SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 75 of 348

CVESummaryPriorityPublished
CVE-2022-25094Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.HIGH 8.8EPSS 23.3%26 February 2022
CVE-2022-25064TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.CRITICAL 9.8EPSS 36.5%25 February 2022
CVE-2022-25061TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.CRITICAL 9.8EPSS 58.7%25 February 2022
CVE-2022-25060TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.CRITICAL 9.8EPSS 40.2%25 February 2022
CVE-2022-24288In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.HIGH 8.8EPSS 77.9%25 February 2022
CVE-2021-44664An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload…HIGH 8.8EPSS 12.8%24 February 2022
CVE-2022-25305The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts…MEDIUM 6.1EPSS 78.9%24 February 2022
CVE-2022-25149The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject…HIGH 7.5EPSS 77.5%24 February 2022
CVE-2022-25148The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication…CRITICAL 9.8EPSS 80.9%24 February 2022
CVE-2022-21824Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which…HIGH 8.2EPSS 21.5%24 February 2022
CVE-2022-0651The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without…HIGH 7.5EPSS 32.2%24 February 2022
CVE-2021-44532The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic…MEDIUM 5.3EPSS 10.4%24 February 2022
CVE-2022-25414Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.CRITICAL 9.8EPSS 10.4%24 February 2022
CVE-2022-25084TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function.CRITICAL 9.8EPSS 24.8%24 February 2022
CVE-2022-25082TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function.CRITICAL 9.8EPSS 15.7%24 February 2022
CVE-2022-25077TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function.CRITICAL 9.8EPSS 32.6%24 February 2022
CVE-2022-25075TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function.CRITICAL 9.8EPSS 56.2%24 February 2022
CVE-2022-25074TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr().CRITICAL 9.8EPSS 13.0%24 February 2022
CVE-2022-25073TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr().CRITICAL 9.8EPSS 13.0%24 February 2022
CVE-2022-25072TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr().CRITICAL 9.8EPSS 13.0%24 February 2022
CVE-2022-23176WatchGuard Firebox and XTM Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 12.7%24 February 2022
CVE-2021-44967A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.HIGH 8.8EPSS 13.5%24 February 2022
CVE-2021-44567An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.CRITICAL 9.8EPSS 23.1%24 February 2022
CVE-2020-27467A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.HIGH 7.5EPSS 15.7%24 February 2022
CVE-2022-20650A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.HIGH 8.8EPSS 14.5%23 February 2022
CVE-2022-20624A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.HIGH 7.5EPSS 12.4%23 February 2022
CVE-2022-20623A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device.HIGH 7.5EPSS 11.9%23 February 2022
CVE-2022-0714Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.MEDIUM 5.5EPSS 12.7%22 February 2022
CVE-2022-24295Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.HIGH 8.8EPSS 16.6%21 February 2022
CVE-2021-44142The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit…HIGH 8.8EPSS 73.9%21 February 2022
CVE-2021-24867Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised.CRITICAL 9.8EPSS 18.9%21 February 2022
CVE-2022-23375WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability.HIGH 8.8EPSS 19.9%19 February 2022
CVE-2022-23642Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service.HIGH 8.8EPSS 74.3%18 February 2022
CVE-2022-0543Debian-specific Redis Server Lua Sandbox Escape VulnerabilityKEVCRITICAL 10.0EPSS 99.4%18 February 2022
CVE-2022-0666CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.HIGH 7.5EPSS 44.3%18 February 2022
CVE-2022-22916O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.CRITICAL 9.8EPSS 38.7%17 February 2022
CVE-2021-46314A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging…CRITICAL 9.8EPSS 33.3%17 February 2022
CVE-2021-45382D-Link Multiple Routers Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.8%17 February 2022
CVE-2021-3781A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command.CRITICAL 9.9EPSS 83.9%16 February 2022
CVE-2021-3560Red Hat Polkit Incorrect Authorization VulnerabilityKEVHIGH 7.8EPSS 23.7%16 February 2022
CVE-2022-24086Adobe Commerce and Magento Open Source Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 99.2%16 February 2022
CVE-2022-0513The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without…HIGH 7.5EPSS 53.5%16 February 2022
CVE-2022-25236xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.CRITICAL 9.8EPSS 35.9%16 February 2022
CVE-2021-35380A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to…HIGH 7.5EPSS 39.0%15 February 2022
CVE-2021-43734kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.HIGH 7.5EPSS 10.7%15 February 2022
CVE-2022-23389PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.CRITICAL 9.8EPSS 22.0%14 February 2022
CVE-2021-45392A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.HIGH 7.5EPSS 12.3%14 February 2022
CVE-2021-45420Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi.CRITICAL 9.8EPSS 17.5%14 February 2022
CVE-2022-0572Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.HIGH 7.8EPSS 26.5%14 February 2022
CVE-2022-0306Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 85.4%12 February 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.