SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 13 of 348

CVESummaryPriorityPublished
CVE-2025-6554Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.1EPSS 12.7%30 June 2025
CVE-2025-32463Sudo Inclusion of Functionality from Untrusted Control Sphere VulnerabilityKEVHIGH 7.8EPSS 59.4%30 June 2025
CVE-2025-6898A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1.LOW 2.1EPSS 12.4%30 June 2025
CVE-2025-5306Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection.HIGH 7.0EPSS 32.0%27 June 2025
CVE-2025-20282A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.CRITICAL 10.0EPSS 27.0%25 June 2025
CVE-2025-20281Cisco Identity Services Engine Injection VulnerabilityKEVCRITICAL 10.0EPSS 97.1%25 June 2025
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow VulnerabilityKEVCRITICAL 9.2EPSS 10.1%25 June 2025
CVE-2024-51978An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device.CRITICAL 9.8EPSS 18.7%25 June 2025
CVE-2024-51977An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device.MEDIUM 5.3EPSS 72.6%25 June 2025
CVE-2025-34040An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface.CRITICAL 10.0EPSS 15.1%24 June 2025
CVE-2025-34037An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080.CRITICAL 10.0EPSS 90.9%24 June 2025
CVE-2025-34036An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82.CRITICAL 10.0EPSS 27.3%24 June 2025
CVE-2025-34035An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier.CRITICAL 10.0EPSS 12.5%24 June 2025
CVE-2025-2828A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27.CRITICAL 10.0EPSS 18.5%23 June 2025
CVE-2025-52877In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possibleMEDIUM 4.8EPSS 23.8%23 June 2025
CVE-2025-52876In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possibleMEDIUM 5.4EPSS 24.5%23 June 2025
CVE-2025-2172Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenamesMEDIUM 6.6EPSS 10.2%23 June 2025
CVE-2025-52488In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server.HIGH 8.6EPSS 35.8%21 June 2025
CVE-2025-6218RARLAB WinRAR Path Traversal VulnerabilityKEVHIGH 7.8EPSS 90.5%21 June 2025
CVE-2025-6216Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability.CRITICAL 9.8EPSS 38.5%21 June 2025
CVE-2025-34030An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php.CRITICAL 10.0EPSS 60.4%20 June 2025
CVE-2025-5121A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.CRITICAL 9.9EPSS 10.5%20 June 2025
CVE-2025-49132Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated.CRITICAL 10.0EPSS 54.7%20 June 2025
CVE-2025-24286A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.MEDIUM 4.9EPSS 14.8%19 June 2025
CVE-2025-23121A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain userHIGH 8.8EPSS 22.2%19 June 2025
CVE-2025-6191Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.HIGH 8.8EPSS 10.3%18 June 2025
CVE-2025-49213An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations.CRITICAL 9.8EPSS 10.2%17 June 2025
CVE-2025-49212An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations.CRITICAL 9.8EPSS 10.2%17 June 2025
CVE-2025-34511Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue.HIGH 8.8EPSS 22.3%17 June 2025
CVE-2025-34510Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability.HIGH 8.8EPSS 18.0%17 June 2025
CVE-2025-34509011941 PRE contain a hardcoded user account.HIGH 7.5EPSS 55.3%17 June 2025
CVE-2025-34508A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior.MEDIUM 5.3EPSS 69.1%17 June 2025
CVE-2025-5777Citrix NetScaler ADC and Gateway Out-of-Bounds Read VulnerabilityKEVCRITICAL 9.3EPSS 100.0%17 June 2025
CVE-2025-48988Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.HIGH 7.5EPSS 59.5%16 June 2025
CVE-2025-48976Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.HIGH 7.5EPSS 62.6%16 June 2025
CVE-2025-5964A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.HIGH 8.4EPSS 14.3%15 June 2025
CVE-2025-49596Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio.CRITICAL 9.4EPSS 44.5%13 June 2025
CVE-2025-45988Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the…CRITICAL 9.8EPSS 10.9%13 June 2025
CVE-2025-47959Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.HIGH 7.1EPSS 10.7%13 June 2025
CVE-2025-4278Under certain conditions html injection in new search page could lead to account takeover.HIGH 8.7EPSS 10.6%12 June 2025
CVE-2025-5301ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol.MEDIUM 6.1EPSS 62.4%12 June 2025
CVE-2025-5959Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.HIGH 8.8EPSS 13.3%11 June 2025
CVE-2025-47166Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.HIGH 8.8EPSS 21.2%10 June 2025
CVE-2025-47163Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.HIGH 8.8EPSS 20.5%10 June 2025
CVE-2025-33073Microsoft Windows SMB Client Improper Access Control VulnerabilityKEVHIGH 8.8EPSS 82.7%10 June 2025
CVE-2025-33071Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.HIGH 8.1EPSS 23.2%10 June 2025
CVE-2025-33053 Microsoft Windows External Control of File Name or Path VulnerabilityKEVHIGH 8.8EPSS 87.6%10 June 2025
CVE-2025-30220GeoServer is an open source server that allows users to share and edit geospatial data.CRITICAL 9.1EPSS 41.4%10 June 2025
CVE-2025-27817A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client.HIGH 7.5EPSS 68.8%10 June 2025
CVE-2025-5905A vulnerability was found in TOTOLINK T10 4.1.8cu.5207.HIGH 7.4EPSS 11.3%10 June 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.