Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 12 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-54068 | Laravel Livewire Code Injection Vulnerability | KEVCRITICAL 9.2EPSS 96.5% | 17 July 2025 |
| CVE-2025-25257 | Fortinet FortiWeb SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 17 July 2025 |
| CVE-2025-34117 | A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. | CRITICAL 9.3EPSS 27.9% | 16 July 2025 |
| CVE-2025-20337 | Cisco Identity Services Engine Injection Vulnerability | KEVCRITICAL 10.0EPSS 67.0% | 16 July 2025 |
| CVE-2025-20284 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. | HIGH 7.2EPSS 16.1% | 16 July 2025 |
| CVE-2025-34300 | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. | CRITICAL 10.0EPSS 78.1% | 16 July 2025 |
| CVE-2025-52690 | Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point. | HIGH 8.1EPSS 10.7% | 16 July 2025 |
| CVE-2025-52689 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spoofing the login request, potentially allowing the attacker to modify the behaviour of the access point. | CRITICAL 9.8EPSS 12.8% | 16 July 2025 |
| CVE-2025-52688 | Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point. | CRITICAL 9.8EPSS 25.9% | 16 July 2025 |
| CVE-2025-52379 | Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update feature. | MEDIUM 5.4EPSS 13.5% | 15 July 2025 |
| CVE-2025-52378 | Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing attackers to inject JavaScript code that is executed in the context of administrator sessions when viewing the device management page… | MEDIUM 5.4EPSS 13.9% | 15 July 2025 |
| CVE-2025-52377 | Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbitrary commands on the device. | MEDIUM 5.4EPSS 12.6% | 15 July 2025 |
| CVE-2025-6965 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. | HIGH 7.2EPSS 72.5% | 15 July 2025 |
| CVE-2025-52376 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security… | CRITICAL 9.8EPSS 11.2% | 15 July 2025 |
| CVE-2025-5394 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. | CRITICAL 9.8EPSS 52.8% | 15 July 2025 |
| CVE-2024-58258 | SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur. | HIGH 7.2EPSS 16.3% | 13 July 2025 |
| CVE-2020-36847 | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. | CRITICAL 9.8EPSS 44.2% | 12 July 2025 |
| CVE-2013-3307 | Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000. | HIGH 8.3EPSS 55.7% | 11 July 2025 |
| CVE-2025-50121 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. | CRITICAL 9.5EPSS 19.3% | 11 July 2025 |
| CVE-2025-7414 | A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). | LOW 2.1EPSS 12.6% | 10 July 2025 |
| CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability | KEVMEDIUM 4.3EPSS 63.0% | 10 July 2025 |
| CVE-2025-47812 | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | KEVCRITICAL 10.0EPSS 92.9% | 10 July 2025 |
| CVE-2025-7407 | A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. | LOW 2.1EPSS 10.6% | 10 July 2025 |
| CVE-2025-6970 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied… | HIGH 7.5EPSS 65.6% | 9 July 2025 |
| CVE-2025-6514 | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL | CRITICAL 9.6EPSS 77.9% | 9 July 2025 |
| CVE-2025-34077 | An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. | CRITICAL 10.0EPSS 15.1% | 9 July 2025 |
| CVE-2025-7206 | A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. | HIGH 8.9EPSS 18.4% | 9 July 2025 |
| CVE-2025-49533 | Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. | CRITICAL 9.8EPSS 52.9% | 8 July 2025 |
| CVE-2025-49719 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. | HIGH 7.5EPSS 10.7% | 8 July 2025 |
| CVE-2025-49706 | Microsoft SharePoint Improper Authentication Vulnerability | KEVMEDIUM 6.5EPSS 99.1% | 8 July 2025 |
| CVE-2025-49704 | Microsoft SharePoint Code Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 8 July 2025 |
| CVE-2025-47984 | Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. | HIGH 7.5EPSS 16.2% | 8 July 2025 |
| CVE-2025-47981 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 32.6% | 8 July 2025 |
| CVE-2025-6771 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution | HIGH 7.2EPSS 19.7% | 8 July 2025 |
| CVE-2025-6770 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution | HIGH 7.2EPSS 16.8% | 8 July 2025 |
| CVE-2025-6793 | Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. | CRITICAL 9.4EPSS 17.3% | 7 July 2025 |
| CVE-2025-7088 | A vulnerability, which was classified as critical, was found in Belkin F9K1122 1.00.33. | HIGH 7.4EPSS 10.9% | 6 July 2025 |
| CVE-2025-7087 | A vulnerability classified as critical was found in Belkin F9K1122 1.00.33. | HIGH 7.4EPSS 10.5% | 6 July 2025 |
| CVE-2025-7083 | A vulnerability was found in Belkin F9K1122 1.00.33. | LOW 2.1EPSS 45.9% | 6 July 2025 |
| CVE-2025-7082 | A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. | LOW 2.1EPSS 16.9% | 6 July 2025 |
| CVE-2025-7081 | A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. | LOW 2.1EPSS 19.7% | 6 July 2025 |
| CVE-2025-47228 | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests. | MEDIUM 6.7EPSS 17.2% | 5 July 2025 |
| CVE-2025-5961 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. | HIGH 7.2EPSS 57.6% | 3 July 2025 |
| CVE-2025-34067 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. | CRITICAL 10.0EPSS 18.5% | 2 July 2025 |
| CVE-2025-6463 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and… | HIGH 8.8EPSS 12.4% | 2 July 2025 |
| CVE-2025-4380 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. | CRITICAL 9.8EPSS 40.4% | 2 July 2025 |
| CVE-2025-53107 | Prior to version 2.1.5, there is a command injection vulnerability caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject arbitrary system commands. | HIGH 7.5EPSS 27.5% | 1 July 2025 |
| CVE-2025-37098 | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | HIGH 7.5EPSS 37.2% | 1 July 2025 |
| CVE-2025-41656 | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | CRITICAL 10.0EPSS 12.7% | 1 July 2025 |
| CVE-2025-6934 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. | CRITICAL 9.8EPSS 26.4% | 1 July 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.