Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 4 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 21 January 2026 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 42.0% | 20 January 2026 |
| CVE-2026-20963 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 32.6% | 13 January 2026 |
| CVE-2026-20805 | Microsoft Windows Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 5.19% | 13 January 2026 |
| CVE-2025-25249 | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 2.40% | 13 January 2026 |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 19.6% | 5 January 2026 |
| CVE-2025-52691 | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 85.7% | 29 December 2025 |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | KEVHIGH 8.8EPSS 49.4% | 22 December 2025 |
| CVE-2025-68613 | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability | KEVHIGH 8.8EPSS 99.1% | 19 December 2025 |
| CVE-2025-14847 | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | KEVHIGH 8.7EPSS 83.2% | 19 December 2025 |
| CVE-2025-14733 | WatchGuard Firebox Out of Bounds Write Vulnerability | KEVCRITICAL 9.3EPSS 26.5% | 19 December 2025 |
| CVE-2025-40602 | SonicWall SMA1000 Missing Authorization Vulnerability | KEVMEDIUM 6.6EPSS 2.08% | 18 December 2025 |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 26.8% | 18 December 2025 |
| CVE-2025-43529 | Apple Multiple Products Use-After-Free WebKit Vulnerability | KEVHIGH 8.8EPSS 8.76% | 17 December 2025 |
| CVE-2025-20393 | Cisco Multiple Products Improper Input Validation Vulnerability | KEVCRITICAL 10.0EPSS 29.9% | 17 December 2025 |
| CVE-2025-59374 | ASUS Live Update Embedded Malicious Code Vulnerability | KEVCRITICAL 9.3EPSS 1.20% | 17 December 2025 |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 90.2% | 16 December 2025 |
| CVE-2025-43520 | Apple Multiple Products Classic Buffer Overflow Vulnerability | KEVMEDIUM 5.5EPSS 0.43% | 12 December 2025 |
| CVE-2025-43510 | Apple Multiple Products Improper Locking Vulnerability | KEVHIGH 7.8EPSS 0.36% | 12 December 2025 |
| CVE-2025-14611 | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | KEVHIGH 7.1EPSS 53.3% | 12 December 2025 |
| CVE-2025-14174 | Google Chromium Out of Bounds Memory Access Vulnerability | KEVHIGH 8.8EPSS 22.3% | 12 December 2025 |
| CVE-2025-8110 | Gogs Path Traversal Vulnerability | KEVHIGH 8.7EPSS 82.5% | 10 December 2025 |
| CVE-2025-62221 | Microsoft Windows Use After Free Vulnerability | KEVHIGH 7.8EPSS 2.50% | 9 December 2025 |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | KEVCRITICAL 9.8EPSS 68.3% | 9 December 2025 |
| CVE-2025-48633 | Android Framework Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 0.26% | 8 December 2025 |
| CVE-2025-48572 | Android Framework Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 0.26% | 8 December 2025 |
| CVE-2025-34291 | Langflow Origin Validation Error Vulnerability | KEVCRITICAL 9.4EPSS 83.6% | 5 December 2025 |
| CVE-2025-66644 | Array Networks ArrayOS AG OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 3.42% | 5 December 2025 |
| CVE-2025-55182 | Meta React Server Components Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 3 December 2025 |
| CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | KEVCRITICAL 9.4EPSS 16.9% | 26 November 2025 |
| CVE-2025-58360 | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability | KEVCRITICAL 9.8EPSS 64.9% | 25 November 2025 |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 55.6% | 18 November 2025 |
| CVE-2025-13223 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 5.03% | 17 November 2025 |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 91.8% | 14 November 2025 |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability | KEVHIGH 7.0EPSS 5.99% | 11 November 2025 |
| CVE-2025-60710 | Microsoft Windows Link Following Vulnerability | KEVHIGH 7.8EPSS 4.60% | 11 November 2025 |
| CVE-2025-12480 | Gladinet Triofox Improper Access Control Vulnerability | KEVCRITICAL 9.1EPSS 90.5% | 10 November 2025 |
| CVE-2025-64328 | Sangoma FreePBX OS Command Injection Vulnerability | KEVHIGH 8.6EPSS 84.6% | 7 November 2025 |
| CVE-2023-43000 | Apple Multiple products Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 3.90% | 5 November 2025 |
| CVE-2025-11953 | React Native Community CLI OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.0% | 3 November 2025 |
| CVE-2025-61757 | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 88.3% | 21 October 2025 |
| CVE-2025-61932 | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability | KEVCRITICAL 9.3EPSS 2.63% | 20 October 2025 |
| CVE-2025-53521 | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.3EPSS 2.21% | 15 October 2025 |
| CVE-2025-59287 | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 14 October 2025 |
| CVE-2025-59230 | Microsoft Windows Improper Access Control Vulnerability | KEVHIGH 7.8EPSS 2.68% | 14 October 2025 |
| CVE-2025-24990 | Microsoft Windows Untrusted Pointer Dereference Vulnerability | KEVHIGH 7.8EPSS 6.37% | 14 October 2025 |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 7.5EPSS 95.9% | 12 October 2025 |
| CVE-2025-11371 | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | KEVHIGH 7.5EPSS 92.1% | 9 October 2025 |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 5 October 2025 |
| CVE-2025-41244 | Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability | KEVHIGH 7.8EPSS 8.44% | 29 September 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.