Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 77 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-4034 | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability | KEVHIGH 7.8EPSS 94.9% | 28 January 2022 |
| CVE-2021-23174 | Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. | MEDIUM 4.8EPSS 83.9% | 28 January 2022 |
| CVE-2021-46065 | A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. | MEDIUM 4.8EPSS 91.7% | 27 January 2022 |
| CVE-2022-0332 | An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | CRITICAL 9.8EPSS 44.9% | 25 January 2022 |
| CVE-2022-23944 | User can access /plugin api without authentication. | CRITICAL 9.1EPSS 79.0% | 25 January 2022 |
| CVE-2022-23437 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. | MEDIUM 6.5EPSS 11.6% | 24 January 2022 |
| CVE-2021-25080 | The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against… | MEDIUM 6.1EPSS 84.2% | 24 January 2022 |
| CVE-2021-25076 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. | HIGH 8.8EPSS 17.1% | 24 January 2022 |
| CVE-2022-22930 | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload. | CRITICAL 9.8EPSS 23.7% | 21 January 2022 |
| CVE-2022-23119 | A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. | HIGH 7.5EPSS 22.3% | 20 January 2022 |
| CVE-2022-22733 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. | MEDIUM 6.5EPSS 37.6% | 20 January 2022 |
| CVE-2022-0281 | Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. | HIGH 7.5EPSS 12.0% | 20 January 2022 |
| CVE-2022-23046 | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | HIGH 7.2EPSS 25.2% | 19 January 2022 |
| CVE-2022-23221 | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392. | CRITICAL 9.8EPSS 64.8% | 19 January 2022 |
| CVE-2022-21371 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). | HIGH 7.5EPSS 92.6% | 19 January 2022 |
| CVE-2022-21280 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). | MEDIUM 6.3EPSS 76.5% | 19 January 2022 |
| CVE-2022-21279 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). | MEDIUM 6.3EPSS 79.0% | 19 January 2022 |
| CVE-2021-35587 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 96.3% | 19 January 2022 |
| CVE-2022-23307 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. | HIGH 8.8EPSS 54.4% | 18 January 2022 |
| CVE-2022-23305 | This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. | CRITICAL 9.8EPSS 66.5% | 18 January 2022 |
| CVE-2022-23302 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. | HIGH 8.8EPSS 63.6% | 18 January 2022 |
| CVE-2021-44757 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. | CRITICAL 9.1EPSS 24.2% | 18 January 2022 |
| CVE-2022-23178 | When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. | CRITICAL 9.8EPSS 75.2% | 15 January 2022 |
| CVE-2021-45068 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 12.3% | 14 January 2022 |
| CVE-2021-45064 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the… | HIGH 7.8EPSS 11.5% | 14 January 2022 |
| CVE-2021-45062 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the… | HIGH 7.8EPSS 16.5% | 14 January 2022 |
| CVE-2021-44715 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated… | MEDIUM 5.5EPSS 14.7% | 14 January 2022 |
| CVE-2021-44710 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the… | HIGH 7.8EPSS 11.6% | 14 January 2022 |
| CVE-2021-44709 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution… | HIGH 7.8EPSS 30.0% | 14 January 2022 |
| CVE-2021-44708 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution… | HIGH 7.8EPSS 39.3% | 14 January 2022 |
| CVE-2021-44704 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the… | HIGH 7.8EPSS 10.8% | 14 January 2022 |
| CVE-2021-44703 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code… | HIGH 7.8EPSS 57.3% | 14 January 2022 |
| CVE-2021-44701 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the… | HIGH 7.8EPSS 20.9% | 14 January 2022 |
| CVE-2022-23227 | NUUO NVRmini2 Devices Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 48.5% | 14 January 2022 |
| CVE-2021-34996 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. | HIGH 8.8EPSS 82.3% | 13 January 2022 |
| CVE-2021-34995 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. | HIGH 8.8EPSS 68.9% | 13 January 2022 |
| CVE-2022-23134 | Zabbix Frontend Improper Access Control Vulnerability | KEVMEDIUM 5.3EPSS 84.7% | 13 January 2022 |
| CVE-2022-23131 | Zabbix Frontend Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 95.7% | 13 January 2022 |
| CVE-2022-23111 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials. | MEDIUM 4.3EPSS 26.5% | 12 January 2022 |
| CVE-2022-20615 | Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | MEDIUM 5.4EPSS 81.8% | 12 January 2022 |
| CVE-2021-42561 | This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands. | HIGH 8.8EPSS 19.6% | 12 January 2022 |
| CVE-2022-21907 | HTTP Protocol Stack Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 92.8% | 11 January 2022 |
| CVE-2022-21882 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 59.2% | 11 January 2022 |
| CVE-2022-21881 | Windows Kernel Elevation of Privilege Vulnerability | HIGH 7.0EPSS 24.2% | 11 January 2022 |
| CVE-2021-43297 | A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. | CRITICAL 9.8EPSS 17.0% | 10 January 2022 |
| CVE-2021-24862 | The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue | HIGH 7.2EPSS 73.3% | 10 January 2022 |
| CVE-2021-42392 | An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. | CRITICAL 9.8EPSS 63.2% | 10 January 2022 |
| CVE-2022-21662 | Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. | MEDIUM 5.4EPSS 64.5% | 6 January 2022 |
| CVE-2022-21661 | Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. | HIGH 7.5EPSS 97.8% | 6 January 2022 |
| CVE-2021-45456 | Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. | CRITICAL 9.8EPSS 88.9% | 6 January 2022 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.