Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 7 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-30066 | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability | KEVHIGH 8.6EPSS 69.8% | 15 March 2025 |
| CVE-2025-27915 | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | KEVMEDIUM 5.4EPSS 3.99% | 12 March 2025 |
| CVE-2025-21590 | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | KEVMEDIUM 6.7EPSS 1.71% | 12 March 2025 |
| CVE-2025-24201 | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | KEVCRITICAL 10.0EPSS 3.80% | 11 March 2025 |
| CVE-2025-26633 | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability | KEVHIGH 7.0EPSS 30.4% | 11 March 2025 |
| CVE-2025-24993 | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 2.17% | 11 March 2025 |
| CVE-2025-24991 | Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability | KEVMEDIUM 5.5EPSS 1.98% | 11 March 2025 |
| CVE-2025-24985 | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 3.85% | 11 March 2025 |
| CVE-2025-24984 | Microsoft Windows NTFS Information Disclosure Vulnerability | KEVMEDIUM 4.6EPSS 1.96% | 11 March 2025 |
| CVE-2025-24983 | Microsoft Windows Win32k Use-After-Free Vulnerability | KEVHIGH 7.0EPSS 1.35% | 11 March 2025 |
| CVE-2025-24054 | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability | KEVMEDIUM 5.4EPSS 58.9% | 11 March 2025 |
| CVE-2025-27363 | FreeType Out-of-Bounds Write Vulnerability | KEVHIGH 8.1EPSS 27.8% | 11 March 2025 |
| CVE-2024-54085 | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | KEVCRITICAL 10.0EPSS 60.7% | 11 March 2025 |
| CVE-2025-24813 | Apache Tomcat Path Equivalence Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 10 March 2025 |
| CVE-2025-1316 | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | KEVCRITICAL 9.3EPSS 74.5% | 5 March 2025 |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | KEVMEDIUM 6.0EPSS 1.74% | 4 March 2025 |
| CVE-2025-22225 | VMware ESXi Arbitrary Write Vulnerability | KEVHIGH 8.2EPSS 1.00% | 4 March 2025 |
| CVE-2025-22224 | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | KEVHIGH 8.2EPSS 1.56% | 4 March 2025 |
| CVE-2024-48248 | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | KEVHIGH 8.6EPSS 94.4% | 4 March 2025 |
| CVE-2025-24893 | XWiki Platform Eval Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 20 February 2025 |
| CVE-2025-24989 | Microsoft Power Pages Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 1.62% | 19 February 2025 |
| CVE-2025-0111 | Palo Alto Networks PAN-OS File Read Vulnerability | KEVHIGH 7.1EPSS 2.00% | 12 February 2025 |
| CVE-2025-0108 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | KEVHIGH 8.8EPSS 98.5% | 12 February 2025 |
| CVE-2025-21418 | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 1.57% | 11 February 2025 |
| CVE-2025-21391 | Microsoft Windows Storage Link Following Vulnerability | KEVHIGH 7.1EPSS 2.30% | 11 February 2025 |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | KEVHIGH 8.1EPSS 7.11% | 11 February 2025 |
| CVE-2025-24016 | Wazuh Server Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.9EPSS 93.8% | 10 February 2025 |
| CVE-2025-24200 | Apple iOS and iPadOS Incorrect Authorization Vulnerability | KEVMEDIUM 6.1EPSS 4.46% | 10 February 2025 |
| CVE-2025-0994 | Trimble Cityworks Deserialization Vulnerability | KEVHIGH 8.6EPSS 31.3% | 6 February 2025 |
| CVE-2024-40891 | Zyxel DSL CPE OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 21.5% | 4 February 2025 |
| CVE-2024-40890 | Zyxel DSL CPE OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 22.3% | 4 February 2025 |
| CVE-2023-52163 | Digiever DS-2105 Pro Missing Authorization Vulnerability | KEVHIGH 8.8EPSS 96.9% | 3 February 2025 |
| CVE-2025-25181 | Advantive VeraCore SQL Injection Vulnerability | KEVHIGH 7.5EPSS 57.0% | 3 February 2025 |
| CVE-2024-57968 | Advantive VeraCore Unrestricted File Upload Vulnerability | KEVHIGH 8.8EPSS 32.3% | 3 February 2025 |
| CVE-2025-24085 | Apple Multiple Products Use-After-Free Vulnerability | KEVCRITICAL 10.0EPSS 17.6% | 27 January 2025 |
| CVE-2025-0411 | 7-Zip Mark of the Web Bypass Vulnerability | KEVHIGH 7.0EPSS 67.1% | 25 January 2025 |
| CVE-2025-23006 | SonicWall SMA1000 Appliances Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 23.4% | 23 January 2025 |
| CVE-2025-23209 | Craft CMS Code Injection Vulnerability | KEVHIGH 8.1EPSS 21.8% | 18 January 2025 |
| CVE-2024-57728 | SimpleHelp Path Traversal Vulnerability | KEVHIGH 7.2EPSS 6.98% | 15 January 2025 |
| CVE-2024-57727 | SimpleHelp Path Traversal Vulnerability | KEVHIGH 7.5EPSS 95.2% | 15 January 2025 |
| CVE-2024-57726 | SimpleHelp Missing Authorization Vulnerability | KEVCRITICAL 9.9EPSS 66.6% | 15 January 2025 |
| CVE-2025-21335 | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.39% | 14 January 2025 |
| CVE-2025-21334 | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.56% | 14 January 2025 |
| CVE-2025-21333 | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 9.99% | 14 January 2025 |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | KEVHIGH 7.5EPSS 90.1% | 14 January 2025 |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | KEVHIGH 7.5EPSS 91.2% | 14 January 2025 |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | KEVHIGH 7.5EPSS 100.0% | 14 January 2025 |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 14 January 2025 |
| CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 95.1% | 9 January 2025 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.0EPSS 100.0% | 8 January 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.