SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 10 of 501

CVESummaryPriorityPublished
CVE-2024-23749KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390).EXPLOITHIGH 7.8EPSS 4.69%9 February 2024
CVE-2024-25004KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600).EXPLOITHIGH 7.8EPSS 1.78%9 February 2024
CVE-2024-25003KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization.EXPLOITHIGH 7.8EPSS 1.81%9 February 2024
CVE-2024-22318IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server.EXPLOITMEDIUM 5.5EPSS 0.57%9 February 2024
CVE-2024-24499Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —8 February 2024
CVE-2024-24497Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —8 February 2024
CVE-2024-24496An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.EXPLOITCRITICAL 9.8EPSS 19.5%8 February 2024
CVE-2024-24495SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.EXPLOITCRITICAL 9.8EPSS 1.33%8 February 2024
CVE-2024-24494Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php…EXPLOITMEDIUM 6.1EPSS 25.9%8 February 2024
CVE-2024-22836An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier.EXPLOITCRITICAL 9.8EPSS 30.0%8 February 2024
CVE-2023-48974Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.EXPLOITCRITICAL 9.6EPSS 2.96%8 February 2024
CVE-2024-24747The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.EXPLOITHIGH 8.8EPSS 34.1%31 January 2024
CVE-2024-23334This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present.EXPLOITHIGH 7.5EPSS 76.9%29 January 2024
CVE-2024-23897Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%24 January 2024
CVE-2024-0204Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.EXPLOITCRITICAL 9.8EPSS 95.1%22 January 2024
CVE-2024-0737A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1.EXPLOITHIGH 7.5EPSS 4.20%19 January 2024
CVE-2024-0725A vulnerability was found in ProSSHD 1.2 on Windows.EXPLOITHIGH 7.5EPSS 3.65%19 January 2024
CVE-2024-0723A vulnerability was found in freeSSHd 1.0.9 on Windows.EXPLOITHIGH 7.5EPSS 3.65%19 January 2024
CVE-2023-7028GitLab Community and Enterprise Editions Improper Access Control VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 94.6%12 January 2024
CVE-2024-21320Windows Themes Spoofing VulnerabilityEXPLOITMEDIUM 6.5EPSS 22.8%9 January 2024
CVE-2023-44088Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection.EXPLOITHIGH 8.8EPSS 0.73%29 December 2023
CVE-2023-6553The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file.EXPLOITCRITICAL 9.8EPSS 97.8%15 December 2023
CVE-2023-6710This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability.EXPLOITMEDIUM 5.4EPSS 2.24%12 December 2023
CVE-2023-6538SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation.EXPLOITMEDIUM 6.5EPSS 1.58%11 December 2023
CVE-2023-4220Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code…EXPLOITMEDIUM 6.1EPSS 76.1%28 November 2023
CVE-2023-48292Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an attacker to execute arbitrary shell commands by tricking an admin into loading the URL…EXPLOITHIGH 8.8EPSS 22.9%20 November 2023
CVE-2023-6019A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.EXPLOITCRITICAL 9.8EPSS 74.6%16 November 2023
CVE-2023-46024SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.EXPLOITHIGH 7.5EPSS 1.08%14 November 2023
CVE-2023-46022SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.EXPLOITHIGH 7.8EPSS 0.80%14 November 2023
CVE-2023-41425Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.EXPLOITMEDIUM 6.1EPSS 54.3%7 November 2023
CVE-2023-5360The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.EXPLOITCRITICAL 9.8EPSS 81.7%31 October 2023
CVE-2023-5702A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic.EXPLOITMEDIUM 6.5EPSS 14.5%23 October 2023
CVE-2023-45131There are no known workarounds for this vulnerability.EXPLOITHIGH 7.5EPSS 1.81%16 October 2023
CVE-2023-44487HTTP/2 Rapid Reset Attack VulnerabilityKEVEXPLOITHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-4911GNU C Library Buffer Overflow VulnerabilityKEVEXPLOITHIGH 7.8EPSS 81.4%3 October 2023
CVE-2023-5222A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0.EXPLOITCRITICAL 9.8EPSS 74.5%27 September 2023
CVE-2023-42793JetBrains TeamCity Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%19 September 2023
CVE-2023-3710Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004.EXPLOITCRITICAL 9.8EPSS 49.0%12 September 2023
CVE-2023-4278The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor.EXPLOITHIGH 7.5EPSS 6.24%11 September 2023
CVE-2023-31468The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM.EXPLOITHIGH 7.8EPSS 0.98%11 September 2023
CVE-2023-31069An issue was discovered in TSplus Remote Access through 16.0.2.14.EXPLOITCRITICAL 9.8EPSS 3.69%11 September 2023
CVE-2023-31068An issue was discovered in TSplus Remote Access through 16.0.2.14.EXPLOITCRITICAL 9.8EPSS 5.42%11 September 2023
CVE-2023-31067An issue was discovered in TSplus Remote Access through 16.0.2.14.EXPLOITCRITICAL 9.8EPSS 5.49%11 September 2023
CVE-2023-37759Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.EXPLOITCRITICAL 9.8EPSS 6.98%8 September 2023
CVE-2014-53298001/tcp is served by a version of Apache HTTP server containing a flaw in handling HTTP requests (CVE-2011-3192), which may lead to a denial-of-service (DoS) condition.EXPLOIT ×2HIGH 7.5EPSS 3.42%8 September 2023
CVE-2023-4634The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09.EXPLOITCRITICAL 9.8EPSS 85.9%6 September 2023
CVE-2023-39362In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.EXPLOITHIGH 7.2EPSS 85.4%5 September 2023
CVE-2023-4708A vulnerability was found in Infosoftbd Clcknshop 1.0.0.EXPLOITCRITICAL 9.8EPSS 31.2%1 September 2023
CVE-2023-31714Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.EXPLOITCRITICAL 9.8EPSS 5.78%30 August 2023
CVE-2023-4548A vulnerability classified as critical has been found in SPA-Cart eCommerce CMS 1.9.0.3.EXPLOITCRITICAL 9.8EPSS 27.9%26 August 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.