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection | CRITICAL 9.8EPSS 34.4% | 7 March 2022 |
| CVE-2021-46704 | In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). | CRITICAL 9.8EPSS 21.9% | 6 March 2022 |
| CVE-2021-44827 | There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root… | HIGH 8.8EPSS 54.0% | 4 March 2022 |
| CVE-2021-3737 | An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. | HIGH 7.5EPSS 11.6% | 4 March 2022 |
| CVE-2022-26318 | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution | KEVCRITICAL 9.8EPSS 78.2% | 4 March 2022 |
| CVE-2021-46381 | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | HIGH 7.5EPSS 58.9% | 4 March 2022 |
| CVE-2021-46379 | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. | MEDIUM 6.1EPSS 15.8% | 4 March 2022 |
| CVE-2021-46378 | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. | HIGH 7.5EPSS 31.9% | 4 March 2022 |
| CVE-2022-0832 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. | MEDIUM 5.4EPSS 66.6% | 4 March 2022 |
| CVE-2021-46393 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. | CRITICAL 9.8EPSS 15.9% | 4 March 2022 |
| CVE-2022-0848 | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | CRITICAL 9.8EPSS 35.4% | 4 March 2022 |
| CVE-2022-22947 | VMware Spring Cloud Gateway Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 98.3% | 3 March 2022 |
| CVE-2022-23648 | A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files… | HIGH 7.5EPSS 27.4% | 3 March 2022 |
| CVE-2022-25089 | Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData. | CRITICAL 9.8EPSS 18.4% | 3 March 2022 |
| CVE-2022-22909 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module. | HIGH 8.8EPSS 45.4% | 3 March 2022 |
| CVE-2021-3654 | A vulnerability was found in openstack-nova's console proxy, noVNC. | MEDIUM 6.1EPSS 26.8% | 2 March 2022 |
| CVE-2022-0711 | This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. | HIGH 7.5EPSS 16.6% | 2 March 2022 |
| CVE-2022-0819 | Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1. | HIGH 8.8EPSS 41.0% | 2 March 2022 |
| CVE-2022-23779 | Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. | MEDIUM 5.3EPSS 15.1% | 2 March 2022 |
| CVE-2022-0824 | Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. | HIGH 8.8EPSS 97.0% | 2 March 2022 |
| CVE-2021-41282 | diag_routes.php in pfSense 2.5.2 allows sed data injection. | HIGH 8.8EPSS 87.1% | 1 March 2022 |
| CVE-2021-46387 | ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). | MEDIUM 6.1EPSS 21.0% | 1 March 2022 |
| CVE-2021-4039 | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device. | CRITICAL 9.8EPSS 71.0% | 1 March 2022 |
| CVE-2022-0412 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint,… | CRITICAL 9.8EPSS 74.0% | 28 February 2022 |
| CVE-2022-26159 | The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters… | MEDIUM 5.3EPSS 13.4% | 28 February 2022 |
| CVE-2022-25359 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | CRITICAL 9.1EPSS 37.3% | 26 February 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.