SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 8 of 501

CVESummaryPriorityPublished
CVE-2024-44000Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.EXPLOITCRITICAL 9.8EPSS 82.3%20 October 2024
CVE-2024-44762A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.EXPLOIT ×2MEDIUM 5.3EPSS 2.57%16 October 2024
CVE-2024-46528An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources…EXPLOITMEDIUM 4.3EPSS 1.58%14 October 2024
CVE-2024-48120X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.EXPLOITMEDIUM 5.4EPSS 0.64%14 October 2024
CVE-2024-48827An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.EXPLOITHIGH 8.8EPSS 2.79%11 October 2024
CVE-2024-42640angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php.EXPLOIT ×2CRITICAL 9.8EPSS 45.1%11 October 2024
CVE-2024-47773An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data.EXPLOITHIGH 8.2EPSS 1.66%8 October 2024
CVE-2024-42831A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at…EXPLOITMEDIUM 6.1EPSS 0.84%7 October 2024
CVE-2024-46278Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.EXPLOITHIGH 8.4EPSS 2.83%7 October 2024
CVE-2024-9054Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This…EXPLOITHIGH 8.5EPSS 15.6%4 October 2024
CVE-2024-7801Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.EXPLOITMEDIUM 6.3EPSS 0.84%4 October 2024
CVE-2024-43687Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.EXPLOITHIGH 7.7EPSS 0.83%4 October 2024
CVE-2024-46626OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.EXPLOITHIGH 8.8EPSS 0.88%2 October 2024
CVE-2024-0132NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system.EXPLOITHIGH 8.3EPSS 40.8%26 September 2024
CVE-2024-23922Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability.EXPLOITMEDIUM 6.8EPSS 1.76%23 September 2024
CVE-2024-46987A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions).EXPLOITHIGH 7.7EPSS 14.6%18 September 2024
CVE-2024-8945A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical.EXPLOITMEDIUM 5.3EPSS 16.0%17 September 2024
CVE-2024-8522The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping…EXPLOITHIGH 7.5EPSS 62.9%12 September 2024
CVE-2024-44541evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."EXPLOITCRITICAL 9.8EPSS 2.58%11 September 2024
CVE-2024-44871An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.EXPLOITHIGH 7.2EPSS 16.2%10 September 2024
CVE-2024-42471Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains…EXPLOITHIGH 7.5EPSS 3.22%2 September 2024
CVE-2024-41358phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.EXPLOITMEDIUM 6.1EPSS 1.59%29 August 2024
CVE-2024-35133IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack.EXPLOITHIGH 8.2EPSS 1.76%29 August 2024
CVE-2024-45440core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.EXPLOITMEDIUM 5.3EPSS 9.27%29 August 2024
CVE-2024-28000Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.EXPLOITCRITICAL 9.8EPSS 68.3%21 August 2024
CVE-2024-35540A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.EXPLOITCRITICAL 9.0EPSS 2.83%20 August 2024
CVE-2024-35539Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function.EXPLOITMEDIUM 6.5EPSS 1.44%19 August 2024
CVE-2024-7815A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic.EXPLOITMEDIUM 5.1EPSS 1.20%15 August 2024
CVE-2024-38193Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 28.5%13 August 2024
CVE-2024-38200Microsoft Office Spoofing VulnerabilityEXPLOITMEDIUM 6.5EPSS 20.5%12 August 2024
CVE-2024-36424K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.EXPLOITMEDIUM 5.5EPSS 0.99%6 August 2024
CVE-2024-33896Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting.EXPLOITHIGH 7.2EPSS 4.02%2 August 2024
CVE-2024-41947By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki…EXPLOITMEDIUM 5.4EPSS 1.67%31 July 2024
CVE-2024-42049TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.EXPLOITCRITICAL 9.1EPSS 2.15%28 July 2024
CVE-2024-39304Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input.EXPLOITHIGH 8.8EPSS 2.98%26 July 2024
CVE-2024-41357phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.EXPLOITHIGH 7.1EPSS 1.12%26 July 2024
CVE-2024-40422The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack.EXPLOITCRITICAL 9.1EPSS 11.3%24 July 2024
CVE-2024-38944An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.EXPLOITCRITICAL 9.8EPSS 2.37%22 July 2024
CVE-2024-6244The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacksEXPLOITHIGH 8.8EPSS 2.84%22 July 2024
CVE-2024-20419A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.EXPLOITCRITICAL 10.0EPSS 80.6%17 July 2024
CVE-2024-5910Palo Alto Networks Expedition Missing Authentication VulnerabilityKEVEXPLOITCRITICAL 9.3EPSS 91.8%10 July 2024
CVE-2024-4879ServiceNow Improper Input Validation VulnerabilityKEVEXPLOITCRITICAL 9.3EPSS 100.0%10 July 2024
CVE-2024-6298Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotelyEXPLOITCRITICAL 9.4EPSS 19.0%5 July 2024
CVE-2024-6209Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorizedEXPLOITCRITICAL 9.4EPSS 17.2%5 July 2024
CVE-2024-39930The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.EXPLOITCRITICAL 9.9EPSS 7.74%4 July 2024
CVE-2024-39143A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.EXPLOITMEDIUM 5.4EPSS 0.93%2 July 2024
CVE-2024-6387There is a race condition which can lead sshd to handle some signals in an unsafe manner.EXPLOITHIGH 8.1EPSS 99.5%1 July 2024
CVE-2024-4007Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.EXPLOITHIGH 8.7EPSS 1.51%1 July 2024
CVE-2014-5470Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.EXPLOITCRITICAL 9.8EPSS 10.0%21 June 2024
CVE-2012-6664Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a ..EXPLOITCRITICAL 9.1EPSS 29.5%21 June 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.