Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 11 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-0769 | D-Link DIR-859 Router Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 82.7% | 21 January 2024 |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | KEVHIGH 7.5EPSS 57.6% | 17 January 2024 |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | KEVHIGH 8.8EPSS 3.19% | 17 January 2024 |
| CVE-2024-0519 | Google Chromium V8 Out-of-Bounds Memory Access Vulnerability | KEVHIGH 8.8EPSS 3.80% | 16 January 2024 |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 16 January 2024 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 12 January 2024 |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | KEVHIGH 8.2EPSS 100.0% | 12 January 2024 |
| CVE-2023-7028 | GitLab Community and Enterprise Editions Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 94.6% | 12 January 2024 |
| CVE-2023-41974 | Apple iOS and iPadOS Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.40% | 10 January 2024 |
| CVE-2022-48618 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.0EPSS 0.49% | 9 January 2024 |
| CVE-2022-2586 | Linux Kernel Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 10.5% | 8 January 2024 |
| CVE-2023-7101 | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 19.1% | 24 December 2023 |
| CVE-2023-7024 | Google Chromium WebRTC Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 7.36% | 21 December 2023 |
| CVE-2023-47565 | QNAP VioStor NVR OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 73.3% | 8 December 2023 |
| CVE-2023-49897 | FXC AE1021, AE1021PE OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 50.4% | 6 December 2023 |
| CVE-2023-44221 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 76.3% | 5 December 2023 |
| CVE-2023-6448 | Unitronics Vision PLC and HMI Insecure Default Password Vulnerability | KEVCRITICAL 9.8EPSS 2.07% | 5 December 2023 |
| CVE-2023-33107 | Qualcomm Multiple Chipsets Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 0.89% | 5 December 2023 |
| CVE-2023-33106 | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability | KEVHIGH 7.8EPSS 0.92% | 5 December 2023 |
| CVE-2023-33063 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.70% | 5 December 2023 |
| CVE-2023-42917 | Apple Multiple Products WebKit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 9.37% | 30 November 2023 |
| CVE-2023-42916 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | KEVMEDIUM 6.5EPSS 17.8% | 30 November 2023 |
| CVE-2023-6345 | Google Skia Integer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 16.5% | 29 November 2023 |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 43.2% | 21 November 2023 |
| CVE-2023-49103 | ownCloud graphapi Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 78.4% | 21 November 2023 |
| CVE-2023-48365 | Qlik Sense HTTP Tunneling Vulnerability | KEVCRITICAL 9.9EPSS 24.5% | 15 November 2023 |
| CVE-2023-36424 | Microsoft Windows Out-of-Bounds Read Vulnerability | KEVHIGH 7.8EPSS 12.2% | 14 November 2023 |
| CVE-2023-36036 | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 16.7% | 14 November 2023 |
| CVE-2023-36033 | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 12.0% | 14 November 2023 |
| CVE-2023-36025 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVHIGH 8.8EPSS 88.1% | 14 November 2023 |
| CVE-2023-47246 | SysAid Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 98.9% | 10 November 2023 |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 31 October 2023 |
| CVE-2023-46604 | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 27 October 2023 |
| CVE-2023-46748 | F5 BIG-IP Configuration Utility SQL Injection Vulnerability | KEVHIGH 8.8EPSS 4.47% | 26 October 2023 |
| CVE-2023-46747 | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 96.5% | 26 October 2023 |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 82.7% | 26 October 2023 |
| CVE-2023-34048 | VMware vCenter Server Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 25 October 2023 |
| CVE-2023-20273 | Cisco IOS XE Web UI Command Injection Vulnerability | KEVHIGH 7.2EPSS 89.6% | 25 October 2023 |
| CVE-2023-5631 | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 5.4EPSS 75.9% | 18 October 2023 |
| CVE-2023-45727 | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability | KEVHIGH 7.5EPSS 3.54% | 18 October 2023 |
| CVE-2023-20198 | Cisco IOS XE Web UI Privilege Escalation Vulnerability | KEVCRITICAL 10.0EPSS 99.6% | 16 October 2023 |
| CVE-2023-41763 | Microsoft Skype for Business Privilege Escalation Vulnerability | KEVMEDIUM 5.3EPSS 90.4% | 10 October 2023 |
| CVE-2023-36584 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | KEVMEDIUM 5.4EPSS 3.06% | 10 October 2023 |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 20.7% | 10 October 2023 |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-44487 | HTTP/2 Rapid Reset Attack Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-42824 | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 0.94% | 4 October 2023 |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 4 October 2023 |
| CVE-2023-4911 | GNU C Library Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 81.4% | 3 October 2023 |
| CVE-2023-4211 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | KEVMEDIUM 5.5EPSS 1.10% | 1 October 2023 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.