SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 16 of 348

CVESummaryPriorityPublished
CVE-2025-4341A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01.MEDIUM 5.3EPSS 20.7%6 May 2025
CVE-2025-4270A vulnerability was found in TOTOLINK A720R 4.1.5cu.374.MEDIUM 6.9EPSS 13.1%5 May 2025
CVE-2025-2605Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse.HIGH 8.8EPSS 13.7%2 May 2025
CVE-2025-4185A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024.MEDIUM 5.3EPSS 11.4%2 May 2025
CVE-2025-36558KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication.MEDIUM 5.1EPSS 18.9%1 May 2025
CVE-2025-35996KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints.HIGH 8.5EPSS 17.3%1 May 2025
CVE-2025-32011KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.CRITICAL 9.3EPSS 27.3%1 May 2025
CVE-2025-27007Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.CRITICAL 9.8EPSS 51.5%1 May 2025
CVE-2025-4076A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22.MEDIUM 5.3EPSS 17.3%29 April 2025
CVE-2025-31650Improper Input Validation vulnerability in Apache Tomcat.HIGH 7.5EPSS 59.9%28 April 2025
CVE-2025-3983A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical.MEDIUM 5.1EPSS 14.5%27 April 2025
CVE-2025-3914The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0.HIGH 8.8EPSS 15.1%26 April 2025
CVE-2025-46618In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tabMEDIUM 6.1EPSS 61.7%25 April 2025
CVE-2025-32432Craft CMS Code Injection VulnerabilityKEVCRITICAL 10.0EPSS 99.8%25 April 2025
CVE-2025-43864If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page.HIGH 7.5EPSS 20.2%25 April 2025
CVE-2025-31324SAP NetWeaver Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 99.5%24 April 2025
CVE-2025-2760GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability.HIGH 7.8EPSS 12.7%23 April 2025
CVE-2025-32969In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database…CRITICAL 9.3EPSS 77.8%23 April 2025
CVE-2025-2703The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability.MEDIUM 6.8EPSS 16.1%23 April 2025
CVE-2025-34028Commvault Command Center Path Traversal VulnerabilityKEVCRITICAL 9.3EPSS 97.7%22 April 2025
CVE-2025-3577**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories…MEDIUM 4.9EPSS 12.0%22 April 2025
CVE-2025-3820A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical.HIGH 8.7EPSS 11.8%19 April 2025
CVE-2025-29513Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.MEDIUM 6.1EPSS 42.8%18 April 2025
CVE-2025-3785A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical.HIGH 8.7EPSS 11.4%18 April 2025
CVE-2025-32583Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.CRITICAL 9.9EPSS 19.0%17 April 2025
CVE-2025-32433Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 10.0EPSS 98.8%16 April 2025
CVE-2025-31201Apple Multiple Products Arbitrary Read and Write VulnerabilityKEVCRITICAL 9.8EPSS 13.9%16 April 2025
CVE-2025-31200Apple Multiple Products Memory Corruption VulnerabilityKEVCRITICAL 9.8EPSS 18.6%16 April 2025
CVE-2025-22037In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response.MEDIUM 5.5EPSS 67.6%16 April 2025
CVE-2025-3663A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513.MEDIUM 6.9EPSS 11.2%16 April 2025
CVE-2025-27892Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint.MEDIUM 6.8EPSS 12.0%15 April 2025
CVE-2025-32778A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check).CRITICAL 9.3EPSS 19.6%15 April 2025
CVE-2025-28137The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.CRITICAL 9.8EPSS 33.6%15 April 2025
CVE-2025-32103CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.MEDIUM 5.0EPSS 16.9%15 April 2025
CVE-2025-2563The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privilegesHIGH 8.1EPSS 48.8%14 April 2025
CVE-2025-3538A vulnerability was found in D-Link DI-8100 16.07.26A1.HIGH 8.7EPSS 13.2%13 April 2025
CVE-2025-2636The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter.HIGH 8.1EPSS 10.4%11 April 2025
CVE-2025-3102The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in…HIGH 8.1EPSS 76.1%10 April 2025
CVE-2024-58136Yiiframework Yii Improper Protection of Alternate Path VulnerabilityKEVCRITICAL 9.8EPSS 87.6%10 April 2025
CVE-2025-32375Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server.CRITICAL 9.8EPSS 52.1%9 April 2025
CVE-2025-30294ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass.MEDIUM 6.8EPSS 17.2%8 April 2025
CVE-2025-30292ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability.MEDIUM 6.1EPSS 15.5%8 April 2025
CVE-2025-30290ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass.HIGH 8.7EPSS 19.5%8 April 2025
CVE-2025-30285ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 8.4EPSS 30.9%8 April 2025
CVE-2025-30281ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution.CRITICAL 9.1EPSS 23.6%8 April 2025
CVE-2025-29824Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 13.9%8 April 2025
CVE-2025-29793Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.HIGH 7.2EPSS 23.6%8 April 2025
CVE-2025-27480Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.HIGH 8.1EPSS 12.5%8 April 2025
CVE-2025-26670Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.HIGH 8.1EPSS 11.1%8 April 2025
CVE-2024-48887A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted requestCRITICAL 9.8EPSS 15.7%8 April 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.