Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 7 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-48849 | Missing Origin Validation in WebSockets vulnerability in FLXEON. | EXPLOITHIGH 8.8EPSS 0.92% | 29 January 2025 |
| CVE-2024-11956 | A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. | EXPLOITMEDIUM 5.1EPSS 0.86% | 28 January 2025 |
| CVE-2024-11954 | A vulnerability classified as problematic was found in Pimcore 11.4.2. | EXPLOITMEDIUM 5.1EPSS 1.09% | 28 January 2025 |
| CVE-2025-24085 | Apple Multiple Products Use-After-Free Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 17.6% | 27 January 2025 |
| CVE-2024-48841 | Network access can be used to execute arbitrary code with elevated privileges. | EXPLOIT ×2CRITICAL 10.0EPSS 4.40% | 27 January 2025 |
| CVE-2024-47605 | The HTML is not sanitized before replacing the shortcode, allowing a script payload to be executed on both the CMS and the front-end of the website. | EXPLOITMEDIUM 5.4EPSS 1.15% | 14 January 2025 |
| CVE-2024-50861 | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. | EXPLOITMEDIUM 6.1EPSS 0.81% | 14 January 2025 |
| CVE-2024-50859 | The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. | EXPLOITMEDIUM 4.8EPSS 0.88% | 14 January 2025 |
| CVE-2024-50858 | Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). | EXPLOITHIGH 8.8EPSS 1.73% | 14 January 2025 |
| CVE-2024-50857 | The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). | EXPLOITMEDIUM 4.8EPSS 1.22% | 14 January 2025 |
| CVE-2024-48760 | An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. | EXPLOITCRITICAL 9.8EPSS 45.1% | 14 January 2025 |
| CVE-2025-21333 | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | KEVEXPLOITHIGH 7.8EPSS 9.99% | 14 January 2025 |
| CVE-2024-54761 | BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. | EXPLOITMEDIUM 6.3EPSS 1.78% | 9 January 2025 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | KEVEXPLOITCRITICAL 9.0EPSS 100.0% | 8 January 2025 |
| CVE-2024-11972 | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo,… | EXPLOITCRITICAL 9.8EPSS 54.5% | 31 December 2024 |
| CVE-2024-11605 | The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | EXPLOITMEDIUM 4.8EPSS 1.26% | 27 December 2024 |
| CVE-2024-12955 | A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. | EXPLOITMEDIUM 6.9EPSS 0.79% | 26 December 2024 |
| CVE-2024-51464 | IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. | EXPLOITMEDIUM 4.3EPSS 1.44% | 21 December 2024 |
| CVE-2024-51463 | IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). | EXPLOITMEDIUM 5.4EPSS 0.87% | 21 December 2024 |
| CVE-2024-55661 | A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Concerns\RemembersQueries` trait. | EXPLOITHIGH 8.7EPSS 29.5% | 13 December 2024 |
| CVE-2024-55889 | Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. | EXPLOITHIGH 7.2EPSS 2.19% | 13 December 2024 |
| CVE-2024-49138 | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | KEVEXPLOITHIGH 7.8EPSS 26.2% | 12 December 2024 |
| CVE-2024-12483 | A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. | EXPLOITMEDIUM 6.3EPSS 3.56% | 12 December 2024 |
| CVE-2024-12344 | A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. | EXPLOITMEDIUM 5.3EPSS 1.87% | 8 December 2024 |
| CVE-2024-12342 | A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. | EXPLOITHIGH 7.1EPSS 9.25% | 8 December 2024 |
| CVE-2024-11728 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient… | EXPLOITHIGH 7.5EPSS 13.6% | 6 December 2024 |
| CVE-2024-6516 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. | EXPLOIT ×3CRITICAL 9.3EPSS 1.08% | 5 December 2024 |
| CVE-2024-51550 | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. | EXPLOITCRITICAL 9.3EPSS 1.81% | 5 December 2024 |
| CVE-2024-51546 | Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. | EXPLOITHIGH 8.7EPSS 1.47% | 5 December 2024 |
| CVE-2024-48846 | Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. | EXPLOITHIGH 7.1EPSS 0.64% | 5 December 2024 |
| CVE-2024-48845 | Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. | EXPLOITCRITICAL 9.3EPSS 1.82% | 5 December 2024 |
| CVE-2024-48844 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. | EXPLOITHIGH 7.2EPSS 0.87% | 5 December 2024 |
| CVE-2024-48840 | Unauthorized Access vulnerabilities allow Remote Code Execution. | EXPLOITCRITICAL 9.3EPSS 2.06% | 5 December 2024 |
| CVE-2024-48839 | Improper Input Validation vulnerability allows Remote Code Execution. | EXPLOIT ×2CRITICAL 9.3EPSS 2.83% | 5 December 2024 |
| CVE-2024-42327 | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. | EXPLOITCRITICAL 9.9EPSS 78.7% | 27 November 2024 |
| CVE-2024-50672 | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. | EXPLOITCRITICAL 9.8EPSS 1.57% | 25 November 2024 |
| CVE-2024-11392 | Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. | EXPLOITHIGH 8.8EPSS 7.26% | 22 November 2024 |
| CVE-2024-30896 | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. | EXPLOITCRITICAL 9.1EPSS 5.36% | 21 November 2024 |
| CVE-2024-8856 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including,… | EXPLOITCRITICAL 9.8EPSS 94.0% | 16 November 2024 |
| CVE-2024-11237 | A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. | EXPLOITHIGH 8.7EPSS 5.33% | 15 November 2024 |
| CVE-2024-10924 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. | EXPLOITCRITICAL 9.8EPSS 82.0% | 15 November 2024 |
| CVE-2024-52302 | There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. | EXPLOITHIGH 8.7EPSS 3.36% | 14 November 2024 |
| CVE-2024-24409 | Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | EXPLOITHIGH 8.8EPSS 6.20% | 8 November 2024 |
| CVE-2024-43425 | Additional restrictions are required to avoid a remote code execution risk in calculated question types. | EXPLOITHIGH 8.1EPSS 87.4% | 7 November 2024 |
| CVE-2024-10914 | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. | EXPLOITCRITICAL 9.2EPSS 96.3% | 6 November 2024 |
| CVE-2024-10758 | A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. | EXPLOITMEDIUM 6.9EPSS 1.43% | 4 November 2024 |
| CVE-2024-51774 | qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors. | EXPLOITHIGH 8.1EPSS 3.30% | 2 November 2024 |
| CVE-2024-51378 | CyberPanel Incorrect Default Permissions Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 94.7% | 29 October 2024 |
| CVE-2024-48573 | A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. | EXPLOITCRITICAL 9.8EPSS 1.03% | 29 October 2024 |
| CVE-2024-50477 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | EXPLOITCRITICAL 9.8EPSS 8.12% | 28 October 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.