SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 4 of 501

CVESummaryPriorityPublished
CVE-2025-57174The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary.EXPLOITCRITICAL 9.8EPSS 2.21%15 September 2025
CVE-2025-10370A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.EXPLOITLOW 2.0EPSS 0.69%13 September 2025
CVE-2025-10327A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.EXPLOITLOW 2.1EPSS 10.2%12 September 2025
CVE-2025-58434This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO).EXPLOITCRITICAL 9.8EPSS 49.9%12 September 2025
CVE-2025-57642A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system.EXPLOITHIGH 7.2EPSS 1.59%10 September 2025
CVE-2025-58180OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command…EXPLOITHIGH 7.5EPSS 20.6%9 September 2025
CVE-2025-10046The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and…EXPLOITMEDIUM 4.9EPSS 0.71%6 September 2025
CVE-2025-8311dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint.EXPLOITCRITICAL 9.4EPSS 1.67%4 September 2025
CVE-2025-57819Sangoma FreePBX Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 85.5%28 August 2025
CVE-2025-9074A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default.EXPLOITCRITICAL 9.3EPSS 1.63%20 August 2025
CVE-2025-9140A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7.EXPLOITLOW 2.1EPSS 0.50%19 August 2025
CVE-2025-9090A vulnerability was identified in Tenda AC20 16.03.08.12.EXPLOITLOW 2.1EPSS 14.1%17 August 2025
CVE-2025-7441The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42.EXPLOITCRITICAL 9.8EPSS 39.5%16 August 2025
CVE-2025-52392Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms.EXPLOITMEDIUM 5.4EPSS 0.86%13 August 2025
CVE-2025-50154Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.EXPLOITMEDIUM 6.5EPSS 25.6%12 August 2025
CVE-2025-8730A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical.EXPLOITHIGH 8.9EPSS 3.36%8 August 2025
CVE-2025-7769Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input.EXPLOITHIGH 8.7EPSS 17.7%6 August 2025
CVE-2025-50286A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface.EXPLOITHIGH 8.1EPSS 9.56%6 August 2025
CVE-2025-7771ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function.EXPLOITHIGH 8.7EPSS 7.17%6 August 2025
CVE-2025-8573Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.EXPLOITLOW 2.0EPSS 0.44%5 August 2025
CVE-2025-8550A vulnerability was found in atjiu pybbs up to 6.0.0.EXPLOITLOW 1.9EPSS 0.63%5 August 2025
CVE-2025-8471A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0.EXPLOITMEDIUM 5.5EPSS 0.64%2 August 2025
CVE-2025-41373A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1.EXPLOITHIGH 8.7EPSS 1.09%1 August 2025
CVE-2025-54589This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without proper escaping, allowing for reflected Cross-Site Scripting (XSS) and can be exploited against both authenticated and unauthenticated…EXPLOITMEDIUM 6.1EPSS 2.42%31 July 2025
CVE-2025-46811A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client.EXPLOITCRITICAL 9.3EPSS 10.7%30 July 2025
CVE-2025-54769An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing.EXPLOITHIGH 8.8EPSS 3.22%29 July 2025
CVE-2025-8191A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3.EXPLOITLOW 2.0EPSS 1.70%26 July 2025
CVE-2025-32429In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm.EXPLOITCRITICAL 9.3EPSS 85.3%24 July 2025
CVE-2025-50481A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a blog post.EXPLOITMEDIUM 4.8EPSS 0.61%23 July 2025
CVE-2025-6018A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM).EXPLOITHIGH 7.8EPSS 1.02%23 July 2025
CVE-2025-7766Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.EXPLOITHIGH 8.6EPSS 1.73%22 July 2025
CVE-2025-6082The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.EXPLOITMEDIUM 5.3EPSS 1.57%22 July 2025
CVE-2025-51403A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.EXPLOITMEDIUM 6.5EPSS 1.53%21 July 2025
CVE-2025-51401A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.EXPLOITMEDIUM 5.4EPSS 0.89%21 July 2025
CVE-2025-51400A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.EXPLOITMEDIUM 5.4EPSS 0.89%21 July 2025
CVE-2025-51398A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.EXPLOITMEDIUM 5.4EPSS 0.89%21 July 2025
CVE-2025-51397A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.EXPLOITMEDIUM 5.4EPSS 0.92%21 July 2025
CVE-2025-51396A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.EXPLOITMEDIUM 5.4EPSS 0.94%21 July 2025
CVE-2025-47917Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation.EXPLOITCRITICAL 9.8EPSS 2.15%20 July 2025
CVE-2025-53770Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%20 July 2025
CVE-2025-27210This vulnerability affects Windows users of `path.join` API.EXPLOITHIGH 7.5EPSS 14.9%18 July 2025
CVE-2025-7795A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9.EXPLOITHIGH 7.4EPSS 3.09%18 July 2025
CVE-2025-49484A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.EXPLOITHIGH 8.7EPSS 3.84%18 July 2025
CVE-2025-25257Fortinet FortiWeb SQL Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.8%17 July 2025
CVE-2025-6965There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available.EXPLOITHIGH 7.2EPSS 72.5%15 July 2025
CVE-2024-58258SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.EXPLOITHIGH 7.2EPSS 16.3%13 July 2025
CVE-2020-36847The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension.EXPLOITCRITICAL 9.8EPSS 44.2%12 July 2025
CVE-2013-3307Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.EXPLOITHIGH 8.3EPSS 55.7%11 July 2025
CVE-2025-52089A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.EXPLOITHIGH 8.8EPSS 7.99%11 July 2025
CVE-2025-47812Wing FTP Server Improper Neutralization of Null Byte or NUL Character VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 92.9%10 July 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.