SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 76 of 348

CVESummaryPriorityPublished
CVE-2022-0289Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 27.7%12 February 2022
CVE-2022-0185Linux Kernel Heap-Based Buffer Overflow VulnerabilityKEVHIGH 8.4EPSS 25.2%11 February 2022
CVE-2021-31932Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.CRITICAL 9.8EPSS 21.6%11 February 2022
CVE-2021-22824A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network.HIGH 7.5EPSS 14.2%11 February 2022
CVE-2021-22823A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages.CRITICAL 9.1EPSS 21.4%11 February 2022
CVE-2021-22802A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network.CRITICAL 9.8EPSS 20.2%11 February 2022
CVE-2022-24112Apache APISIX Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 96.0%11 February 2022
CVE-2021-44521When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the…CRITICAL 9.1EPSS 55.0%11 February 2022
CVE-2022-0557OS Command Injection in Packagist microweber/microweber prior to 1.2.11.HIGH 7.2EPSS 51.2%11 February 2022
CVE-2022-24954Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.CRITICAL 9.8EPSS 11.9%11 February 2022
CVE-2022-20708Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityKEVHIGH 8.0EPSS 14.9%10 February 2022
CVE-2022-20707Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and…HIGH 7.3EPSS 75.3%10 February 2022
CVE-2022-20705Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and…CRITICAL 9.8EPSS 80.0%10 February 2022
CVE-2022-20699Cisco Small Business RV Series Routers Stack-based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 72.5%10 February 2022
CVE-2021-45901The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.MEDIUM 5.3EPSS 14.3%10 February 2022
CVE-2022-24315A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message.HIGH 7.5EPSS 19.3%9 February 2022
CVE-2022-24314A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message.HIGH 7.5EPSS 18.2%9 February 2022
CVE-2022-24313A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message.CRITICAL 9.8EPSS 44.6%9 February 2022
CVE-2022-22536SAP Multiple Products HTTP Request Smuggling VulnerabilityKEVCRITICAL 10.0EPSS 97.9%9 February 2022
CVE-2022-22718Microsoft Windows Print Spooler Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 18.5%9 February 2022
CVE-2022-22715Named Pipe File System Elevation of Privilege VulnerabilityHIGH 7.8EPSS 12.6%9 February 2022
CVE-2022-22005Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 16.4%9 February 2022
CVE-2022-21999Microsoft Windows Print Spooler Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 41.7%9 February 2022
CVE-2022-21993Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityHIGH 7.5EPSS 43.6%9 February 2022
CVE-2022-21971Microsoft Windows Runtime Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 53.9%9 February 2022
CVE-2021-46354Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site.HIGH 7.5EPSS 12.9%9 February 2022
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityKEVMEDIUM 6.1EPSS 30.9%9 February 2022
CVE-2021-44864TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow.MEDIUM 6.5EPSS 10.2%8 February 2022
CVE-2021-25114The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injectionCRITICAL 9.8EPSS 81.8%7 February 2022
CVE-2022-22833An attacker can obtain sensitive information via a /js/app.js request.HIGH 7.5EPSS 11.6%6 February 2022
CVE-2022-22832An issue was discovered in Servisnet Tessa 0.0.2.CRITICAL 9.8EPSS 14.1%6 February 2022
CVE-2022-22831An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.CRITICAL 9.8EPSS 11.4%6 February 2022
CVE-2022-0437Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.MEDIUM 6.1EPSS 15.1%5 February 2022
CVE-2022-0218The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the…MEDIUM 6.1EPSS 70.5%4 February 2022
CVE-2022-23329A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.CRITICAL 9.8EPSS 14.4%4 February 2022
CVE-2022-24260A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.CRITICAL 9.8EPSS 50.0%4 February 2022
CVE-2022-24144Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting.CRITICAL 9.8EPSS 18.5%4 February 2022
CVE-2022-23357mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.CRITICAL 9.1EPSS 19.9%3 February 2022
CVE-2022-23833An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2.HIGH 7.5EPSS 49.5%3 February 2022
CVE-2021-43062A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code…MEDIUM 6.1EPSS 12.9%2 February 2022
CVE-2022-24223AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.CRITICAL 9.8EPSS 62.0%1 February 2022
CVE-2022-24218An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.CRITICAL 9.1EPSS 17.0%1 February 2022
CVE-2021-24926The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 12.9%1 February 2022
CVE-2021-24762The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.CRITICAL 9.8EPSS 86.8%1 February 2022
CVE-2022-23409The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.MEDIUM 4.9EPSS 13.8%31 January 2022
CVE-2021-34805For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.HIGH 7.5EPSS 26.8%31 January 2022
CVE-2022-24124The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.HIGH 7.5EPSS 55.3%29 January 2022
CVE-2021-40412An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102.HIGH 7.2EPSS 27.5%28 January 2022
CVE-2021-40410An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102.HIGH 7.2EPSS 27.9%28 January 2022
CVE-2021-40407Reolink RLC-410W IP Camera OS Command Injection Vulnerability KEVHIGH 7.2EPSS 47.6%28 January 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.