Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 9 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 88.5% | 10 September 2024 |
| CVE-2024-43461 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | KEVHIGH 8.8EPSS 54.5% | 10 September 2024 |
| CVE-2024-38226 | Microsoft Publisher Protection Mechanism Failure Vulnerability | KEVHIGH 7.3EPSS 2.67% | 10 September 2024 |
| CVE-2024-38217 | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability | KEVMEDIUM 5.4EPSS 10.0% | 10 September 2024 |
| CVE-2024-38014 | Microsoft Windows Installer Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 6.26% | 10 September 2024 |
| CVE-2024-40711 | Veeam Backup and Replication Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 90.4% | 7 September 2024 |
| CVE-2024-20439 | Cisco Smart Licensing Utility Static Credential Vulnerability | KEVCRITICAL 9.8EPSS 92.1% | 4 September 2024 |
| CVE-2024-45195 | Apache OFBiz Forced Browsing Vulnerability | KEVHIGH 7.5EPSS 100.0% | 4 September 2024 |
| CVE-2024-6670 | Progress WhatsUp Gold SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 93.0% | 29 August 2024 |
| CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 18.2% | 23 August 2024 |
| CVE-2024-39717 | Versa Director Dangerous File Type Upload Vulnerability | KEVHIGH 7.2EPSS 4.01% | 22 August 2024 |
| CVE-2024-28987 | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | KEVCRITICAL 9.1EPSS 93.2% | 21 August 2024 |
| CVE-2024-7971 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.6EPSS 20.7% | 21 August 2024 |
| CVE-2024-7965 | Google Chromium V8 Inappropriate Implementation Vulnerability | KEVHIGH 8.8EPSS 18.5% | 21 August 2024 |
| CVE-2024-7262 | Kingsoft WPS Office Path Traversal Vulnerability | KEVCRITICAL 9.3EPSS 2.94% | 15 August 2024 |
| CVE-2024-28986 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 84.6% | 13 August 2024 |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 13 August 2024 |
| CVE-2024-38213 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVMEDIUM 6.5EPSS 13.6% | 13 August 2024 |
| CVE-2024-38193 | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 28.5% | 13 August 2024 |
| CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 8.19% | 13 August 2024 |
| CVE-2024-38178 | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 41.4% | 13 August 2024 |
| CVE-2024-38107 | Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 1.64% | 13 August 2024 |
| CVE-2024-38106 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 6.34% | 13 August 2024 |
| CVE-2024-41710 | Mitel SIP Phones Argument Injection Vulnerability | KEVHIGH 7.2EPSS 41.6% | 12 August 2024 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 23.6% | 12 August 2024 |
| CVE-2024-7694 | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | KEVHIGH 7.2EPSS 1.81% | 12 August 2024 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 12 August 2024 |
| CVE-2024-42009 | RoundCube Webmail Cross-Site Scripting Vulnerability | KEVCRITICAL 9.3EPSS 82.9% | 5 August 2024 |
| CVE-2024-38856 | Apache OFBiz Incorrect Authorization Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 5 August 2024 |
| CVE-2023-45249 | Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability | KEVCRITICAL 9.8EPSS 53.3% | 24 July 2024 |
| CVE-2024-21182 | Oracle WebLogic Server Unspecified Vulnerability | KEVHIGH 7.5EPSS 74.2% | 16 July 2024 |
| CVE-2024-5910 | Palo Alto Networks Expedition Missing Authentication Vulnerability | KEVCRITICAL 9.3EPSS 91.8% | 10 July 2024 |
| CVE-2024-5217 | ServiceNow Incomplete List of Disallowed Inputs Vulnerability | KEVCRITICAL 9.2EPSS 99.6% | 10 July 2024 |
| CVE-2024-4879 | ServiceNow Improper Input Validation Vulnerability | KEVCRITICAL 9.3EPSS 100.0% | 10 July 2024 |
| CVE-2024-38112 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | KEVHIGH 7.5EPSS 84.2% | 9 July 2024 |
| CVE-2024-38094 | Microsoft SharePoint Deserialization Vulnerability | KEVHIGH 7.2EPSS 50.9% | 9 July 2024 |
| CVE-2024-38080 | Microsoft Windows Hyper-V Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 7.12% | 9 July 2024 |
| CVE-2024-39891 | Twilio Authy Information Disclosure Vulnerability | KEVMEDIUM 5.3EPSS 1.67% | 2 July 2024 |
| CVE-2024-38475 | Apache HTTP Server Improper Escaping of Output Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 1 July 2024 |
| CVE-2024-20399 | Cisco NX-OS Command Injection Vulnerability | KEVMEDIUM 6.7EPSS 4.31% | 1 July 2024 |
| CVE-2024-36401 | OSGeo GeoServer GeoTools Eval Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 1 July 2024 |
| CVE-2024-4885 | Progress WhatsUp Gold Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 25 June 2024 |
| CVE-2024-37085 | VMware ESXi Authentication Bypass Vulnerability | KEVHIGH 7.2EPSS 26.8% | 25 June 2024 |
| CVE-2024-37079 | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 22.4% | 18 June 2024 |
| CVE-2024-6047 | GeoVision Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 10.1% | 17 June 2024 |
| CVE-2024-32896 | Android Pixel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.99% | 13 June 2024 |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 13 June 2024 |
| CVE-2024-35250 | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | KEVHIGH 7.8EPSS 25.0% | 11 June 2024 |
| CVE-2024-30088 | Microsoft Windows Kernel TOCTOU Race Condition Vulnerability | KEVHIGH 7.0EPSS 68.2% | 11 June 2024 |
| CVE-2024-36971 | Android Kernel Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 2.70% | 10 June 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.