Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 9 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-28397 | An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. | EXPLOITMEDIUM 5.3EPSS 4.55% | 20 June 2024 |
| CVE-2024-6039 | A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. | EXPLOITMEDIUM 5.3EPSS 0.73% | 16 June 2024 |
| CVE-2023-27636 | Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | EXPLOITMEDIUM 5.4EPSS 1.29% | 16 June 2024 |
| CVE-2024-31777 | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint. | EXPLOITCRITICAL 9.8EPSS 3.82% | 13 June 2024 |
| CVE-2024-4577 | PHP-CGI OS Command Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 9 June 2024 |
| CVE-2024-37383 | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVEXPLOITMEDIUM 6.1EPSS 73.3% | 7 June 2024 |
| CVE-2024-28995 | SolarWinds Serv-U Path Traversal Vulnerability | KEVEXPLOITHIGH 7.5EPSS 99.6% | 6 June 2024 |
| CVE-2024-28999 | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | EXPLOITHIGH 7.5EPSS 13.9% | 4 June 2024 |
| CVE-2024-25600 | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6. | EXPLOITCRITICAL 10.0EPSS 88.2% | 4 June 2024 |
| CVE-2024-23692 | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.5% | 31 May 2024 |
| CVE-2024-4358 | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 97.5% | 29 May 2024 |
| CVE-2024-34241 | A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications. | EXPLOITMEDIUM 4.8EPSS 0.76% | 17 May 2024 |
| CVE-2024-4956 | Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. | EXPLOITHIGH 7.5EPSS 18.2% | 16 May 2024 |
| CVE-2024-4367 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. | EXPLOITHIGH 8.8EPSS 70.7% | 14 May 2024 |
| CVE-2024-25641 | Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. | EXPLOITHIGH 7.2EPSS 86.3% | 14 May 2024 |
| CVE-2024-32113 | Apache OFBiz Path Traversal Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.4% | 8 May 2024 |
| CVE-2024-31621 | An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. | EXPLOITHIGH 7.6EPSS 59.9% | 29 April 2024 |
| CVE-2024-33559 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5. | EXPLOITCRITICAL 9.3EPSS 3.55% | 29 April 2024 |
| CVE-2024-31804 | An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component. | EXPLOITMEDIUM 6.7EPSS 0.68% | 23 April 2024 |
| CVE-2024-27348 | Apache HugeGraph-Server Improper Access Control Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.2% | 22 April 2024 |
| CVE-2024-29291 | An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. | EXPLOITUnscoredEPSS 1.34% | 16 April 2024 |
| CVE-2024-21111 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | EXPLOITHIGH 7.8EPSS 1.78% | 16 April 2024 |
| CVE-2024-0399 | The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role. | EXPLOITHIGH 8.1EPSS 2.88% | 15 April 2024 |
| CVE-2024-3400 | Palo Alto Networks PAN-OS Command Injection Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 100.0% | 12 April 2024 |
| CVE-2024-30269 | DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. | EXPLOITMEDIUM 5.3EPSS 15.9% | 8 April 2024 |
| CVE-2024-27620 | An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API. | EXPLOITHIGH 7.5EPSS 2.34% | 6 April 2024 |
| CVE-2024-24724 | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization. | EXPLOITCRITICAL 9.8EPSS 26.1% | 3 April 2024 |
| CVE-2024-25736 | Remote attackers can restart the device via a /device/reboot GET request. | EXPLOITHIGH 7.5EPSS 4.34% | 27 March 2024 |
| CVE-2024-25735 | Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request. | EXPLOITCRITICAL 9.1EPSS 50.6% | 27 March 2024 |
| CVE-2024-25734 | The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts. | EXPLOITHIGH 7.5EPSS 4.05% | 27 March 2024 |
| CVE-2024-2054 | The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. | EXPLOITCRITICAL 9.8EPSS 81.3% | 21 March 2024 |
| CVE-2024-28595 | SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php. | EXPLOITCRITICAL 9.8EPSS 1.23% | 19 March 2024 |
| CVE-2023-40279 | An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do. | EXPLOITHIGH 7.5EPSS 3.38% | 19 March 2024 |
| CVE-2023-40278 | An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. | EXPLOITHIGH 7.5EPSS 3.00% | 19 March 2024 |
| CVE-2024-20767 | Adobe ColdFusion Improper Access Control Vulnerability | KEVEXPLOITHIGH 7.4EPSS 98.5% | 18 March 2024 |
| CVE-2024-22513 | djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. | EXPLOITMEDIUM 5.5EPSS 0.80% | 16 March 2024 |
| CVE-2024-1234 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. | EXPLOITMEDIUM 5.4EPSS 1.59% | 13 March 2024 |
| CVE-2024-28623 | RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section. | EXPLOITMEDIUM 6.1EPSS 1.32% | 13 March 2024 |
| CVE-2024-27612 | Numbas editor before 7.3 mishandles editing of themes and extensions. | EXPLOITMEDIUM 6.2EPSS 10.7% | 8 March 2024 |
| CVE-2024-27198 | JetBrains TeamCity Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 4 March 2024 |
| CVE-2024-27747 | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | EXPLOITCRITICAL 9.8EPSS 23.6% | 1 March 2024 |
| CVE-2024-27746 | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | EXPLOITCRITICAL 9.8EPSS 12.9% | 1 March 2024 |
| CVE-2024-27744 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component. | EXPLOITMEDIUM 6.1EPSS 1.33% | 1 March 2024 |
| CVE-2024-27743 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component. | EXPLOITMEDIUM 6.1EPSS 1.31% | 1 March 2024 |
| CVE-2024-25832 | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | EXPLOITHIGH 8.8EPSS 12.8% | 29 February 2024 |
| CVE-2024-25830 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. | EXPLOITCRITICAL 9.8EPSS 24.0% | 29 February 2024 |
| CVE-2024-27356 | Attackers can download files such as logs via commands, potentially obtaining critical user information. | EXPLOITHIGH 7.5EPSS 23.9% | 27 February 2024 |
| CVE-2024-23346 | A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. | EXPLOITHIGH 7.8EPSS 3.82% | 21 February 2024 |
| CVE-2024-21338 | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | KEVEXPLOIT ×2HIGH 7.8EPSS 59.8% | 13 February 2024 |
| CVE-2024-0566 | The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | EXPLOITHIGH 7.2EPSS 3.30% | 12 February 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.