Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 11 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-53778 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | HIGH 8.8EPSS 38.9% | 12 August 2025 |
| CVE-2025-53772 | Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. | HIGH 8.8EPSS 23.9% | 12 August 2025 |
| CVE-2025-53760 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | HIGH 7.1EPSS 12.7% | 12 August 2025 |
| CVE-2025-53722 | Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. | HIGH 7.5EPSS 18.8% | 12 August 2025 |
| CVE-2025-50154 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | MEDIUM 6.5EPSS 25.6% | 12 August 2025 |
| CVE-2025-49712 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | HIGH 8.8EPSS 20.0% | 12 August 2025 |
| CVE-2024-32640 | Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. | CRITICAL 9.8EPSS 71.6% | 11 August 2025 |
| CVE-2025-25231 | Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. | HIGH 7.5EPSS 21.3% | 11 August 2025 |
| CVE-2025-8356 | In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. | CRITICAL 9.8EPSS 15.5% | 8 August 2025 |
| CVE-2025-8088 | RARLAB WinRAR Path Traversal Vulnerability | KEVHIGH 8.4EPSS 94.6% | 8 August 2025 |
| CVE-2025-34152 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. | CRITICAL 9.4EPSS 69.1% | 7 August 2025 |
| CVE-2025-47188 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a… | MEDIUM 6.5EPSS 50.2% | 7 August 2025 |
| CVE-2025-7769 | Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. | HIGH 8.7EPSS 16.5% | 6 August 2025 |
| CVE-2013-10069 | The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. | CRITICAL 10.0EPSS 11.9% | 5 August 2025 |
| CVE-2025-54254 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. | HIGH 8.6EPSS 77.2% | 5 August 2025 |
| CVE-2025-54253 | Adobe Experience Manager Forms Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 88.0% | 5 August 2025 |
| CVE-2025-54987 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | CRITICAL 9.8EPSS 18.1% | 5 August 2025 |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 22.0% | 5 August 2025 |
| CVE-2025-53417 | DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability | CRITICAL 9.3EPSS 12.6% | 5 August 2025 |
| CVE-2025-36604 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. | CRITICAL 9.8EPSS 63.0% | 4 August 2025 |
| CVE-2025-6205 | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability | KEVCRITICAL 9.1EPSS 73.3% | 4 August 2025 |
| CVE-2025-6204 | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability | KEVHIGH 8.0EPSS 77.3% | 4 August 2025 |
| CVE-2025-20702 | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. | HIGH 8.8EPSS 11.2% | 4 August 2025 |
| CVE-2025-54782 | In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. | CRITICAL 9.4EPSS 51.3% | 2 August 2025 |
| CVE-2025-54136 | In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an already trusted MCP configuration file inside a shared GitHub repository or editing the file locally on the target's machine. | HIGH 8.8EPSS 27.1% | 2 August 2025 |
| CVE-2013-10059 | An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. | HIGH 8.6EPSS 19.1% | 1 August 2025 |
| CVE-2013-10048 | An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. | CRITICAL 9.3EPSS 12.1% | 1 August 2025 |
| CVE-2025-54574 | In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. | CRITICAL 9.8EPSS 22.7% | 1 August 2025 |
| CVE-2025-46811 | A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. | CRITICAL 9.3EPSS 10.7% | 30 July 2025 |
| CVE-2025-54381 | In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. | CRITICAL 9.9EPSS 14.0% | 29 July 2025 |
| CVE-2025-5120 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). | CRITICAL 10.0EPSS 22.8% | 27 July 2025 |
| CVE-2025-8159 | A vulnerability was found in D-Link DIR-513 1.0. | HIGH 7.4EPSS 15.6% | 25 July 2025 |
| CVE-2025-8155 | A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. | LOW 2.0EPSS 17.3% | 25 July 2025 |
| CVE-2019-25224 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. | CRITICAL 9.8EPSS 21.4% | 25 July 2025 |
| CVE-2025-32429 | In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. | CRITICAL 9.3EPSS 85.3% | 24 July 2025 |
| CVE-2025-40598 | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code. | MEDIUM 6.1EPSS 50.7% | 23 July 2025 |
| CVE-2025-40597 | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. | HIGH 7.5EPSS 29.4% | 23 July 2025 |
| CVE-2025-40596 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution. | HIGH 7.3EPSS 56.5% | 23 July 2025 |
| CVE-2025-40599 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. | CRITICAL 9.1EPSS 13.0% | 23 July 2025 |
| CVE-2025-54453 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | CRITICAL 9.8EPSS 21.9% | 23 July 2025 |
| CVE-2025-54445 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0. | CRITICAL 9.8EPSS 11.0% | 23 July 2025 |
| CVE-2025-51471 | Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint. | MEDIUM 6.9EPSS 14.2% | 22 July 2025 |
| CVE-2025-34143 | An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. | CRITICAL 9.3EPSS 31.9% | 22 July 2025 |
| CVE-2025-7952 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. | LOW 2.1EPSS 18.2% | 22 July 2025 |
| CVE-2025-53771 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | MEDIUM 6.5EPSS 99.7% | 20 July 2025 |
| CVE-2025-53770 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 20 July 2025 |
| CVE-2025-27210 | This vulnerability affects Windows users of `path.join` API. | HIGH 7.5EPSS 14.9% | 18 July 2025 |
| CVE-2025-54309 | CrushFTP Unprotected Alternate Channel Vulnerability | KEVCRITICAL 9.8EPSS 94.7% | 18 July 2025 |
| CVE-2025-6197 | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. | MEDIUM 4.2EPSS 70.1% | 18 July 2025 |
| CVE-2025-6023 | An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. | HIGH 7.6EPSS 42.1% | 18 July 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.