Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 10 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-4577 | PHP-CGI OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 9 June 2024 |
| CVE-2024-4610 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.76% | 7 June 2024 |
| CVE-2024-37383 | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 73.3% | 7 June 2024 |
| CVE-2024-28995 | SolarWinds Serv-U Path Traversal Vulnerability | KEVHIGH 7.5EPSS 99.6% | 6 June 2024 |
| CVE-2024-29824 | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 31 May 2024 |
| CVE-2024-23692 | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 31 May 2024 |
| CVE-2024-4358 | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | KEVCRITICAL 9.8EPSS 97.5% | 29 May 2024 |
| CVE-2024-24919 | Check Point Quantum Security Gateways Information Disclosure Vulnerability | KEVHIGH 8.6EPSS 100.0% | 28 May 2024 |
| CVE-2024-5274 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.6EPSS 7.47% | 28 May 2024 |
| CVE-2024-4978 | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | KEVHIGH 8.7EPSS 26.9% | 23 May 2024 |
| CVE-2024-4947 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.6EPSS 15.2% | 15 May 2024 |
| CVE-2024-30051 | Microsoft DWM Core Library Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.64% | 14 May 2024 |
| CVE-2024-30040 | Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 3.94% | 14 May 2024 |
| CVE-2024-4761 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | KEVHIGH 8.8EPSS 11.0% | 14 May 2024 |
| CVE-2024-4671 | Google Chromium Visuals Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 8.35% | 14 May 2024 |
| CVE-2024-32113 | Apache OFBiz Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 8 May 2024 |
| CVE-2023-50224 | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | KEVMEDIUM 6.5EPSS 15.6% | 3 May 2024 |
| CVE-2024-20359 | Cisco ASA and FTD Privilege Escalation Vulnerability | KEVMEDIUM 6.0EPSS 19.4% | 24 April 2024 |
| CVE-2024-20353 | Cisco ASA and FTD Denial of Service Vulnerability | KEVHIGH 8.6EPSS 70.7% | 24 April 2024 |
| CVE-2024-4040 | CrushFTP VFS Sandbox Escape Vulnerability | KEVCRITICAL 10.0EPSS 99.5% | 22 April 2024 |
| CVE-2024-27348 | Apache HugeGraph-Server Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 22 April 2024 |
| CVE-2024-3400 | Palo Alto Networks PAN-OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 12 April 2024 |
| CVE-2024-29988 | Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 44.9% | 9 April 2024 |
| CVE-2024-29748 | Android Pixel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 0.67% | 5 April 2024 |
| CVE-2024-29745 | Android Pixel Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 0.48% | 5 April 2024 |
| CVE-2024-3273 | D-Link Multiple NAS Devices Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 April 2024 |
| CVE-2024-3272 | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 4 April 2024 |
| CVE-2024-29059 | Microsoft .NET Framework Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 98.6% | 23 March 2024 |
| CVE-2024-20767 | Adobe ColdFusion Improper Access Control Vulnerability | KEVHIGH 7.4EPSS 98.5% | 18 March 2024 |
| CVE-2024-26169 | Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 4.01% | 12 March 2024 |
| CVE-2023-48788 | Fortinet FortiClient EMS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.4% | 12 March 2024 |
| CVE-2024-23296 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 1.41% | 5 March 2024 |
| CVE-2024-23225 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 1.48% | 5 March 2024 |
| CVE-2024-27199 | JetBrains TeamCity Relative Path Traversal Vulnerability | KEVHIGH 7.3EPSS 100.0% | 4 March 2024 |
| CVE-2024-27198 | JetBrains TeamCity Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 4 March 2024 |
| CVE-2024-1212 | Progress Kemp LoadMaster OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 95.4% | 21 February 2024 |
| CVE-2024-1709 | ConnectWise ScreenConnect Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 21 February 2024 |
| CVE-2024-1708 | ConnectWise ScreenConnect Path Traversal Vulnerability | KEVHIGH 8.4EPSS 95.5% | 21 February 2024 |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability | KEVHIGH 8.8EPSS 3.93% | 17 February 2024 |
| CVE-2024-23113 | Fortinet Multiple Products Format String Vulnerability | KEVCRITICAL 9.8EPSS 61.7% | 15 February 2024 |
| CVE-2024-21413 | Microsoft Outlook Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 94.7% | 13 February 2024 |
| CVE-2024-21412 | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | KEVHIGH 8.1EPSS 95.4% | 13 February 2024 |
| CVE-2024-21410 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 12.6% | 13 February 2024 |
| CVE-2024-21351 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVHIGH 7.6EPSS 30.3% | 13 February 2024 |
| CVE-2024-21338 | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | KEVHIGH 7.8EPSS 59.8% | 13 February 2024 |
| CVE-2024-21762 | Fortinet FortiOS Out-of-Bound Write Vulnerability | KEVCRITICAL 9.8EPSS 84.3% | 9 February 2024 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 8.2EPSS 100.0% | 31 January 2024 |
| CVE-2024-1086 | Linux Kernel Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 28.1% | 31 January 2024 |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 24 January 2024 |
| CVE-2024-23222 | Apple Multiple Products WebKit Type Confusion Vulnerability | KEVHIGH 8.8EPSS 10.6% | 23 January 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.