Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 75 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-25094 | Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php. | HIGH 8.8EPSS 23.3% | 26 February 2022 |
| CVE-2022-25064 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. | CRITICAL 9.8EPSS 36.5% | 25 February 2022 |
| CVE-2022-25061 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | CRITICAL 9.8EPSS 58.7% | 25 February 2022 |
| CVE-2022-25060 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. | CRITICAL 9.8EPSS 40.2% | 25 February 2022 |
| CVE-2022-24288 | In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI. | HIGH 8.8EPSS 77.9% | 25 February 2022 |
| CVE-2021-44664 | An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload… | HIGH 8.8EPSS 12.8% | 24 February 2022 |
| CVE-2022-25305 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts… | MEDIUM 6.1EPSS 78.9% | 24 February 2022 |
| CVE-2022-25149 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject… | HIGH 7.5EPSS 77.5% | 24 February 2022 |
| CVE-2022-25148 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication… | CRITICAL 9.8EPSS 80.9% | 24 February 2022 |
| CVE-2022-21824 | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which… | HIGH 8.2EPSS 21.5% | 24 February 2022 |
| CVE-2022-0651 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without… | HIGH 7.5EPSS 32.2% | 24 February 2022 |
| CVE-2021-44532 | The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic… | MEDIUM 5.3EPSS 10.4% | 24 February 2022 |
| CVE-2022-25414 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. | CRITICAL 9.8EPSS 10.4% | 24 February 2022 |
| CVE-2022-25084 | TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. | CRITICAL 9.8EPSS 24.8% | 24 February 2022 |
| CVE-2022-25082 | TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. | CRITICAL 9.8EPSS 15.7% | 24 February 2022 |
| CVE-2022-25077 | TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. | CRITICAL 9.8EPSS 32.6% | 24 February 2022 |
| CVE-2022-25075 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. | CRITICAL 9.8EPSS 56.2% | 24 February 2022 |
| CVE-2022-25074 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). | CRITICAL 9.8EPSS 13.0% | 24 February 2022 |
| CVE-2022-25073 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). | CRITICAL 9.8EPSS 13.0% | 24 February 2022 |
| CVE-2022-25072 | TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). | CRITICAL 9.8EPSS 13.0% | 24 February 2022 |
| CVE-2022-23176 | WatchGuard Firebox and XTM Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 12.7% | 24 February 2022 |
| CVE-2021-44967 | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. | HIGH 8.8EPSS 13.5% | 24 February 2022 |
| CVE-2021-44567 | An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. | CRITICAL 9.8EPSS 23.1% | 24 February 2022 |
| CVE-2020-27467 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. | HIGH 7.5EPSS 15.7% | 24 February 2022 |
| CVE-2022-20650 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. | HIGH 8.8EPSS 14.5% | 23 February 2022 |
| CVE-2022-20624 | A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. | HIGH 7.5EPSS 12.4% | 23 February 2022 |
| CVE-2022-20623 | A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. | HIGH 7.5EPSS 11.9% | 23 February 2022 |
| CVE-2022-0714 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. | MEDIUM 5.5EPSS 12.7% | 22 February 2022 |
| CVE-2022-24295 | Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL. | HIGH 8.8EPSS 16.6% | 21 February 2022 |
| CVE-2021-44142 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit… | HIGH 8.8EPSS 73.9% | 21 February 2022 |
| CVE-2021-24867 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. | CRITICAL 9.8EPSS 18.9% | 21 February 2022 |
| CVE-2022-23375 | WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. | HIGH 8.8EPSS 19.9% | 19 February 2022 |
| CVE-2022-23642 | Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. | HIGH 8.8EPSS 74.3% | 18 February 2022 |
| CVE-2022-0543 | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | KEVCRITICAL 10.0EPSS 99.4% | 18 February 2022 |
| CVE-2022-0666 | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11. | HIGH 7.5EPSS 44.3% | 18 February 2022 |
| CVE-2022-22916 | O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. | CRITICAL 9.8EPSS 38.7% | 17 February 2022 |
| CVE-2021-46314 | A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging… | CRITICAL 9.8EPSS 33.3% | 17 February 2022 |
| CVE-2021-45382 | D-Link Multiple Routers Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.8% | 17 February 2022 |
| CVE-2021-3781 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. | CRITICAL 9.9EPSS 83.9% | 16 February 2022 |
| CVE-2021-3560 | Red Hat Polkit Incorrect Authorization Vulnerability | KEVHIGH 7.8EPSS 23.7% | 16 February 2022 |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 16 February 2022 |
| CVE-2022-0513 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without… | HIGH 7.5EPSS 53.5% | 16 February 2022 |
| CVE-2022-25236 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | CRITICAL 9.8EPSS 35.9% | 16 February 2022 |
| CVE-2021-35380 | A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to… | HIGH 7.5EPSS 39.0% | 15 February 2022 |
| CVE-2021-43734 | kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host. | HIGH 7.5EPSS 10.7% | 15 February 2022 |
| CVE-2022-23389 | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. | CRITICAL 9.8EPSS 22.0% | 14 February 2022 |
| CVE-2021-45392 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service. | HIGH 7.5EPSS 12.3% | 14 February 2022 |
| CVE-2021-45420 | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. | CRITICAL 9.8EPSS 17.5% | 14 February 2022 |
| CVE-2022-0572 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | HIGH 7.8EPSS 26.5% | 14 February 2022 |
| CVE-2022-0306 | Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 85.4% | 12 February 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.