SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 9 of 501

CVESummaryPriorityPublished
CVE-2024-28397An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.EXPLOITMEDIUM 5.3EPSS 4.55%20 June 2024
CVE-2024-6039A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2.EXPLOITMEDIUM 5.3EPSS 0.73%16 June 2024
CVE-2023-27636Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.EXPLOITMEDIUM 5.4EPSS 1.29%16 June 2024
CVE-2024-31777File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.EXPLOITCRITICAL 9.8EPSS 3.82%13 June 2024
CVE-2024-4577PHP-CGI OS Command Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%9 June 2024
CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS) VulnerabilityKEVEXPLOITMEDIUM 6.1EPSS 73.3%7 June 2024
CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability KEVEXPLOITHIGH 7.5EPSS 99.6%6 June 2024
CVE-2024-28999The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.EXPLOITHIGH 7.5EPSS 13.9%4 June 2024
CVE-2024-25600Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.EXPLOITCRITICAL 10.0EPSS 88.2%4 June 2024
CVE-2024-23692Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.5%31 May 2024
CVE-2024-4358Progress Telerik Report Server Authentication Bypass by Spoofing VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 97.5%29 May 2024
CVE-2024-34241A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.EXPLOITMEDIUM 4.8EPSS 0.76%17 May 2024
CVE-2024-4956Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files.EXPLOITHIGH 7.5EPSS 18.2%16 May 2024
CVE-2024-4367A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.EXPLOITHIGH 8.8EPSS 70.7%14 May 2024
CVE-2024-25641Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server.EXPLOITHIGH 7.2EPSS 86.3%14 May 2024
CVE-2024-32113Apache OFBiz Path Traversal VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.4%8 May 2024
CVE-2024-31621An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.EXPLOITHIGH 7.6EPSS 59.9%29 April 2024
CVE-2024-33559Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.EXPLOITCRITICAL 9.3EPSS 3.55%29 April 2024
CVE-2024-31804An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.EXPLOITMEDIUM 6.7EPSS 0.68%23 April 2024
CVE-2024-27348Apache HugeGraph-Server Improper Access Control VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.2%22 April 2024
CVE-2024-29291An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log.EXPLOITUnscoredEPSS 1.34%16 April 2024
CVE-2024-21111Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).EXPLOITHIGH 7.8EPSS 1.78%16 April 2024
CVE-2024-0399The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.EXPLOITHIGH 8.1EPSS 2.88%15 April 2024
CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 100.0%12 April 2024
CVE-2024-30269DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0.EXPLOITMEDIUM 5.3EPSS 15.9%8 April 2024
CVE-2024-27620An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.EXPLOITHIGH 7.5EPSS 2.34%6 April 2024
CVE-2024-24724Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.EXPLOITCRITICAL 9.8EPSS 26.1%3 April 2024
CVE-2024-25736Remote attackers can restart the device via a /device/reboot GET request.EXPLOITHIGH 7.5EPSS 4.34%27 March 2024
CVE-2024-25735Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.EXPLOITCRITICAL 9.1EPSS 50.6%27 March 2024
CVE-2024-25734The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.EXPLOITHIGH 7.5EPSS 4.05%27 March 2024
CVE-2024-2054The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.EXPLOITCRITICAL 9.8EPSS 81.3%21 March 2024
CVE-2024-28595SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.EXPLOITCRITICAL 9.8EPSS 1.23%19 March 2024
CVE-2023-40279An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.EXPLOITHIGH 7.5EPSS 3.38%19 March 2024
CVE-2023-40278An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA.EXPLOITHIGH 7.5EPSS 3.00%19 March 2024
CVE-2024-20767Adobe ColdFusion Improper Access Control VulnerabilityKEVEXPLOITHIGH 7.4EPSS 98.5%18 March 2024
CVE-2024-22513djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure.EXPLOITMEDIUM 5.5EPSS 0.80%16 March 2024
CVE-2024-1234The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping.EXPLOITMEDIUM 5.4EPSS 1.59%13 March 2024
CVE-2024-28623RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.EXPLOITMEDIUM 6.1EPSS 1.32%13 March 2024
CVE-2024-27612Numbas editor before 7.3 mishandles editing of themes and extensions.EXPLOITMEDIUM 6.2EPSS 10.7%8 March 2024
CVE-2024-27198JetBrains TeamCity Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%4 March 2024
CVE-2024-27747File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.EXPLOITCRITICAL 9.8EPSS 23.6%1 March 2024
CVE-2024-27746SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.EXPLOITCRITICAL 9.8EPSS 12.9%1 March 2024
CVE-2024-27744Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.EXPLOITMEDIUM 6.1EPSS 1.33%1 March 2024
CVE-2024-27743Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.EXPLOITMEDIUM 6.1EPSS 1.31%1 March 2024
CVE-2024-25832F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.EXPLOITHIGH 8.8EPSS 12.8%29 February 2024
CVE-2024-25830F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.EXPLOITCRITICAL 9.8EPSS 24.0%29 February 2024
CVE-2024-27356Attackers can download files such as logs via commands, potentially obtaining critical user information.EXPLOITHIGH 7.5EPSS 23.9%27 February 2024
CVE-2024-23346A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20.EXPLOITHIGH 7.8EPSS 3.82%21 February 2024
CVE-2024-21338Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 59.8%13 February 2024
CVE-2024-0566The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.EXPLOITHIGH 7.2EPSS 3.30%12 February 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.