Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 5 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-44177 | A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. | EXPLOITHIGH 8.2EPSS 4.34% | 9 July 2025 |
| CVE-2025-34077 | An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. | EXPLOITCRITICAL 10.0EPSS 15.1% | 9 July 2025 |
| CVE-2025-49744 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.0EPSS 0.73% | 8 July 2025 |
| CVE-2025-49730 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.8EPSS 0.60% | 8 July 2025 |
| CVE-2025-49683 | Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | EXPLOITHIGH 7.8EPSS 1.90% | 8 July 2025 |
| CVE-2025-49677 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.0EPSS 0.97% | 8 July 2025 |
| CVE-2025-47987 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.8EPSS 1.70% | 8 July 2025 |
| CVE-2025-32023 | From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote code execution. | EXPLOITHIGH 7.8EPSS 3.96% | 7 July 2025 |
| CVE-2025-47228 | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests. | EXPLOITMEDIUM 6.7EPSS 17.2% | 5 July 2025 |
| CVE-2025-6563 | A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. | EXPLOITMEDIUM 4.8EPSS 0.67% | 3 July 2025 |
| CVE-2025-49741 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | EXPLOITHIGH 7.5EPSS 3.50% | 1 July 2025 |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVEXPLOITHIGH 7.8EPSS 59.4% | 30 June 2025 |
| CVE-2025-32462 | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. | EXPLOITHIGH 8.8EPSS 4.28% | 30 June 2025 |
| CVE-2024-57708 | An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. | EXPLOITMEDIUM 5.7EPSS 0.89% | 25 June 2025 |
| CVE-2025-34040 | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. | EXPLOITCRITICAL 10.0EPSS 15.1% | 24 June 2025 |
| CVE-2025-49132 | Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. | EXPLOITCRITICAL 10.0EPSS 54.7% | 20 June 2025 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 100.0% | 17 June 2025 |
| CVE-2025-47957 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | EXPLOITHIGH 8.4EPSS 1.31% | 10 June 2025 |
| CVE-2025-47175 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | EXPLOITHIGH 7.8EPSS 2.39% | 10 June 2025 |
| CVE-2025-47171 | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | EXPLOITMEDIUM 6.7EPSS 1.66% | 10 June 2025 |
| CVE-2025-47166 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | EXPLOITHIGH 8.8EPSS 21.2% | 10 June 2025 |
| CVE-2025-47165 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | EXPLOITHIGH 7.8EPSS 2.19% | 10 June 2025 |
| CVE-2025-33073 | Microsoft Windows SMB Client Improper Access Control Vulnerability | KEVEXPLOITHIGH 8.8EPSS 82.7% | 10 June 2025 |
| CVE-2024-50562 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN… | EXPLOITMEDIUM 4.8EPSS 1.15% | 10 June 2025 |
| CVE-2025-46041 | A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add). | EXPLOITMEDIUM 5.4EPSS 0.60% | 9 June 2025 |
| CVE-2025-49619 | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. | EXPLOITHIGH 8.5EPSS 20.0% | 7 June 2025 |
| CVE-2025-5640 | A vulnerability was found in PX4-Autopilot 1.12.3. | EXPLOITMEDIUM 4.8EPSS 0.99% | 5 June 2025 |
| CVE-2025-5548 | A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. | EXPLOITMEDIUM 6.9EPSS 15.0% | 4 June 2025 |
| CVE-2025-45542 | SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. | EXPLOITHIGH 7.3EPSS 1.09% | 2 June 2025 |
| CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | KEVEXPLOITHIGH 8.8EPSS 98.9% | 2 June 2025 |
| CVE-2025-5298 | A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. | EXPLOITMEDIUM 6.9EPSS 0.93% | 28 May 2025 |
| CVE-2024-13946 | DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | EXPLOITHIGH 7.1EPSS 1.02% | 22 May 2025 |
| CVE-2025-4123 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. | EXPLOITMEDIUM 6.1EPSS 97.0% | 22 May 2025 |
| CVE-2025-46822 | Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. | EXPLOITHIGH 7.7EPSS 4.03% | 21 May 2025 |
| CVE-2025-4524 | The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. | EXPLOITCRITICAL 9.8EPSS 10.4% | 21 May 2025 |
| CVE-2025-4094 | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them. | EXPLOITCRITICAL 9.8EPSS 15.8% | 21 May 2025 |
| CVE-2025-37928 | In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function… | EXPLOITHIGH 7.8EPSS 0.67% | 20 May 2025 |
| CVE-2025-41228 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. | EXPLOITMEDIUM 4.3EPSS 0.89% | 20 May 2025 |
| CVE-2025-4971 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | EXPLOITHIGH 8.5EPSS 0.58% | 20 May 2025 |
| CVE-2025-4871 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. | EXPLOITMEDIUM 6.9EPSS 1.62% | 18 May 2025 |
| CVE-2025-47916 | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. | EXPLOITCRITICAL 9.8EPSS 83.7% | 16 May 2025 |
| CVE-2025-47161 | Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.8EPSS 0.80% | 15 May 2025 |
| CVE-2025-30397 | Microsoft Windows Scripting Engine Type Confusion Vulnerability | KEVEXPLOITHIGH 7.5EPSS 26.8% | 13 May 2025 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | KEVEXPLOITHIGH 7.5EPSS 99.9% | 13 May 2025 |
| CVE-2025-3605 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. | EXPLOITCRITICAL 9.8EPSS 6.94% | 9 May 2025 |
| CVE-2025-27533 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. | EXPLOITMEDIUM 6.9EPSS 8.66% | 7 May 2025 |
| CVE-2025-2011 | The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | EXPLOITHIGH 7.5EPSS 46.4% | 6 May 2025 |
| CVE-2025-28062 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. | EXPLOITHIGH 8.1EPSS 0.77% | 5 May 2025 |
| CVE-2025-4255 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. | EXPLOITMEDIUM 6.9EPSS 2.02% | 5 May 2025 |
| CVE-2025-47226 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. | EXPLOITLOW 3.3EPSS 1.25% | 2 May 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.