SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 8 of 35

CVESummaryPriorityPublished
CVE-2024-50603Aviatrix Controllers OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.5%8 January 2025
CVE-2024-12987DrayTek Vigor Routers OS Command Injection VulnerabilityKEVMEDIUM 6.9EPSS 98.1%27 December 2024
CVE-2024-53197Linux Kernel Out-of-Bounds Access VulnerabilityKEVHIGH 7.8EPSS 3.56%27 December 2024
CVE-2024-3393Palo Alto Networks PAN-OS Malicious DNS Packet VulnerabilityKEVHIGH 8.7EPSS 28.4%27 December 2024
CVE-2024-53150Linux Kernel Out-of-Bounds Read VulnerabilityKEVHIGH 7.1EPSS 1.35%24 December 2024
CVE-2024-56145Craft CMS Code Injection VulnerabilityKEVCRITICAL 9.3EPSS 97.4%18 December 2024
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 13.8%18 December 2024
CVE-2024-12356BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability KEVCRITICAL 9.8EPSS 88.0%17 December 2024
CVE-2024-55956Cleo Multiple Products Unauthenticated File Upload VulnerabilityKEVCRITICAL 9.8EPSS 94.0%13 December 2024
CVE-2024-49138Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 25.4%12 December 2024
CVE-2024-55550Mitel MiCollab Path Traversal VulnerabilityKEVLOW 2.7EPSS 37.8%10 December 2024
CVE-2024-53104Linux Kernel Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 3.40%2 December 2024
CVE-2024-11667Zyxel Multiple Firewalls Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 2.93%27 November 2024
CVE-2024-49035Microsoft Partner Center Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 1.30%26 November 2024
CVE-2024-11680ProjectSend Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 91.7%26 November 2024
CVE-2024-44309Apple Multiple Products Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.3EPSS 22.6%20 November 2024
CVE-2024-44308Apple Multiple Products Code Execution VulnerabilityKEVHIGH 8.8EPSS 10.2%20 November 2024
CVE-2024-50302Linux Kernel Use of Uninitialized Resource VulnerabilityKEVMEDIUM 5.5EPSS 0.81%19 November 2024
CVE-2024-21287Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization VulnerabilityKEVHIGH 7.5EPSS 1.72%18 November 2024
CVE-2024-9474Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityKEVMEDIUM 6.9EPSS 94.7%18 November 2024
CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityKEVCRITICAL 9.3EPSS 99.7%18 November 2024
CVE-2024-11182MDaemon Email Server Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 5.3EPSS 17.7%15 November 2024
CVE-2024-11120GeoVision Devices OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 28.4%15 November 2024
CVE-2024-43093Android Framework Privilege Escalation VulnerabilityKEVHIGH 7.3EPSS 0.71%13 November 2024
CVE-2024-8069Citrix Session Recording Deserialization of Untrusted Data VulnerabilityKEVMEDIUM 5.1EPSS 14.6%12 November 2024
CVE-2024-8068Citrix Session Recording Improper Privilege Management VulnerabilityKEVMEDIUM 5.1EPSS 1.40%12 November 2024
CVE-2024-49039Microsoft Windows Task Scheduler Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 14.2%12 November 2024
CVE-2024-43451Microsoft Windows NTLMv2 Hash Disclosure Spoofing VulnerabilityKEVMEDIUM 6.5EPSS 84.1%12 November 2024
CVE-2024-51567CyberPanel Incorrect Default Permissions VulnerabilityKEVCRITICAL 9.8EPSS 86.5%29 October 2024
CVE-2024-51378CyberPanel Incorrect Default Permissions VulnerabilityKEVCRITICAL 9.8EPSS 94.7%29 October 2024
CVE-2024-50623Cleo Multiple Products Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 98.6%28 October 2024
CVE-2024-20481Cisco ASA and FTD Denial-of-Service VulnerabilityKEVMEDIUM 5.8EPSS 15.8%23 October 2024
CVE-2024-47575Fortinet FortiManager Missing Authentication VulnerabilityKEVCRITICAL 9.8EPSS 95.1%23 October 2024
CVE-2024-41713Mitel MiCollab Path Traversal VulnerabilityKEVCRITICAL 9.1EPSS 98.1%21 October 2024
CVE-2024-9537ScienceLogic SL1 Unspecified VulnerabilityKEVCRITICAL 9.3EPSS 3.83%18 October 2024
CVE-2024-9465Palo Alto Networks Expedition SQL Injection VulnerabilityKEVCRITICAL 9.2EPSS 99.6%9 October 2024
CVE-2024-9463Palo Alto Networks Expedition OS Command Injection VulnerabilityKEVCRITICAL 9.9EPSS 98.5%9 October 2024
CVE-2024-9680Mozilla Firefox Use-After-Free VulnerabilityKEVCRITICAL 9.8EPSS 23.2%9 October 2024
CVE-2024-43573Microsoft Windows MSHTML Platform Spoofing VulnerabilityKEVHIGH 8.1EPSS 43.8%8 October 2024
CVE-2024-43572Microsoft Windows Management Console Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 66.7%8 October 2024
CVE-2024-43468Microsoft Configuration Manager SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 82.0%8 October 2024
CVE-2024-9380Ivanti Cloud Services Appliance (CSA) OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 63.2%8 October 2024
CVE-2024-9379Ivanti Cloud Services Appliance (CSA) SQL Injection VulnerabilityKEVHIGH 7.2EPSS 43.8%8 October 2024
CVE-2024-43047Qualcomm Multiple Chipsets Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.67%7 October 2024
CVE-2024-45519Synacor Zimbra Collaboration Suite (ZCS) Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%2 October 2024
CVE-2024-8963Ivanti Cloud Services Appliance (CSA) Path Traversal VulnerabilityKEVCRITICAL 9.1EPSS 98.6%19 September 2024
CVE-2024-8957PTZOptics PT30X-SDI/NDI Cameras OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 81.0%17 September 2024
CVE-2024-8956PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass VulnerabilityKEVCRITICAL 9.1EPSS 61.3%17 September 2024
CVE-2024-38813VMware vCenter Server Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 17.4%17 September 2024
CVE-2024-38812VMware vCenter Server Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 54.6%17 September 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.