Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 6 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-33053 | Microsoft Windows External Control of File Name or Path Vulnerability | KEVHIGH 8.8EPSS 87.6% | 10 June 2025 |
| CVE-2025-47827 | IGEL OS Use of a Key Past its Expiration Date Vulnerability | KEVMEDIUM 4.6EPSS 4.93% | 5 June 2025 |
| CVE-2025-21479 | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | KEVHIGH 8.6EPSS 0.84% | 3 June 2025 |
| CVE-2025-27038 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | KEVHIGH 7.5EPSS 1.02% | 3 June 2025 |
| CVE-2025-21480 | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | KEVHIGH 8.6EPSS 0.46% | 3 June 2025 |
| CVE-2025-5419 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | KEVHIGH 8.8EPSS 7.82% | 3 June 2025 |
| CVE-2025-5086 | Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.0EPSS 91.9% | 2 June 2025 |
| CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 98.9% | 2 June 2025 |
| CVE-2025-48928 | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability | KEVMEDIUM 4.0EPSS 0.55% | 28 May 2025 |
| CVE-2025-48927 | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | KEVMEDIUM 5.3EPSS 11.1% | 28 May 2025 |
| CVE-2025-34026 | Versa Concerto Improper Authentication Vulnerability | KEVCRITICAL 9.2EPSS 81.9% | 21 May 2025 |
| CVE-2025-4008 | Smartbedded Meteobridge Command Injection Vulnerability | KEVHIGH 8.7EPSS 93.7% | 21 May 2025 |
| CVE-2025-32709 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 2.09% | 13 May 2025 |
| CVE-2025-32706 | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 2.24% | 13 May 2025 |
| CVE-2025-32701 | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.36% | 13 May 2025 |
| CVE-2025-30400 | Microsoft Windows DWM Core Library Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.85% | 13 May 2025 |
| CVE-2025-30397 | Microsoft Windows Scripting Engine Type Confusion Vulnerability | KEVHIGH 7.5EPSS 26.8% | 13 May 2025 |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVHIGH 8.8EPSS 86.2% | 13 May 2025 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 99.9% | 13 May 2025 |
| CVE-2025-32756 | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 29.8% | 13 May 2025 |
| CVE-2025-4632 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 24.3% | 13 May 2025 |
| CVE-2025-42999 | SAP NetWeaver Deserialization Vulnerability | KEVCRITICAL 9.1EPSS 13.9% | 13 May 2025 |
| CVE-2025-47729 | TeleMessage TM SGNL Hidden Functionality Vulnerability | KEVMEDIUM 4.9EPSS 0.43% | 8 May 2025 |
| CVE-2025-35939 | Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability | KEVMEDIUM 6.9EPSS 1.32% | 7 May 2025 |
| CVE-2025-2776 | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | KEVCRITICAL 9.8EPSS 64.4% | 7 May 2025 |
| CVE-2025-2775 | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | KEVHIGH 7.5EPSS 43.0% | 7 May 2025 |
| CVE-2025-27920 | Srimax Output Messenger Directory Traversal Vulnerability | KEVHIGH 8.8EPSS 1.85% | 5 May 2025 |
| CVE-2025-3935 | ConnectWise ScreenConnect Improper Authentication Vulnerability | KEVHIGH 7.2EPSS 3.39% | 25 April 2025 |
| CVE-2025-3928 | Commvault Web Server Unspecified Vulnerability | KEVHIGH 8.7EPSS 2.14% | 25 April 2025 |
| CVE-2025-32432 | Craft CMS Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 25 April 2025 |
| CVE-2025-31324 | SAP NetWeaver Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 24 April 2025 |
| CVE-2025-1976 | Broadcom Brocade Fabric OS Code Injection Vulnerability | KEVHIGH 8.6EPSS 0.69% | 24 April 2025 |
| CVE-2025-34028 | Commvault Command Center Path Traversal Vulnerability | KEVCRITICAL 9.3EPSS 97.7% | 22 April 2025 |
| CVE-2025-42599 | Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 3.30% | 18 April 2025 |
| CVE-2025-32433 | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 10.0EPSS 98.8% | 16 April 2025 |
| CVE-2025-31201 | Apple Multiple Products Arbitrary Read and Write Vulnerability | KEVCRITICAL 9.8EPSS 13.9% | 16 April 2025 |
| CVE-2025-31200 | Apple Multiple Products Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 18.6% | 16 April 2025 |
| CVE-2024-58136 | Yiiframework Yii Improper Protection of Alternate Path Vulnerability | KEVCRITICAL 9.8EPSS 84.6% | 10 April 2025 |
| CVE-2025-29824 | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 13.9% | 8 April 2025 |
| CVE-2025-3248 | Langflow Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 7 April 2025 |
| CVE-2025-31161 | CrushFTP Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 3 April 2025 |
| CVE-2025-30406 | Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability | KEVCRITICAL 9.8EPSS 94.3% | 3 April 2025 |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 3 April 2025 |
| CVE-2025-31125 | Vite Vitejs Improper Access Control Vulnerability | KEVHIGH 7.5EPSS 58.5% | 31 March 2025 |
| CVE-2025-2783 | Google Chromium Mojo Sandbox Escape Vulnerability | KEVHIGH 8.3EPSS 9.24% | 26 March 2025 |
| CVE-2025-29635 | D-Link DIR-823X Command Injection Vulnerability | KEVHIGH 7.2EPSS 87.9% | 25 March 2025 |
| CVE-2025-2749 | Kentico Xperience Path Traversal Vulnerability | KEVHIGH 7.2EPSS 3.99% | 24 March 2025 |
| CVE-2025-2747 | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.8EPSS 92.5% | 24 March 2025 |
| CVE-2025-2746 | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.8EPSS 59.1% | 24 March 2025 |
| CVE-2025-30154 | reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability | KEVHIGH 8.6EPSS 2.40% | 19 March 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.