Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 13 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.1EPSS 12.7% | 30 June 2025 |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVHIGH 7.8EPSS 59.4% | 30 June 2025 |
| CVE-2025-6898 | A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. | LOW 2.1EPSS 12.4% | 30 June 2025 |
| CVE-2025-5306 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. | HIGH 7.0EPSS 32.0% | 27 June 2025 |
| CVE-2025-20282 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. | CRITICAL 10.0EPSS 27.0% | 25 June 2025 |
| CVE-2025-20281 | Cisco Identity Services Engine Injection Vulnerability | KEVCRITICAL 10.0EPSS 97.1% | 25 June 2025 |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | KEVCRITICAL 9.2EPSS 10.1% | 25 June 2025 |
| CVE-2024-51978 | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. | CRITICAL 9.8EPSS 18.7% | 25 June 2025 |
| CVE-2024-51977 | An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. | MEDIUM 5.3EPSS 72.6% | 25 June 2025 |
| CVE-2025-34040 | An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. | CRITICAL 10.0EPSS 15.1% | 24 June 2025 |
| CVE-2025-34037 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. | CRITICAL 10.0EPSS 90.9% | 24 June 2025 |
| CVE-2025-34036 | An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. | CRITICAL 10.0EPSS 27.3% | 24 June 2025 |
| CVE-2025-34035 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. | CRITICAL 10.0EPSS 12.5% | 24 June 2025 |
| CVE-2025-2828 | A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. | CRITICAL 10.0EPSS 18.5% | 23 June 2025 |
| CVE-2025-52877 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | MEDIUM 4.8EPSS 23.8% | 23 June 2025 |
| CVE-2025-52876 | In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible | MEDIUM 5.4EPSS 24.5% | 23 June 2025 |
| CVE-2025-2172 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames | MEDIUM 6.6EPSS 10.2% | 23 June 2025 |
| CVE-2025-52488 | In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. | HIGH 8.6EPSS 35.8% | 21 June 2025 |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability | KEVHIGH 7.8EPSS 90.5% | 21 June 2025 |
| CVE-2025-6216 | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. | CRITICAL 9.8EPSS 38.5% | 21 June 2025 |
| CVE-2025-34030 | An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. | CRITICAL 10.0EPSS 60.4% | 20 June 2025 |
| CVE-2025-5121 | A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group. | CRITICAL 9.9EPSS 10.5% | 20 June 2025 |
| CVE-2025-49132 | Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. | CRITICAL 10.0EPSS 54.7% | 20 June 2025 |
| CVE-2025-24286 | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. | MEDIUM 4.9EPSS 14.8% | 19 June 2025 |
| CVE-2025-23121 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | HIGH 8.8EPSS 22.2% | 19 June 2025 |
| CVE-2025-6191 | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | HIGH 8.8EPSS 10.3% | 18 June 2025 |
| CVE-2025-49213 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. | CRITICAL 9.8EPSS 10.2% | 17 June 2025 |
| CVE-2025-49212 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. | CRITICAL 9.8EPSS 10.2% | 17 June 2025 |
| CVE-2025-34511 | Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. | HIGH 8.8EPSS 22.3% | 17 June 2025 |
| CVE-2025-34510 | Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. | HIGH 8.8EPSS 18.0% | 17 June 2025 |
| CVE-2025-34509 | 011941 PRE contain a hardcoded user account. | HIGH 7.5EPSS 55.3% | 17 June 2025 |
| CVE-2025-34508 | A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. | MEDIUM 5.3EPSS 69.1% | 17 June 2025 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | KEVCRITICAL 9.3EPSS 100.0% | 17 June 2025 |
| CVE-2025-48988 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. | HIGH 7.5EPSS 59.5% | 16 June 2025 |
| CVE-2025-48976 | Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. | HIGH 7.5EPSS 62.6% | 16 June 2025 |
| CVE-2025-5964 | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. | HIGH 8.4EPSS 14.3% | 15 June 2025 |
| CVE-2025-49596 | Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. | CRITICAL 9.4EPSS 44.5% | 13 June 2025 |
| CVE-2025-45988 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the… | CRITICAL 9.8EPSS 10.9% | 13 June 2025 |
| CVE-2025-47959 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network. | HIGH 7.1EPSS 10.7% | 13 June 2025 |
| CVE-2025-4278 | Under certain conditions html injection in new search page could lead to account takeover. | HIGH 8.7EPSS 10.6% | 12 June 2025 |
| CVE-2025-5301 | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. | MEDIUM 6.1EPSS 62.4% | 12 June 2025 |
| CVE-2025-5959 | Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | HIGH 8.8EPSS 13.3% | 11 June 2025 |
| CVE-2025-47166 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | HIGH 8.8EPSS 21.2% | 10 June 2025 |
| CVE-2025-47163 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | HIGH 8.8EPSS 20.5% | 10 June 2025 |
| CVE-2025-33073 | Microsoft Windows SMB Client Improper Access Control Vulnerability | KEVHIGH 8.8EPSS 82.7% | 10 June 2025 |
| CVE-2025-33071 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | HIGH 8.1EPSS 23.2% | 10 June 2025 |
| CVE-2025-33053 | Microsoft Windows External Control of File Name or Path Vulnerability | KEVHIGH 8.8EPSS 87.6% | 10 June 2025 |
| CVE-2025-30220 | GeoServer is an open source server that allows users to share and edit geospatial data. | CRITICAL 9.1EPSS 41.4% | 10 June 2025 |
| CVE-2025-27817 | A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. | HIGH 7.5EPSS 68.8% | 10 June 2025 |
| CVE-2025-5905 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. | HIGH 7.4EPSS 11.3% | 10 June 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.