Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 8 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-44000 | Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1. | EXPLOITCRITICAL 9.8EPSS 82.3% | 20 October 2024 |
| CVE-2024-44762 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts. | EXPLOIT ×2MEDIUM 5.3EPSS 2.57% | 16 October 2024 |
| CVE-2024-46528 | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources… | EXPLOITMEDIUM 4.3EPSS 1.58% | 14 October 2024 |
| CVE-2024-48120 | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. | EXPLOITMEDIUM 5.4EPSS 0.64% | 14 October 2024 |
| CVE-2024-48827 | An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function. | EXPLOITHIGH 8.8EPSS 2.79% | 11 October 2024 |
| CVE-2024-42640 | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. | EXPLOIT ×2CRITICAL 9.8EPSS 45.1% | 11 October 2024 |
| CVE-2024-47773 | An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. | EXPLOITHIGH 8.2EPSS 1.66% | 8 October 2024 |
| CVE-2024-42831 | A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at… | EXPLOITMEDIUM 6.1EPSS 0.84% | 7 October 2024 |
| CVE-2024-46278 | Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console. | EXPLOITHIGH 8.4EPSS 2.83% | 7 October 2024 |
| CVE-2024-9054 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This… | EXPLOITHIGH 8.5EPSS 15.6% | 4 October 2024 |
| CVE-2024-7801 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | EXPLOITMEDIUM 6.3EPSS 0.84% | 4 October 2024 |
| CVE-2024-43687 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | EXPLOITHIGH 7.7EPSS 0.83% | 4 October 2024 |
| CVE-2024-46626 | OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. | EXPLOITHIGH 8.8EPSS 0.88% | 2 October 2024 |
| CVE-2024-0132 | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. | EXPLOITHIGH 8.3EPSS 40.8% | 26 September 2024 |
| CVE-2024-23922 | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. | EXPLOITMEDIUM 6.8EPSS 1.76% | 23 September 2024 |
| CVE-2024-46987 | A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions). | EXPLOITHIGH 7.7EPSS 14.6% | 18 September 2024 |
| CVE-2024-8945 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. | EXPLOITMEDIUM 5.3EPSS 16.0% | 17 September 2024 |
| CVE-2024-8522 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping… | EXPLOITHIGH 7.5EPSS 62.9% | 12 September 2024 |
| CVE-2024-44541 | evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin." | EXPLOITCRITICAL 9.8EPSS 2.58% | 11 September 2024 |
| CVE-2024-44871 | An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. | EXPLOITHIGH 7.2EPSS 16.2% | 10 September 2024 |
| CVE-2024-42471 | Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains… | EXPLOITHIGH 7.5EPSS 3.22% | 2 September 2024 |
| CVE-2024-41358 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. | EXPLOITMEDIUM 6.1EPSS 1.59% | 29 August 2024 |
| CVE-2024-35133 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. | EXPLOITHIGH 8.2EPSS 1.76% | 29 August 2024 |
| CVE-2024-45440 | core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist. | EXPLOITMEDIUM 5.3EPSS 9.27% | 29 August 2024 |
| CVE-2024-28000 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | EXPLOITCRITICAL 9.8EPSS 68.3% | 21 August 2024 |
| CVE-2024-35540 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | EXPLOITCRITICAL 9.0EPSS 2.83% | 20 August 2024 |
| CVE-2024-35539 | Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. | EXPLOITMEDIUM 6.5EPSS 1.44% | 19 August 2024 |
| CVE-2024-7815 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. | EXPLOITMEDIUM 5.1EPSS 1.20% | 15 August 2024 |
| CVE-2024-38193 | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 28.5% | 13 August 2024 |
| CVE-2024-38200 | Microsoft Office Spoofing Vulnerability | EXPLOITMEDIUM 6.5EPSS 20.5% | 12 August 2024 |
| CVE-2024-36424 | K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference. | EXPLOITMEDIUM 5.5EPSS 0.99% | 6 August 2024 |
| CVE-2024-33896 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. | EXPLOITHIGH 7.2EPSS 4.02% | 2 August 2024 |
| CVE-2024-41947 | By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki… | EXPLOITMEDIUM 5.4EPSS 1.67% | 31 July 2024 |
| CVE-2024-42049 | TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection. | EXPLOITCRITICAL 9.1EPSS 2.15% | 28 July 2024 |
| CVE-2024-39304 | Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. | EXPLOITHIGH 8.8EPSS 2.98% | 26 July 2024 |
| CVE-2024-41357 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. | EXPLOITHIGH 7.1EPSS 1.12% | 26 July 2024 |
| CVE-2024-40422 | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. | EXPLOITCRITICAL 9.1EPSS 11.3% | 24 July 2024 |
| CVE-2024-38944 | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component. | EXPLOITCRITICAL 9.8EPSS 2.37% | 22 July 2024 |
| CVE-2024-6244 | The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | EXPLOITHIGH 8.8EPSS 2.84% | 22 July 2024 |
| CVE-2024-20419 | A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. | EXPLOITCRITICAL 10.0EPSS 80.6% | 17 July 2024 |
| CVE-2024-5910 | Palo Alto Networks Expedition Missing Authentication Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 91.8% | 10 July 2024 |
| CVE-2024-4879 | ServiceNow Improper Input Validation Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 100.0% | 10 July 2024 |
| CVE-2024-6298 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely | EXPLOITCRITICAL 9.4EPSS 19.0% | 5 July 2024 |
| CVE-2024-6209 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized | EXPLOITCRITICAL 9.4EPSS 17.2% | 5 July 2024 |
| CVE-2024-39930 | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. | EXPLOITCRITICAL 9.9EPSS 7.74% | 4 July 2024 |
| CVE-2024-39143 | A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload. | EXPLOITMEDIUM 5.4EPSS 0.93% | 2 July 2024 |
| CVE-2024-6387 | There is a race condition which can lead sshd to handle some signals in an unsafe manner. | EXPLOITHIGH 8.1EPSS 99.5% | 1 July 2024 |
| CVE-2024-4007 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | EXPLOITHIGH 8.7EPSS 1.51% | 1 July 2024 |
| CVE-2014-5470 | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation. | EXPLOIT ✓CRITICAL 9.8EPSS 10.0% | 21 June 2024 |
| CVE-2012-6664 | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. | EXPLOIT ✓CRITICAL 9.1EPSS 29.5% | 21 June 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.