Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 76 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-0289 | Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 27.7% | 12 February 2022 |
| CVE-2022-0185 | Linux Kernel Heap-Based Buffer Overflow Vulnerability | KEVHIGH 8.4EPSS 25.2% | 11 February 2022 |
| CVE-2021-31932 | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. | CRITICAL 9.8EPSS 21.6% | 11 February 2022 |
| CVE-2021-22824 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. | HIGH 7.5EPSS 14.2% | 11 February 2022 |
| CVE-2021-22823 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. | CRITICAL 9.1EPSS 21.4% | 11 February 2022 |
| CVE-2021-22802 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. | CRITICAL 9.8EPSS 20.2% | 11 February 2022 |
| CVE-2022-24112 | Apache APISIX Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 96.0% | 11 February 2022 |
| CVE-2021-44521 | When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the… | CRITICAL 9.1EPSS 55.0% | 11 February 2022 |
| CVE-2022-0557 | OS Command Injection in Packagist microweber/microweber prior to 1.2.11. | HIGH 7.2EPSS 51.2% | 11 February 2022 |
| CVE-2022-24954 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings. | CRITICAL 9.8EPSS 11.9% | 11 February 2022 |
| CVE-2022-20708 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVHIGH 8.0EPSS 14.9% | 10 February 2022 |
| CVE-2022-20707 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and… | HIGH 7.3EPSS 75.3% | 10 February 2022 |
| CVE-2022-20705 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and… | CRITICAL 9.8EPSS 80.0% | 10 February 2022 |
| CVE-2022-20699 | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 72.5% | 10 February 2022 |
| CVE-2021-45901 | The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists. | MEDIUM 5.3EPSS 14.3% | 10 February 2022 |
| CVE-2022-24315 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. | HIGH 7.5EPSS 19.3% | 9 February 2022 |
| CVE-2022-24314 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. | HIGH 7.5EPSS 18.2% | 9 February 2022 |
| CVE-2022-24313 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. | CRITICAL 9.8EPSS 44.6% | 9 February 2022 |
| CVE-2022-22536 | SAP Multiple Products HTTP Request Smuggling Vulnerability | KEVCRITICAL 10.0EPSS 97.9% | 9 February 2022 |
| CVE-2022-22718 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 18.5% | 9 February 2022 |
| CVE-2022-22715 | Named Pipe File System Elevation of Privilege Vulnerability | HIGH 7.8EPSS 12.6% | 9 February 2022 |
| CVE-2022-22005 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 16.4% | 9 February 2022 |
| CVE-2022-21999 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 41.7% | 9 February 2022 |
| CVE-2022-21993 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | HIGH 7.5EPSS 43.6% | 9 February 2022 |
| CVE-2022-21971 | Microsoft Windows Runtime Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 53.9% | 9 February 2022 |
| CVE-2021-46354 | Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. | HIGH 7.5EPSS 12.9% | 9 February 2022 |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 30.9% | 9 February 2022 |
| CVE-2021-44864 | TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. | MEDIUM 6.5EPSS 10.2% | 8 February 2022 |
| CVE-2021-25114 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | CRITICAL 9.8EPSS 81.8% | 7 February 2022 |
| CVE-2022-22833 | An attacker can obtain sensitive information via a /js/app.js request. | HIGH 7.5EPSS 11.6% | 6 February 2022 |
| CVE-2022-22832 | An issue was discovered in Servisnet Tessa 0.0.2. | CRITICAL 9.8EPSS 14.1% | 6 February 2022 |
| CVE-2022-22831 | An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header. | CRITICAL 9.8EPSS 11.4% | 6 February 2022 |
| CVE-2022-0437 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. | MEDIUM 6.1EPSS 15.1% | 5 February 2022 |
| CVE-2022-0218 | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the… | MEDIUM 6.1EPSS 70.5% | 4 February 2022 |
| CVE-2022-23329 | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files. | CRITICAL 9.8EPSS 14.4% | 4 February 2022 |
| CVE-2022-24260 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | CRITICAL 9.8EPSS 50.0% | 4 February 2022 |
| CVE-2022-24144 | Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. | CRITICAL 9.8EPSS 18.5% | 4 February 2022 |
| CVE-2022-23357 | mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. | CRITICAL 9.1EPSS 19.9% | 3 February 2022 |
| CVE-2022-23833 | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. | HIGH 7.5EPSS 49.5% | 3 February 2022 |
| CVE-2021-43062 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code… | MEDIUM 6.1EPSS 12.9% | 2 February 2022 |
| CVE-2022-24223 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | CRITICAL 9.8EPSS 62.0% | 1 February 2022 |
| CVE-2022-24218 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | CRITICAL 9.1EPSS 17.0% | 1 February 2022 |
| CVE-2021-24926 | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 12.9% | 1 February 2022 |
| CVE-2021-24762 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. | CRITICAL 9.8EPSS 86.8% | 1 February 2022 |
| CVE-2022-23409 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | MEDIUM 4.9EPSS 13.8% | 31 January 2022 |
| CVE-2021-34805 | For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal. | HIGH 7.5EPSS 26.8% | 31 January 2022 |
| CVE-2022-24124 | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations. | HIGH 7.5EPSS 55.3% | 29 January 2022 |
| CVE-2021-40412 | An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. | HIGH 7.2EPSS 27.5% | 28 January 2022 |
| CVE-2021-40410 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. | HIGH 7.2EPSS 27.9% | 28 January 2022 |
| CVE-2021-40407 | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 47.6% | 28 January 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.