SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 9 of 35

CVESummaryPriorityPublished
CVE-2024-8190Ivanti Cloud Services Appliance OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 88.5%10 September 2024
CVE-2024-43461Microsoft Windows MSHTML Platform Spoofing VulnerabilityKEVHIGH 8.8EPSS 54.5%10 September 2024
CVE-2024-38226Microsoft Publisher Protection Mechanism Failure VulnerabilityKEVHIGH 7.3EPSS 2.67%10 September 2024
CVE-2024-38217Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure VulnerabilityKEVMEDIUM 5.4EPSS 10.0%10 September 2024
CVE-2024-38014Microsoft Windows Installer Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 6.26%10 September 2024
CVE-2024-40711Veeam Backup and Replication Deserialization VulnerabilityKEVCRITICAL 9.8EPSS 90.4%7 September 2024
CVE-2024-20439Cisco Smart Licensing Utility Static Credential VulnerabilityKEVCRITICAL 9.8EPSS 92.1%4 September 2024
CVE-2024-45195Apache OFBiz Forced Browsing VulnerabilityKEVHIGH 7.5EPSS 100.0%4 September 2024
CVE-2024-6670Progress WhatsUp Gold SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 93.0%29 August 2024
CVE-2024-40766SonicWall SonicOS Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 18.2%23 August 2024
CVE-2024-39717Versa Director Dangerous File Type Upload VulnerabilityKEVHIGH 7.2EPSS 4.01%22 August 2024
CVE-2024-28987SolarWinds Web Help Desk Hardcoded Credential VulnerabilityKEVCRITICAL 9.1EPSS 93.2%21 August 2024
CVE-2024-7971Google Chromium V8 Type Confusion VulnerabilityKEVCRITICAL 9.6EPSS 20.7%21 August 2024
CVE-2024-7965Google Chromium V8 Inappropriate Implementation VulnerabilityKEVHIGH 8.8EPSS 18.5%21 August 2024
CVE-2024-7262Kingsoft WPS Office Path Traversal VulnerabilityKEVCRITICAL 9.3EPSS 2.94%15 August 2024
CVE-2024-28986SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 84.6%13 August 2024
CVE-2024-7593Ivanti Virtual Traffic Manager Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%13 August 2024
CVE-2024-38213Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVMEDIUM 6.5EPSS 13.6%13 August 2024
CVE-2024-38193Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 28.5%13 August 2024
CVE-2024-38189Microsoft Project Remote Code Execution Vulnerability KEVHIGH 8.8EPSS 8.19%13 August 2024
CVE-2024-38178Microsoft Windows Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 41.4%13 August 2024
CVE-2024-38107Microsoft Windows Power Dependency Coordinator Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 1.64%13 August 2024
CVE-2024-38106Microsoft Windows Kernel Privilege Escalation VulnerabilityKEVHIGH 7.0EPSS 6.34%13 August 2024
CVE-2024-41710Mitel SIP Phones Argument Injection VulnerabilityKEVHIGH 7.2EPSS 41.6%12 August 2024
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 23.6%12 August 2024
CVE-2024-7694TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type VulnerabilityKEVHIGH 7.2EPSS 1.81%12 August 2024
CVE-2024-7399Samsung MagicINFO 9 Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 91.9%12 August 2024
CVE-2024-42009RoundCube Webmail Cross-Site Scripting VulnerabilityKEVCRITICAL 9.3EPSS 82.9%5 August 2024
CVE-2024-38856Apache OFBiz Incorrect Authorization VulnerabilityKEVCRITICAL 9.8EPSS 99.4%5 August 2024
CVE-2023-45249Acronis Cyber Infrastructure (ACI) Insecure Default Password VulnerabilityKEVCRITICAL 9.8EPSS 53.3%24 July 2024
CVE-2024-21182Oracle WebLogic Server Unspecified VulnerabilityKEVHIGH 7.5EPSS 74.2%16 July 2024
CVE-2024-5910Palo Alto Networks Expedition Missing Authentication VulnerabilityKEVCRITICAL 9.3EPSS 91.8%10 July 2024
CVE-2024-5217ServiceNow Incomplete List of Disallowed Inputs VulnerabilityKEVCRITICAL 9.2EPSS 99.6%10 July 2024
CVE-2024-4879ServiceNow Improper Input Validation VulnerabilityKEVCRITICAL 9.3EPSS 100.0%10 July 2024
CVE-2024-38112Microsoft Windows MSHTML Platform Spoofing VulnerabilityKEVHIGH 7.5EPSS 84.2%9 July 2024
CVE-2024-38094Microsoft SharePoint Deserialization VulnerabilityKEVHIGH 7.2EPSS 50.9%9 July 2024
CVE-2024-38080Microsoft Windows Hyper-V Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 7.12%9 July 2024
CVE-2024-39891Twilio Authy Information Disclosure VulnerabilityKEVMEDIUM 5.3EPSS 1.67%2 July 2024
CVE-2024-38475Apache HTTP Server Improper Escaping of Output VulnerabilityKEVCRITICAL 9.1EPSS 100.0%1 July 2024
CVE-2024-20399Cisco NX-OS Command Injection VulnerabilityKEVMEDIUM 6.7EPSS 4.31%1 July 2024
CVE-2024-36401OSGeo GeoServer GeoTools Eval Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.8%1 July 2024
CVE-2024-4885Progress WhatsUp Gold Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 99.3%25 June 2024
CVE-2024-37085VMware ESXi Authentication Bypass VulnerabilityKEVHIGH 7.2EPSS 26.8%25 June 2024
CVE-2024-37079Broadcom VMware vCenter Server Out-of-bounds Write VulnerabilityKEVCRITICAL 9.8EPSS 22.4%18 June 2024
CVE-2024-6047GeoVision Devices OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 10.1%17 June 2024
CVE-2024-32896Android Pixel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 2.99%13 June 2024
CVE-2024-34102Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) VulnerabilityKEVCRITICAL 9.8EPSS 100.0%13 June 2024
CVE-2024-35250Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability KEVHIGH 7.8EPSS 25.0%11 June 2024
CVE-2024-30088Microsoft Windows Kernel TOCTOU Race Condition VulnerabilityKEVHIGH 7.0EPSS 68.2%11 June 2024
CVE-2024-36971Android Kernel Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 2.70%10 June 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.