SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 11 of 35

CVESummaryPriorityPublished
CVE-2024-0769 D-Link DIR-859 Router Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 82.7%21 January 2024
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 57.6%17 January 2024
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityKEVHIGH 8.8EPSS 3.19%17 January 2024
CVE-2024-0519Google Chromium V8 Out-of-Bounds Memory Access VulnerabilityKEVHIGH 8.8EPSS 3.80%16 January 2024
CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%16 January 2024
CVE-2024-21887Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityKEVCRITICAL 9.1EPSS 100.0%12 January 2024
CVE-2023-46805Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityKEVHIGH 8.2EPSS 100.0%12 January 2024
CVE-2023-7028GitLab Community and Enterprise Editions Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 94.6%12 January 2024
CVE-2023-41974Apple iOS and iPadOS Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 1.40%10 January 2024
CVE-2022-48618Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.0EPSS 0.49%9 January 2024
CVE-2022-2586Linux Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 10.5%8 January 2024
CVE-2023-7101Spreadsheet::ParseExcel Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 19.1%24 December 2023
CVE-2023-7024Google Chromium WebRTC Heap Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 7.36%21 December 2023
CVE-2023-47565QNAP VioStor NVR OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 73.3%8 December 2023
CVE-2023-49897FXC AE1021, AE1021PE OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 50.4%6 December 2023
CVE-2023-44221SonicWall SMA100 Appliances OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 76.3%5 December 2023
CVE-2023-6448Unitronics Vision PLC and HMI Insecure Default Password VulnerabilityKEVCRITICAL 9.8EPSS 2.07%5 December 2023
CVE-2023-33107Qualcomm Multiple Chipsets Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 0.89%5 December 2023
CVE-2023-33106Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset VulnerabilityKEVHIGH 7.8EPSS 0.92%5 December 2023
CVE-2023-33063Qualcomm Multiple Chipsets Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.70%5 December 2023
CVE-2023-42917Apple Multiple Products WebKit Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 9.37%30 November 2023
CVE-2023-42916Apple Multiple Products WebKit Out-of-Bounds Read VulnerabilityKEVMEDIUM 6.5EPSS 17.8%30 November 2023
CVE-2023-6345Google Skia Integer Overflow VulnerabilityKEVCRITICAL 9.6EPSS 16.5%29 November 2023
CVE-2023-49105ownCloud Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 43.2%21 November 2023
CVE-2023-49103ownCloud graphapi Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 78.4%21 November 2023
CVE-2023-48365Qlik Sense HTTP Tunneling VulnerabilityKEVCRITICAL 9.9EPSS 24.5%15 November 2023
CVE-2023-36424Microsoft Windows Out-of-Bounds Read VulnerabilityKEVHIGH 7.8EPSS 12.2%14 November 2023
CVE-2023-36036Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 16.7%14 November 2023
CVE-2023-36033Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 12.0%14 November 2023
CVE-2023-36025Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 88.1%14 November 2023
CVE-2023-47246SysAid Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 98.9%10 November 2023
CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityKEVCRITICAL 9.8EPSS 100.0%31 October 2023
CVE-2023-46604Apache ActiveMQ Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 99.7%27 October 2023
CVE-2023-46748F5 BIG-IP Configuration Utility SQL Injection VulnerabilityKEVHIGH 8.8EPSS 4.47%26 October 2023
CVE-2023-46747F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 96.5%26 October 2023
CVE-2023-43208NextGen Healthcare Mirth Connect Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 82.7%26 October 2023
CVE-2023-34048VMware vCenter Server Out-of-Bounds Write VulnerabilityKEVCRITICAL 9.8EPSS 99.4%25 October 2023
CVE-2023-20273Cisco IOS XE Web UI Command Injection VulnerabilityKEVHIGH 7.2EPSS 89.6%25 October 2023
CVE-2023-5631Roundcube Webmail Persistent Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 5.4EPSS 75.9%18 October 2023
CVE-2023-45727North Grid Proself Improper Restriction of XML External Entity (XXE) Reference VulnerabilityKEVHIGH 7.5EPSS 3.54%18 October 2023
CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation VulnerabilityKEVCRITICAL 10.0EPSS 99.6%16 October 2023
CVE-2023-41763Microsoft Skype for Business Privilege Escalation VulnerabilityKEVMEDIUM 5.3EPSS 90.4%10 October 2023
CVE-2023-36584Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass VulnerabilityKEVMEDIUM 5.4EPSS 3.06%10 October 2023
CVE-2023-36563Microsoft WordPad Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 20.7%10 October 2023
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-44487HTTP/2 Rapid Reset Attack VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-42824Apple iOS and iPadOS Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 0.94%4 October 2023
CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityKEVCRITICAL 9.8EPSS 99.2%4 October 2023
CVE-2023-4911GNU C Library Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 81.4%3 October 2023
CVE-2023-4211Arm Mali GPU Kernel Driver Use-After-Free VulnerabilityKEVMEDIUM 5.5EPSS 1.10%1 October 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.