SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 10 of 35

CVESummaryPriorityPublished
CVE-2024-4577PHP-CGI OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%9 June 2024
CVE-2024-4610Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.76%7 June 2024
CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 73.3%7 June 2024
CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability KEVHIGH 7.5EPSS 99.6%6 June 2024
CVE-2024-29824Ivanti Endpoint Manager (EPM) SQL Injection VulnerabilityKEVHIGH 8.8EPSS 100.0%31 May 2024
CVE-2024-23692Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityKEVCRITICAL 9.8EPSS 99.5%31 May 2024
CVE-2024-4358Progress Telerik Report Server Authentication Bypass by Spoofing VulnerabilityKEVCRITICAL 9.8EPSS 97.5%29 May 2024
CVE-2024-24919Check Point Quantum Security Gateways Information Disclosure VulnerabilityKEVHIGH 8.6EPSS 100.0%28 May 2024
CVE-2024-5274Google Chromium V8 Type Confusion VulnerabilityKEVCRITICAL 9.6EPSS 7.47%28 May 2024
CVE-2024-4978Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code VulnerabilityKEVHIGH 8.7EPSS 26.9%23 May 2024
CVE-2024-4947Google Chromium V8 Type Confusion VulnerabilityKEVCRITICAL 9.6EPSS 15.2%15 May 2024
CVE-2024-30051 Microsoft DWM Core Library Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 5.64%14 May 2024
CVE-2024-30040Microsoft Windows MSHTML Platform Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 3.94%14 May 2024
CVE-2024-4761Google Chromium V8 Out-of-Bounds Memory Write VulnerabilityKEVHIGH 8.8EPSS 11.0%14 May 2024
CVE-2024-4671Google Chromium Visuals Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 8.35%14 May 2024
CVE-2024-32113Apache OFBiz Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 99.4%8 May 2024
CVE-2023-50224TP-Link TL-WR841N Authentication Bypass by Spoofing VulnerabilityKEVMEDIUM 6.5EPSS 15.6%3 May 2024
CVE-2024-20359Cisco ASA and FTD Privilege Escalation VulnerabilityKEVMEDIUM 6.0EPSS 19.4%24 April 2024
CVE-2024-20353Cisco ASA and FTD Denial of Service VulnerabilityKEVHIGH 8.6EPSS 70.7%24 April 2024
CVE-2024-4040CrushFTP VFS Sandbox Escape VulnerabilityKEVCRITICAL 10.0EPSS 99.5%22 April 2024
CVE-2024-27348Apache HugeGraph-Server Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 99.2%22 April 2024
CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityKEVCRITICAL 10.0EPSS 100.0%12 April 2024
CVE-2024-29988Microsoft SmartScreen Prompt Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 44.9%9 April 2024
CVE-2024-29748Android Pixel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 0.67%5 April 2024
CVE-2024-29745Android Pixel Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 0.48%5 April 2024
CVE-2024-3273D-Link Multiple NAS Devices Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%4 April 2024
CVE-2024-3272D-Link Multiple NAS Devices Use of Hard-Coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 98.0%4 April 2024
CVE-2024-29059Microsoft .NET Framework Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 98.6%23 March 2024
CVE-2024-20767Adobe ColdFusion Improper Access Control VulnerabilityKEVHIGH 7.4EPSS 98.5%18 March 2024
CVE-2024-26169Microsoft Windows Error Reporting Service Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 4.01%12 March 2024
CVE-2023-48788Fortinet FortiClient EMS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.4%12 March 2024
CVE-2024-23296Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 1.41%5 March 2024
CVE-2024-23225Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 1.48%5 March 2024
CVE-2024-27199JetBrains TeamCity Relative Path Traversal VulnerabilityKEVHIGH 7.3EPSS 100.0%4 March 2024
CVE-2024-27198JetBrains TeamCity Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.9%4 March 2024
CVE-2024-1212Progress Kemp LoadMaster OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 95.4%21 February 2024
CVE-2024-1709ConnectWise ScreenConnect Authentication Bypass VulnerabilityKEVCRITICAL 10.0EPSS 100.0%21 February 2024
CVE-2024-1708ConnectWise ScreenConnect Path Traversal VulnerabilityKEVHIGH 8.4EPSS 95.5%21 February 2024
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) Deserialization VulnerabilityKEVHIGH 8.8EPSS 3.93%17 February 2024
CVE-2024-23113Fortinet Multiple Products Format String VulnerabilityKEVCRITICAL 9.8EPSS 61.7%15 February 2024
CVE-2024-21413Microsoft Outlook Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 94.7%13 February 2024
CVE-2024-21412Microsoft Windows Internet Shortcut Files Security Feature Bypass VulnerabilityKEVHIGH 8.1EPSS 95.4%13 February 2024
CVE-2024-21410Microsoft Exchange Server Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 12.6%13 February 2024
CVE-2024-21351Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVHIGH 7.6EPSS 30.3%13 February 2024
CVE-2024-21338Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control VulnerabilityKEVHIGH 7.8EPSS 59.8%13 February 2024
CVE-2024-21762Fortinet FortiOS Out-of-Bound Write VulnerabilityKEVCRITICAL 9.8EPSS 84.3%9 February 2024
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 8.2EPSS 100.0%31 January 2024
CVE-2024-1086Linux Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 28.1%31 January 2024
CVE-2024-23897Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%24 January 2024
CVE-2024-23222Apple Multiple Products WebKit Type Confusion VulnerabilityKEVHIGH 8.8EPSS 10.6%23 January 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.