SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 4 of 35

CVESummaryPriorityPublished
CVE-2026-24061GNU InetUtils Argument Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.0%21 January 2026
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityKEVCRITICAL 10.0EPSS 42.0%20 January 2026
CVE-2026-20963Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 32.6%13 January 2026
CVE-2026-20805Microsoft Windows Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 5.19%13 January 2026
CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 2.40%13 January 2026
CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting VulnerabilityKEVMEDIUM 6.1EPSS 19.6%5 January 2026
CVE-2025-52691SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type VulnerabilityKEVCRITICAL 10.0EPSS 85.7%29 December 2025
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion VulnerabilityKEVHIGH 8.8EPSS 49.4%22 December 2025
CVE-2025-68613n8n Improper Control of Dynamically-Managed Code Resources VulnerabilityKEVHIGH 8.8EPSS 99.1%19 December 2025
CVE-2025-14847MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency VulnerabilityKEVHIGH 8.7EPSS 83.2%19 December 2025
CVE-2025-14733WatchGuard Firebox Out of Bounds Write VulnerabilityKEVCRITICAL 9.3EPSS 26.5%19 December 2025
CVE-2025-40602SonicWall SMA1000 Missing Authorization VulnerabilityKEVMEDIUM 6.6EPSS 2.08%18 December 2025
CVE-2025-68461RoundCube Webmail Cross-site Scripting VulnerabilityKEVMEDIUM 6.1EPSS 26.8%18 December 2025
CVE-2025-43529Apple Multiple Products Use-After-Free WebKit VulnerabilityKEVHIGH 8.8EPSS 8.76%17 December 2025
CVE-2025-20393Cisco Multiple Products Improper Input Validation VulnerabilityKEVCRITICAL 10.0EPSS 29.9%17 December 2025
CVE-2025-59374ASUS Live Update Embedded Malicious Code VulnerabilityKEVCRITICAL 9.3EPSS 1.20%17 December 2025
CVE-2025-37164Hewlett Packard Enterprise (HPE) OneView Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 90.2%16 December 2025
CVE-2025-43520Apple Multiple Products Classic Buffer Overflow VulnerabilityKEVMEDIUM 5.5EPSS 0.43%12 December 2025
CVE-2025-43510Apple Multiple Products Improper Locking VulnerabilityKEVHIGH 7.8EPSS 0.36%12 December 2025
CVE-2025-14611Gladinet CentreStack and Triofox Hard Coded Cryptographic VulnerabilityKEVHIGH 7.1EPSS 53.3%12 December 2025
CVE-2025-14174Google Chromium Out of Bounds Memory Access VulnerabilityKEVHIGH 8.8EPSS 22.3%12 December 2025
CVE-2025-8110Gogs Path Traversal VulnerabilityKEVHIGH 8.7EPSS 82.5%10 December 2025
CVE-2025-62221Microsoft Windows Use After Free VulnerabilityKEVHIGH 7.8EPSS 2.50%9 December 2025
CVE-2025-59718Fortinet Multiple Products Improper Verification of Cryptographic Signature VulnerabilityKEVCRITICAL 9.8EPSS 68.3%9 December 2025
CVE-2025-48633Android Framework Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 0.26%8 December 2025
CVE-2025-48572Android Framework Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 0.26%8 December 2025
CVE-2025-34291Langflow Origin Validation Error VulnerabilityKEVCRITICAL 9.4EPSS 83.6%5 December 2025
CVE-2025-66644Array Networks ArrayOS AG OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 3.42%5 December 2025
CVE-2025-55182Meta React Server Components Remote Code Execution VulnerabilityKEVCRITICAL 10.0EPSS 99.8%3 December 2025
CVE-2025-62593Ray-Project Ray Code Injection VulnerabilityKEVCRITICAL 9.4EPSS 16.9%26 November 2025
CVE-2025-58360OSGeo GeoServer Improper Restriction of XML External Entity Reference VulnerabilityKEVCRITICAL 9.8EPSS 64.9%25 November 2025
CVE-2025-58034Fortinet FortiWeb OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 55.6%18 November 2025
CVE-2025-13223Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 5.03%17 November 2025
CVE-2025-64446Fortinet FortiWeb Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 91.8%14 November 2025
CVE-2025-62215Microsoft Windows Race Condition VulnerabilityKEVHIGH 7.0EPSS 5.99%11 November 2025
CVE-2025-60710Microsoft Windows Link Following VulnerabilityKEVHIGH 7.8EPSS 4.60%11 November 2025
CVE-2025-12480Gladinet Triofox Improper Access Control VulnerabilityKEVCRITICAL 9.1EPSS 90.5%10 November 2025
CVE-2025-64328Sangoma FreePBX OS Command Injection VulnerabilityKEVHIGH 8.6EPSS 84.6%7 November 2025
CVE-2023-43000Apple Multiple products Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 3.90%5 November 2025
CVE-2025-11953React Native Community CLI OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 94.0%3 November 2025
CVE-2025-61757Oracle Fusion Middleware Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 88.3%21 October 2025
CVE-2025-61932Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel VulnerabilityKEVCRITICAL 9.3EPSS 2.63%20 October 2025
CVE-2025-53521F5 BIG-IP Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.3EPSS 2.21%15 October 2025
CVE-2025-59287Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 100.0%14 October 2025
CVE-2025-59230Microsoft Windows Improper Access Control VulnerabilityKEVHIGH 7.8EPSS 2.68%14 October 2025
CVE-2025-24990Microsoft Windows Untrusted Pointer Dereference VulnerabilityKEVHIGH 7.8EPSS 6.37%14 October 2025
CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 7.5EPSS 95.9%12 October 2025
CVE-2025-11371Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties VulnerabilityKEVHIGH 7.5EPSS 92.1%9 October 2025
CVE-2025-61882Oracle E-Business Suite Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 99.7%5 October 2025
CVE-2025-41244Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions VulnerabilityKEVHIGH 7.8EPSS 8.44%29 September 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.