Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 5 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-20362 | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | KEVHIGH 8.6EPSS 87.1% | 25 September 2025 |
| CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | KEVCRITICAL 9.9EPSS 70.7% | 25 September 2025 |
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | KEVHIGH 7.7EPSS 39.4% | 24 September 2025 |
| CVE-2025-10585 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.8EPSS 5.39% | 24 September 2025 |
| CVE-2025-26399 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 89.5% | 23 September 2025 |
| CVE-2025-59689 | Libraesva Email Security Gateway Command Injection Vulnerability | KEVMEDIUM 6.1EPSS 1.86% | 19 September 2025 |
| CVE-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | KEVCRITICAL 9.0EPSS 99.7% | 19 September 2025 |
| CVE-2025-10035 | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 18 September 2025 |
| CVE-2025-9242 | WatchGuard Firebox Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.3EPSS 91.3% | 17 September 2025 |
| CVE-2025-21043 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 1.91% | 12 September 2025 |
| CVE-2025-21042 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 33.2% | 12 September 2025 |
| CVE-2025-54236 | Adobe Commerce and Magento Improper Input Validation Vulnerability | KEVCRITICAL 9.1EPSS 94.5% | 9 September 2025 |
| CVE-2025-48543 | Android Runtime Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 0.53% | 4 September 2025 |
| CVE-2025-53690 | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.0EPSS 51.1% | 3 September 2025 |
| CVE-2025-9377 | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | KEVHIGH 8.6EPSS 33.5% | 29 August 2025 |
| CVE-2025-55177 | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | KEVMEDIUM 5.4EPSS 4.21% | 29 August 2025 |
| CVE-2025-57819 | Sangoma FreePBX Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 85.5% | 28 August 2025 |
| CVE-2025-7775 | Citrix NetScaler Memory Overflow Vulnerability | KEVCRITICAL 9.2EPSS 19.6% | 26 August 2025 |
| CVE-2025-43300 | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | KEVCRITICAL 10.0EPSS 22.0% | 21 August 2025 |
| CVE-2025-8876 | N-able N-Central Command Injection Vulnerability | KEVCRITICAL 9.4EPSS 3.33% | 14 August 2025 |
| CVE-2025-8875 | N-able N-Central Insecure Deserialization Vulnerability | KEVCRITICAL 9.4EPSS 1.72% | 14 August 2025 |
| CVE-2025-8088 | RARLAB WinRAR Path Traversal Vulnerability | KEVHIGH 8.4EPSS 94.6% | 8 August 2025 |
| CVE-2025-54253 | Adobe Experience Manager Forms Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 88.0% | 5 August 2025 |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 22.0% | 5 August 2025 |
| CVE-2025-6205 | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability | KEVCRITICAL 9.1EPSS 73.3% | 4 August 2025 |
| CVE-2025-6204 | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability | KEVHIGH 8.0EPSS 77.3% | 4 August 2025 |
| CVE-2025-31277 | Apple Multiple Products Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 1.53% | 30 July 2025 |
| CVE-2025-38352 | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability | KEVHIGH 7.8EPSS 1.25% | 22 July 2025 |
| CVE-2025-53770 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 20 July 2025 |
| CVE-2025-54313 | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | KEVHIGH 7.5EPSS 4.35% | 19 July 2025 |
| CVE-2025-54309 | CrushFTP Unprotected Alternate Channel Vulnerability | KEVCRITICAL 9.8EPSS 94.7% | 18 July 2025 |
| CVE-2025-54068 | Laravel Livewire Code Injection Vulnerability | KEVCRITICAL 9.2EPSS 96.5% | 17 July 2025 |
| CVE-2025-25257 | Fortinet FortiWeb SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 17 July 2025 |
| CVE-2025-20337 | Cisco Identity Services Engine Injection Vulnerability | KEVCRITICAL 10.0EPSS 67.0% | 16 July 2025 |
| CVE-2025-6558 | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 9.59% | 15 July 2025 |
| CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability | KEVMEDIUM 4.3EPSS 63.0% | 10 July 2025 |
| CVE-2025-47812 | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | KEVCRITICAL 10.0EPSS 92.9% | 10 July 2025 |
| CVE-2025-48384 | Git Link Following Vulnerability | KEVHIGH 8.0EPSS 4.11% | 8 July 2025 |
| CVE-2025-49706 | Microsoft SharePoint Improper Authentication Vulnerability | KEVMEDIUM 6.5EPSS 99.1% | 8 July 2025 |
| CVE-2025-49704 | Microsoft SharePoint Code Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 8 July 2025 |
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.1EPSS 12.7% | 30 June 2025 |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVHIGH 7.8EPSS 59.4% | 30 June 2025 |
| CVE-2025-20281 | Cisco Identity Services Engine Injection Vulnerability | KEVCRITICAL 10.0EPSS 97.1% | 25 June 2025 |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | KEVCRITICAL 9.2EPSS 10.1% | 25 June 2025 |
| CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | KEVCRITICAL 10.0EPSS 2.46% | 24 June 2025 |
| CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 1.69% | 23 June 2025 |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability | KEVHIGH 7.8EPSS 90.5% | 21 June 2025 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | KEVCRITICAL 9.3EPSS 100.0% | 17 June 2025 |
| CVE-2025-43200 | Apple Multiple Products Unspecified Vulnerability | KEVMEDIUM 4.2EPSS 1.04% | 16 June 2025 |
| CVE-2025-33073 | Microsoft Windows SMB Client Improper Access Control Vulnerability | KEVHIGH 8.8EPSS 82.7% | 10 June 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.