SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 7 of 501

CVESummaryPriorityPublished
CVE-2024-48849Missing Origin Validation in WebSockets vulnerability in FLXEON.EXPLOITHIGH 8.8EPSS 0.92%29 January 2025
CVE-2024-11956A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0.EXPLOITMEDIUM 5.1EPSS 0.86%28 January 2025
CVE-2024-11954A vulnerability classified as problematic was found in Pimcore 11.4.2.EXPLOITMEDIUM 5.1EPSS 1.09%28 January 2025
CVE-2025-24085Apple Multiple Products Use-After-Free VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 17.6%27 January 2025
CVE-2024-48841Network access can be used to execute arbitrary code with elevated privileges.EXPLOIT ×2CRITICAL 10.0EPSS 4.40%27 January 2025
CVE-2024-47605The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on both the CMS and the front-end of the website.EXPLOITMEDIUM 5.4EPSS 1.15%14 January 2025
CVE-2024-50861The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS.EXPLOITMEDIUM 6.1EPSS 0.81%14 January 2025
CVE-2024-50859The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS.EXPLOITMEDIUM 4.8EPSS 0.88%14 January 2025
CVE-2024-50858Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF).EXPLOITHIGH 8.8EPSS 1.73%14 January 2025
CVE-2024-50857The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS).EXPLOITMEDIUM 4.8EPSS 1.22%14 January 2025
CVE-2024-48760An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function.EXPLOITCRITICAL 9.8EPSS 45.1%14 January 2025
CVE-2025-21333Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow VulnerabilityKEVEXPLOITHIGH 7.8EPSS 9.99%14 January 2025
CVE-2024-54761BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.EXPLOITMEDIUM 6.3EPSS 1.78%9 January 2025
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow VulnerabilityKEVEXPLOITCRITICAL 9.0EPSS 100.0%8 January 2025
CVE-2024-11972The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo,…EXPLOITCRITICAL 9.8EPSS 54.5%31 December 2024
CVE-2024-11605The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…EXPLOITMEDIUM 4.8EPSS 1.26%27 December 2024
CVE-2024-12955A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic.EXPLOITMEDIUM 6.9EPSS 0.79%26 December 2024
CVE-2024-51464IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions.EXPLOITMEDIUM 4.3EPSS 1.44%21 December 2024
CVE-2024-51463IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF).EXPLOITMEDIUM 5.4EPSS 0.87%21 December 2024
CVE-2024-55661A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Concerns\RemembersQueries` trait.EXPLOITHIGH 8.7EPSS 29.5%13 December 2024
CVE-2024-55889Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent.EXPLOITHIGH 7.2EPSS 2.19%13 December 2024
CVE-2024-49138Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityKEVEXPLOITHIGH 7.8EPSS 26.2%12 December 2024
CVE-2024-12483A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3.EXPLOITMEDIUM 6.3EPSS 3.56%12 December 2024
CVE-2024-12344A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021.EXPLOITMEDIUM 5.3EPSS 1.87%8 December 2024
CVE-2024-12342A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021.EXPLOITHIGH 7.1EPSS 9.25%8 December 2024
CVE-2024-11728The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient…EXPLOITHIGH 7.5EPSS 13.6%6 December 2024
CVE-2024-6516Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.EXPLOIT ×3CRITICAL 9.3EPSS 1.08%5 December 2024
CVE-2024-51550Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.EXPLOITCRITICAL 9.3EPSS 1.81%5 December 2024
CVE-2024-51546Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.EXPLOITHIGH 8.7EPSS 1.47%5 December 2024
CVE-2024-48846Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.EXPLOITHIGH 7.1EPSS 0.64%5 December 2024
CVE-2024-48845Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.EXPLOITCRITICAL 9.3EPSS 1.82%5 December 2024
CVE-2024-48844Denial of Service vulnerabilities where found providing a potiential for device service disruptions.EXPLOITHIGH 7.2EPSS 0.87%5 December 2024
CVE-2024-48840Unauthorized Access vulnerabilities allow Remote Code Execution.EXPLOITCRITICAL 9.3EPSS 2.06%5 December 2024
CVE-2024-48839Improper Input Validation vulnerability allows Remote Code Execution.EXPLOIT ×2CRITICAL 9.3EPSS 2.83%5 December 2024
CVE-2024-42327A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability.EXPLOITCRITICAL 9.9EPSS 78.7%27 November 2024
CVE-2024-50672A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.EXPLOITCRITICAL 9.8EPSS 1.57%25 November 2024
CVE-2024-11392Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability.EXPLOITHIGH 8.8EPSS 7.26%22 November 2024
CVE-2024-30896InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token.EXPLOITCRITICAL 9.1EPSS 5.36%21 November 2024
CVE-2024-8856The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including,…EXPLOITCRITICAL 9.8EPSS 94.0%16 November 2024
CVE-2024-11237A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021.EXPLOITHIGH 8.7EPSS 5.33%15 November 2024
CVE-2024-10924The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1.EXPLOITCRITICAL 9.8EPSS 82.0%15 November 2024
CVE-2024-52302There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture.EXPLOITHIGH 8.7EPSS 3.36%14 November 2024
CVE-2024-24409Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.EXPLOITHIGH 8.8EPSS 6.20%8 November 2024
CVE-2024-43425Additional restrictions are required to avoid a remote code execution risk in calculated question types.EXPLOITHIGH 8.1EPSS 87.4%7 November 2024
CVE-2024-10914A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.EXPLOITCRITICAL 9.2EPSS 96.3%6 November 2024
CVE-2024-10758A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0.EXPLOITMEDIUM 6.9EPSS 1.43%4 November 2024
CVE-2024-51774qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.EXPLOITHIGH 8.1EPSS 3.30%2 November 2024
CVE-2024-51378CyberPanel Incorrect Default Permissions VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 94.7%29 October 2024
CVE-2024-48573A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.EXPLOITCRITICAL 9.8EPSS 1.03%29 October 2024
CVE-2024-50477Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.EXPLOITCRITICAL 9.8EPSS 8.12%28 October 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.