Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 16 September 2026
17,375 results · page 15 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-26086 | An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. | HIGH 7.5EPSS 14.1% | 20 May 2025 |
| CVE-2025-4978 | A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. | CRITICAL 9.3EPSS 21.0% | 20 May 2025 |
| CVE-2025-4322 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. | CRITICAL 9.8EPSS 15.5% | 20 May 2025 |
| CVE-2025-4902 | A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). | MEDIUM 6.9EPSS 13.5% | 19 May 2025 |
| CVE-2025-4901 | A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). | MEDIUM 5.3EPSS 77.3% | 19 May 2025 |
| CVE-2025-47931 | LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. | LOW 2.1EPSS 11.9% | 17 May 2025 |
| CVE-2025-47916 | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. | CRITICAL 9.8EPSS 83.7% | 16 May 2025 |
| CVE-2025-0133 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when… | LOW 2.7EPSS 46.4% | 14 May 2025 |
| CVE-2025-3600 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. | HIGH 7.5EPSS 24.1% | 14 May 2025 |
| CVE-2024-54780 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. | HIGH 8.8EPSS 12.1% | 14 May 2025 |
| CVE-2025-3833 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | HIGH 8.1EPSS 44.4% | 14 May 2025 |
| CVE-2025-43566 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. | MEDIUM 6.8EPSS 55.1% | 13 May 2025 |
| CVE-2025-43565 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. | HIGH 8.4EPSS 15.7% | 13 May 2025 |
| CVE-2025-43564 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. | CRITICAL 9.1EPSS 15.3% | 13 May 2025 |
| CVE-2025-43563 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. | CRITICAL 9.1EPSS 15.3% | 13 May 2025 |
| CVE-2025-43562 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the… | CRITICAL 9.1EPSS 45.1% | 13 May 2025 |
| CVE-2025-43561 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.1EPSS 20.6% | 13 May 2025 |
| CVE-2025-43560 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.1EPSS 19.4% | 13 May 2025 |
| CVE-2025-30397 | Microsoft Windows Scripting Engine Type Confusion Vulnerability | KEVHIGH 7.5EPSS 26.8% | 13 May 2025 |
| CVE-2025-30394 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. | MEDIUM 5.9EPSS 30.5% | 13 May 2025 |
| CVE-2025-29971 | Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network. | HIGH 7.5EPSS 64.4% | 13 May 2025 |
| CVE-2025-29962 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | HIGH 8.8EPSS 14.3% | 13 May 2025 |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVHIGH 8.8EPSS 86.2% | 13 May 2025 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 99.9% | 13 May 2025 |
| CVE-2025-45858 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function. | CRITICAL 9.8EPSS 10.7% | 13 May 2025 |
| CVE-2024-48766 | NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. | HIGH 8.6EPSS 69.7% | 13 May 2025 |
| CVE-2024-46506 | NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. | CRITICAL 10.0EPSS 62.0% | 13 May 2025 |
| CVE-2025-32756 | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 29.8% | 13 May 2025 |
| CVE-2025-4632 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 24.3% | 13 May 2025 |
| CVE-2025-42999 | SAP NetWeaver Deserialization Vulnerability | KEVCRITICAL 9.1EPSS 13.9% | 13 May 2025 |
| CVE-2025-4544 | A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. | HIGH 7.5EPSS 10.9% | 11 May 2025 |
| CVE-2025-47269 | Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. | HIGH 8.3EPSS 42.7% | 9 May 2025 |
| CVE-2025-4443 | A vulnerability was found in D-Link DIR-605L 2.13B01. | MEDIUM 5.3EPSS 57.6% | 9 May 2025 |
| CVE-2025-45797 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. | CRITICAL 9.8EPSS 17.5% | 8 May 2025 |
| CVE-2025-32873 | The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. | MEDIUM 5.3EPSS 13.6% | 8 May 2025 |
| CVE-2025-31644 | When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system… | HIGH 8.5EPSS 26.5% | 7 May 2025 |
| CVE-2025-32821 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance. | HIGH 7.2EPSS 19.9% | 7 May 2025 |
| CVE-2025-20188 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to… | CRITICAL 10.0EPSS 27.1% | 7 May 2025 |
| CVE-2025-2777 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. | CRITICAL 9.8EPSS 72.2% | 7 May 2025 |
| CVE-2025-2776 | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | KEVCRITICAL 9.8EPSS 64.4% | 7 May 2025 |
| CVE-2025-2775 | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | KEVHIGH 7.5EPSS 43.0% | 7 May 2025 |
| CVE-2025-25014 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. | CRITICAL 9.8EPSS 21.5% | 6 May 2025 |
| CVE-2025-45488 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter. | CRITICAL 9.8EPSS 11.1% | 6 May 2025 |
| CVE-2025-45487 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. | CRITICAL 9.8EPSS 11.0% | 6 May 2025 |
| CVE-2025-4357 | A vulnerability was found in Tenda RX3 16.03.13.11_multi. | MEDIUM 5.1EPSS 15.0% | 6 May 2025 |
| CVE-2025-2011 | The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | HIGH 7.5EPSS 46.4% | 6 May 2025 |
| CVE-2025-4341 | A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. | MEDIUM 5.3EPSS 20.7% | 6 May 2025 |
| CVE-2025-4270 | A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. | MEDIUM 6.9EPSS 13.1% | 5 May 2025 |
| CVE-2025-2605 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. | HIGH 8.8EPSS 13.7% | 2 May 2025 |
| CVE-2025-4185 | A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. | MEDIUM 5.3EPSS 11.4% | 2 May 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.