SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 77 of 348

CVESummaryPriorityPublished
CVE-2021-4034Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityKEVHIGH 7.8EPSS 94.9%28 January 2022
CVE-2021-23174Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].MEDIUM 4.8EPSS 83.9%28 January 2022
CVE-2021-46065A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.MEDIUM 4.8EPSS 91.7%27 January 2022
CVE-2022-0332An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.CRITICAL 9.8EPSS 44.9%25 January 2022
CVE-2022-23944User can access /plugin api without authentication.CRITICAL 9.1EPSS 79.0%25 January 2022
CVE-2022-23437There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads.MEDIUM 6.5EPSS 11.6%24 January 2022
CVE-2021-25080The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against…MEDIUM 6.1EPSS 84.2%24 January 2022
CVE-2021-25076The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection.HIGH 8.8EPSS 17.1%24 January 2022
CVE-2022-22930A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.CRITICAL 9.8EPSS 23.7%21 January 2022
CVE-2022-23119A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system.HIGH 7.5EPSS 22.3%20 January 2022
CVE-2022-22733Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation.MEDIUM 6.5EPSS 37.6%20 January 2022
CVE-2022-0281Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.HIGH 7.5EPSS 12.0%20 January 2022
CVE-2022-23046PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.phpHIGH 7.2EPSS 25.2%19 January 2022
CVE-2022-23221H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.CRITICAL 9.8EPSS 64.8%19 January 2022
CVE-2022-21371Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).HIGH 7.5EPSS 92.6%19 January 2022
CVE-2022-21280Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).MEDIUM 6.3EPSS 76.5%19 January 2022
CVE-2022-21279Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).MEDIUM 6.3EPSS 79.0%19 January 2022
CVE-2021-35587Oracle Fusion Middleware Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 96.3%19 January 2022
CVE-2022-23307CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw.HIGH 8.8EPSS 54.4%18 January 2022
CVE-2022-23305This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed.CRITICAL 9.8EPSS 66.5%18 January 2022
CVE-2022-23302JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to.HIGH 8.8EPSS 63.6%18 January 2022
CVE-2021-44757Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.CRITICAL 9.1EPSS 24.2%18 January 2022
CVE-2022-23178When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface.CRITICAL 9.8EPSS 75.2%15 January 2022
CVE-2021-45068Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 12.3%14 January 2022
CVE-2021-45064Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…HIGH 7.8EPSS 11.5%14 January 2022
CVE-2021-45062Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…HIGH 7.8EPSS 16.5%14 January 2022
CVE-2021-44715Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated…MEDIUM 5.5EPSS 14.7%14 January 2022
CVE-2021-44710Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…HIGH 7.8EPSS 11.6%14 January 2022
CVE-2021-44709Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution…HIGH 7.8EPSS 30.0%14 January 2022
CVE-2021-44708Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution…HIGH 7.8EPSS 39.3%14 January 2022
CVE-2021-44704Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…HIGH 7.8EPSS 10.8%14 January 2022
CVE-2021-44703Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code…HIGH 7.8EPSS 57.3%14 January 2022
CVE-2021-44701Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…HIGH 7.8EPSS 20.9%14 January 2022
CVE-2022-23227NUUO NVRmini2 Devices Missing Authentication Vulnerability KEVCRITICAL 9.8EPSS 48.5%14 January 2022
CVE-2021-34996This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.HIGH 8.8EPSS 82.3%13 January 2022
CVE-2021-34995This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.HIGH 8.8EPSS 68.9%13 January 2022
CVE-2022-23134Zabbix Frontend Improper Access Control VulnerabilityKEVMEDIUM 5.3EPSS 84.7%13 January 2022
CVE-2022-23131Zabbix Frontend Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 95.7%13 January 2022
CVE-2022-23111A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.MEDIUM 4.3EPSS 26.5%12 January 2022
CVE-2022-20615Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.MEDIUM 5.4EPSS 81.8%12 January 2022
CVE-2021-42561This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.HIGH 8.8EPSS 19.6%12 January 2022
CVE-2022-21907HTTP Protocol Stack Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 92.8%11 January 2022
CVE-2022-21882Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 59.2%11 January 2022
CVE-2022-21881Windows Kernel Elevation of Privilege VulnerabilityHIGH 7.0EPSS 24.2%11 January 2022
CVE-2021-43297A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution.CRITICAL 9.8EPSS 17.0%10 January 2022
CVE-2021-24862The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issueHIGH 7.2EPSS 73.3%10 January 2022
CVE-2021-42392An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution.CRITICAL 9.8EPSS 63.2%10 January 2022
CVE-2022-21662Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users.MEDIUM 5.4EPSS 64.5%6 January 2022
CVE-2022-21661Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way.HIGH 7.5EPSS 97.8%6 January 2022
CVE-2021-45456Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user.CRITICAL 9.8EPSS 88.9%6 January 2022

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.