SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 6 of 35

CVESummaryPriorityPublished
CVE-2025-33053 Microsoft Windows External Control of File Name or Path VulnerabilityKEVHIGH 8.8EPSS 87.6%10 June 2025
CVE-2025-47827IGEL OS Use of a Key Past its Expiration Date VulnerabilityKEVMEDIUM 4.6EPSS 4.93%5 June 2025
CVE-2025-21479Qualcomm Multiple Chipsets Incorrect Authorization VulnerabilityKEVHIGH 8.6EPSS 0.84%3 June 2025
CVE-2025-27038Qualcomm Multiple Chipsets Use-After-Free VulnerabilityKEVHIGH 7.5EPSS 1.02%3 June 2025
CVE-2025-21480Qualcomm Multiple Chipsets Incorrect Authorization VulnerabilityKEVHIGH 8.6EPSS 0.46%3 June 2025
CVE-2025-5419Google Chromium V8 Out-of-Bounds Read and Write VulnerabilityKEVHIGH 8.8EPSS 7.82%3 June 2025
CVE-2025-5086Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.0EPSS 91.9%2 June 2025
CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 98.9%2 June 2025
CVE-2025-48928TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere VulnerabilityKEVMEDIUM 4.0EPSS 0.55%28 May 2025
CVE-2025-48927TeleMessage TM SGNL Initialization of a Resource with an Insecure Default VulnerabilityKEVMEDIUM 5.3EPSS 11.1%28 May 2025
CVE-2025-34026Versa Concerto Improper Authentication VulnerabilityKEVCRITICAL 9.2EPSS 81.9%21 May 2025
CVE-2025-4008Smartbedded Meteobridge Command Injection VulnerabilityKEVHIGH 8.7EPSS 93.7%21 May 2025
CVE-2025-32709Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 2.09%13 May 2025
CVE-2025-32706Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 2.24%13 May 2025
CVE-2025-32701Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 1.36%13 May 2025
CVE-2025-30400Microsoft Windows DWM Core Library Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 1.85%13 May 2025
CVE-2025-30397Microsoft Windows Scripting Engine Type Confusion VulnerabilityKEVHIGH 7.5EPSS 26.8%13 May 2025
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityKEVHIGH 8.8EPSS 86.2%13 May 2025
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass VulnerabilityKEVHIGH 7.5EPSS 99.9%13 May 2025
CVE-2025-32756Fortinet Multiple Products Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 29.8%13 May 2025
CVE-2025-4632Samsung MagicINFO 9 Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 24.3%13 May 2025
CVE-2025-42999SAP NetWeaver Deserialization VulnerabilityKEVCRITICAL 9.1EPSS 13.9%13 May 2025
CVE-2025-47729TeleMessage TM SGNL Hidden Functionality VulnerabilityKEVMEDIUM 4.9EPSS 0.43%8 May 2025
CVE-2025-35939Craft CMS External Control of Assumed-Immutable Web Parameter VulnerabilityKEVMEDIUM 6.9EPSS 1.32%7 May 2025
CVE-2025-2776SysAid On-Prem Improper Restriction of XML External Entity Reference VulnerabilityKEVCRITICAL 9.8EPSS 64.4%7 May 2025
CVE-2025-2775SysAid On-Prem Improper Restriction of XML External Entity Reference VulnerabilityKEVHIGH 7.5EPSS 43.0%7 May 2025
CVE-2025-27920Srimax Output Messenger Directory Traversal VulnerabilityKEVHIGH 8.8EPSS 1.85%5 May 2025
CVE-2025-3935ConnectWise ScreenConnect Improper Authentication VulnerabilityKEVHIGH 7.2EPSS 3.39%25 April 2025
CVE-2025-3928Commvault Web Server Unspecified VulnerabilityKEVHIGH 8.7EPSS 2.14%25 April 2025
CVE-2025-32432Craft CMS Code Injection VulnerabilityKEVCRITICAL 10.0EPSS 99.8%25 April 2025
CVE-2025-31324SAP NetWeaver Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 99.5%24 April 2025
CVE-2025-1976Broadcom Brocade Fabric OS Code Injection VulnerabilityKEVHIGH 8.6EPSS 0.69%24 April 2025
CVE-2025-34028Commvault Command Center Path Traversal VulnerabilityKEVCRITICAL 9.3EPSS 97.7%22 April 2025
CVE-2025-42599Qualitia Active! Mail Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 3.30%18 April 2025
CVE-2025-32433Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 10.0EPSS 98.8%16 April 2025
CVE-2025-31201Apple Multiple Products Arbitrary Read and Write VulnerabilityKEVCRITICAL 9.8EPSS 13.9%16 April 2025
CVE-2025-31200Apple Multiple Products Memory Corruption VulnerabilityKEVCRITICAL 9.8EPSS 18.6%16 April 2025
CVE-2024-58136Yiiframework Yii Improper Protection of Alternate Path VulnerabilityKEVCRITICAL 9.8EPSS 84.6%10 April 2025
CVE-2025-29824Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 13.9%8 April 2025
CVE-2025-3248Langflow Missing Authentication VulnerabilityKEVCRITICAL 9.8EPSS 100.0%7 April 2025
CVE-2025-31161CrushFTP Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%3 April 2025
CVE-2025-30406Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key VulnerabilityKEVCRITICAL 9.8EPSS 94.3%3 April 2025
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 100.0%3 April 2025
CVE-2025-31125Vite Vitejs Improper Access Control VulnerabilityKEVHIGH 7.5EPSS 58.5%31 March 2025
CVE-2025-2783Google Chromium Mojo Sandbox Escape VulnerabilityKEVHIGH 8.3EPSS 9.24%26 March 2025
CVE-2025-29635D-Link DIR-823X Command Injection VulnerabilityKEVHIGH 7.2EPSS 87.9%25 March 2025
CVE-2025-2749Kentico Xperience Path Traversal VulnerabilityKEVHIGH 7.2EPSS 3.99%24 March 2025
CVE-2025-2747Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.8EPSS 92.5%24 March 2025
CVE-2025-2746Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.8EPSS 59.1%24 March 2025
CVE-2025-30154reviewdog/action-setup GitHub Action Embedded Malicious Code VulnerabilityKEVHIGH 8.6EPSS 2.40%19 March 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.