Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 8 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-50603 | Aviatrix Controllers OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.5% | 8 January 2025 |
| CVE-2024-12987 | DrayTek Vigor Routers OS Command Injection Vulnerability | KEVMEDIUM 6.9EPSS 98.1% | 27 December 2024 |
| CVE-2024-53197 | Linux Kernel Out-of-Bounds Access Vulnerability | KEVHIGH 7.8EPSS 3.56% | 27 December 2024 |
| CVE-2024-3393 | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | KEVHIGH 8.7EPSS 28.4% | 27 December 2024 |
| CVE-2024-53150 | Linux Kernel Out-of-Bounds Read Vulnerability | KEVHIGH 7.1EPSS 1.35% | 24 December 2024 |
| CVE-2024-56145 | Craft CMS Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 97.4% | 18 December 2024 |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 13.8% | 18 December 2024 |
| CVE-2024-12356 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 88.0% | 17 December 2024 |
| CVE-2024-55956 | Cleo Multiple Products Unauthenticated File Upload Vulnerability | KEVCRITICAL 9.8EPSS 94.0% | 13 December 2024 |
| CVE-2024-49138 | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 25.4% | 12 December 2024 |
| CVE-2024-55550 | Mitel MiCollab Path Traversal Vulnerability | KEVLOW 2.7EPSS 37.8% | 10 December 2024 |
| CVE-2024-53104 | Linux Kernel Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 3.40% | 2 December 2024 |
| CVE-2024-11667 | Zyxel Multiple Firewalls Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 2.93% | 27 November 2024 |
| CVE-2024-49035 | Microsoft Partner Center Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 1.30% | 26 November 2024 |
| CVE-2024-11680 | ProjectSend Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 91.7% | 26 November 2024 |
| CVE-2024-44309 | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.3EPSS 22.6% | 20 November 2024 |
| CVE-2024-44308 | Apple Multiple Products Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.2% | 20 November 2024 |
| CVE-2024-50302 | Linux Kernel Use of Uninitialized Resource Vulnerability | KEVMEDIUM 5.5EPSS 0.81% | 19 November 2024 |
| CVE-2024-21287 | Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability | KEVHIGH 7.5EPSS 1.72% | 18 November 2024 |
| CVE-2024-9474 | Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | KEVMEDIUM 6.9EPSS 94.7% | 18 November 2024 |
| CVE-2024-0012 | Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | KEVCRITICAL 9.3EPSS 99.7% | 18 November 2024 |
| CVE-2024-11182 | MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 5.3EPSS 17.7% | 15 November 2024 |
| CVE-2024-11120 | GeoVision Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 28.4% | 15 November 2024 |
| CVE-2024-43093 | Android Framework Privilege Escalation Vulnerability | KEVHIGH 7.3EPSS 0.71% | 13 November 2024 |
| CVE-2024-8069 | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | KEVMEDIUM 5.1EPSS 14.6% | 12 November 2024 |
| CVE-2024-8068 | Citrix Session Recording Improper Privilege Management Vulnerability | KEVMEDIUM 5.1EPSS 1.40% | 12 November 2024 |
| CVE-2024-49039 | Microsoft Windows Task Scheduler Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 14.2% | 12 November 2024 |
| CVE-2024-43451 | Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability | KEVMEDIUM 6.5EPSS 84.1% | 12 November 2024 |
| CVE-2024-51567 | CyberPanel Incorrect Default Permissions Vulnerability | KEVCRITICAL 9.8EPSS 86.5% | 29 October 2024 |
| CVE-2024-51378 | CyberPanel Incorrect Default Permissions Vulnerability | KEVCRITICAL 9.8EPSS 94.7% | 29 October 2024 |
| CVE-2024-50623 | Cleo Multiple Products Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 98.6% | 28 October 2024 |
| CVE-2024-20481 | Cisco ASA and FTD Denial-of-Service Vulnerability | KEVMEDIUM 5.8EPSS 15.8% | 23 October 2024 |
| CVE-2024-47575 | Fortinet FortiManager Missing Authentication Vulnerability | KEVCRITICAL 9.8EPSS 95.1% | 23 October 2024 |
| CVE-2024-41713 | Mitel MiCollab Path Traversal Vulnerability | KEVCRITICAL 9.1EPSS 98.1% | 21 October 2024 |
| CVE-2024-9537 | ScienceLogic SL1 Unspecified Vulnerability | KEVCRITICAL 9.3EPSS 3.83% | 18 October 2024 |
| CVE-2024-9465 | Palo Alto Networks Expedition SQL Injection Vulnerability | KEVCRITICAL 9.2EPSS 99.6% | 9 October 2024 |
| CVE-2024-9463 | Palo Alto Networks Expedition OS Command Injection Vulnerability | KEVCRITICAL 9.9EPSS 98.5% | 9 October 2024 |
| CVE-2024-9680 | Mozilla Firefox Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 23.2% | 9 October 2024 |
| CVE-2024-43573 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | KEVHIGH 8.1EPSS 43.8% | 8 October 2024 |
| CVE-2024-43572 | Microsoft Windows Management Console Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 66.7% | 8 October 2024 |
| CVE-2024-43468 | Microsoft Configuration Manager SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 82.0% | 8 October 2024 |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 63.2% | 8 October 2024 |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | KEVHIGH 7.2EPSS 43.8% | 8 October 2024 |
| CVE-2024-43047 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.67% | 7 October 2024 |
| CVE-2024-45519 | Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 2 October 2024 |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | KEVCRITICAL 9.1EPSS 98.6% | 19 September 2024 |
| CVE-2024-8957 | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 81.0% | 17 September 2024 |
| CVE-2024-8956 | PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability | KEVCRITICAL 9.1EPSS 61.3% | 17 September 2024 |
| CVE-2024-38813 | VMware vCenter Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 17.4% | 17 September 2024 |
| CVE-2024-38812 | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 54.6% | 17 September 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.