SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,014 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 16 September 2026

17,375 results · page 14 of 348

CVESummaryPriorityPublished
CVE-2025-5904A vulnerability was found in TOTOLINK T10 4.1.8cu.5207.HIGH 7.4EPSS 11.0%10 June 2025
CVE-2025-5903A vulnerability was found in TOTOLINK T10 4.1.8cu.5207.HIGH 7.4EPSS 11.0%10 June 2025
CVE-2025-49619Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block.HIGH 8.5EPSS 20.0%7 June 2025
CVE-2025-5473GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability.HIGH 8.8EPSS 23.5%6 June 2025
CVE-2025-41646An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion.CRITICAL 9.8EPSS 51.5%6 June 2025
CVE-2025-5623A vulnerability was found in D-Link DIR-816 1.10CNB05.CRITICAL 9.3EPSS 18.5%5 June 2025
CVE-2025-5573A vulnerability was found in D-Link DCS-932L 2.18.01.MEDIUM 5.3EPSS 13.8%4 June 2025
CVE-2025-5571A vulnerability was found in D-Link DCS-932L 2.18.01.MEDIUM 5.3EPSS 13.6%4 June 2025
CVE-2025-5548A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.MEDIUM 6.9EPSS 15.0%4 June 2025
CVE-2025-5527A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01.HIGH 8.7EPSS 11.9%3 June 2025
CVE-2025-49002Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited.HIGH 8.2EPSS 50.3%3 June 2025
CVE-2025-49001The vulnerability has been fixed in v2.10.10.HIGH 7.7EPSS 22.2%3 June 2025
CVE-2025-48999A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10.MEDIUM 6.8EPSS 10.0%3 June 2025
CVE-2025-44148Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx componentCRITICAL 9.8EPSS 54.7%3 June 2025
CVE-2025-5504A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical.MEDIUM 5.3EPSS 12.9%3 June 2025
CVE-2025-5086Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.0EPSS 91.9%2 June 2025
CVE-2025-20297In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious…MEDIUM 5.4EPSS 25.9%2 June 2025
CVE-2024-7074An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services.MEDIUM 6.8EPSS 17.2%2 June 2025
CVE-2025-5447A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 32.2%2 June 2025
CVE-2025-5446A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 18.1%2 June 2025
CVE-2025-5445A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical.MEDIUM 5.3EPSS 17.9%2 June 2025
CVE-2025-5444A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical.MEDIUM 5.3EPSS 14.9%2 June 2025
CVE-2025-5443A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 17.9%2 June 2025
CVE-2025-5442A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 18.1%2 June 2025
CVE-2025-5441A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 18.1%2 June 2025
CVE-2025-5438A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001.MEDIUM 5.3EPSS 26.1%2 June 2025
CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 98.9%2 June 2025
CVE-2025-48047An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.CRITICAL 9.4EPSS 15.7%29 May 2025
CVE-2025-48927TeleMessage TM SGNL Initialization of a Resource with an Insecure Default VulnerabilityKEVMEDIUM 5.3EPSS 11.1%28 May 2025
CVE-2025-4009This device exposes a web management interface on port 80.CRITICAL 9.3EPSS 71.4%28 May 2025
CVE-2025-48828Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine.HIGH 8.1EPSS 57.6%27 May 2025
CVE-2025-48827vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in…CRITICAL 9.8EPSS 75.8%27 May 2025
CVE-2025-43860A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the (1) Text…HIGH 7.6EPSS 14.1%23 May 2025
CVE-2025-32794A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the First and Last Name…HIGH 7.6EPSS 14.4%23 May 2025
CVE-2025-47646Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from…CRITICAL 9.8EPSS 24.9%23 May 2025
CVE-2025-47539Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26.CRITICAL 9.8EPSS 27.9%23 May 2025
CVE-2025-36527Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.HIGH 8.3EPSS 36.5%23 May 2025
CVE-2025-32815Authentication Bypass via a Hardcoded credential can occur.MEDIUM 6.5EPSS 39.7%22 May 2025
CVE-2025-32814Unauthenticated SQL Injection can occur.CRITICAL 9.8EPSS 36.4%22 May 2025
CVE-2025-32813Remote Unauthenticated Command Injection can occur.HIGH 7.2EPSS 43.9%22 May 2025
CVE-2025-3943Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection.HIGH 7.5EPSS 10.4%22 May 2025
CVE-2025-4123A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect.MEDIUM 6.1EPSS 97.0%22 May 2025
CVE-2025-34027The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints.CRITICAL 10.0EPSS 45.2%21 May 2025
CVE-2025-34026Versa Concerto Improper Authentication VulnerabilityKEVCRITICAL 9.2EPSS 81.9%21 May 2025
CVE-2025-4008Smartbedded Meteobridge Command Injection VulnerabilityKEVHIGH 8.7EPSS 93.7%21 May 2025
CVE-2025-40775When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it.HIGH 7.5EPSS 15.2%21 May 2025
CVE-2025-4524The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter.CRITICAL 9.8EPSS 10.4%21 May 2025
CVE-2025-4094The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.CRITICAL 9.8EPSS 15.8%21 May 2025
CVE-2025-44084D-link DI-8100 16.07.26A1 is vulnerable to Command Injection.CRITICAL 9.8EPSS 20.1%20 May 2025
CVE-2025-37924In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user.HIGH 7.8EPSS 20.7%20 May 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.