Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 16 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-4341 | A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. | MEDIUM 5.3EPSS 20.7% | 6 May 2025 |
| CVE-2025-4270 | A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. | MEDIUM 6.9EPSS 13.1% | 5 May 2025 |
| CVE-2025-2605 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. | HIGH 8.8EPSS 13.7% | 2 May 2025 |
| CVE-2025-4185 | A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. | MEDIUM 5.3EPSS 11.4% | 2 May 2025 |
| CVE-2025-36558 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. | MEDIUM 5.1EPSS 18.9% | 1 May 2025 |
| CVE-2025-35996 | KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. | HIGH 8.5EPSS 17.3% | 1 May 2025 |
| CVE-2025-32011 | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal. | CRITICAL 9.3EPSS 27.3% | 1 May 2025 |
| CVE-2025-27007 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | CRITICAL 9.8EPSS 51.5% | 1 May 2025 |
| CVE-2025-4076 | A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. | MEDIUM 5.3EPSS 17.3% | 29 April 2025 |
| CVE-2025-31650 | Improper Input Validation vulnerability in Apache Tomcat. | HIGH 7.5EPSS 59.9% | 28 April 2025 |
| CVE-2025-3983 | A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. | MEDIUM 5.1EPSS 14.5% | 27 April 2025 |
| CVE-2025-3914 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. | HIGH 8.8EPSS 15.1% | 26 April 2025 |
| CVE-2025-46618 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | MEDIUM 6.1EPSS 61.7% | 25 April 2025 |
| CVE-2025-32432 | Craft CMS Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 25 April 2025 |
| CVE-2025-43864 | If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. | HIGH 7.5EPSS 20.2% | 25 April 2025 |
| CVE-2025-31324 | SAP NetWeaver Unrestricted File Upload Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 24 April 2025 |
| CVE-2025-2760 | GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. | HIGH 7.8EPSS 12.7% | 23 April 2025 |
| CVE-2025-32969 | In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database… | CRITICAL 9.3EPSS 77.8% | 23 April 2025 |
| CVE-2025-2703 | The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. | MEDIUM 6.8EPSS 16.1% | 23 April 2025 |
| CVE-2025-34028 | Commvault Command Center Path Traversal Vulnerability | KEVCRITICAL 9.3EPSS 97.7% | 22 April 2025 |
| CVE-2025-3577 | **UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories… | MEDIUM 4.9EPSS 12.0% | 22 April 2025 |
| CVE-2025-3820 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. | HIGH 8.7EPSS 11.8% | 19 April 2025 |
| CVE-2025-29513 | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator. | MEDIUM 6.1EPSS 42.8% | 18 April 2025 |
| CVE-2025-3785 | A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. | HIGH 8.7EPSS 11.4% | 18 April 2025 |
| CVE-2025-32583 | Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0. | CRITICAL 9.9EPSS 19.0% | 17 April 2025 |
| CVE-2025-32433 | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 10.0EPSS 98.8% | 16 April 2025 |
| CVE-2025-31201 | Apple Multiple Products Arbitrary Read and Write Vulnerability | KEVCRITICAL 9.8EPSS 13.9% | 16 April 2025 |
| CVE-2025-31200 | Apple Multiple Products Memory Corruption Vulnerability | KEVCRITICAL 9.8EPSS 18.6% | 16 April 2025 |
| CVE-2025-22037 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. | MEDIUM 5.5EPSS 67.6% | 16 April 2025 |
| CVE-2025-3663 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | MEDIUM 6.9EPSS 11.2% | 16 April 2025 |
| CVE-2025-27892 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. | MEDIUM 6.8EPSS 12.0% | 15 April 2025 |
| CVE-2025-32778 | A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). | CRITICAL 9.3EPSS 19.6% | 15 April 2025 |
| CVE-2025-28137 | The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. | CRITICAL 9.8EPSS 33.6% | 15 April 2025 |
| CVE-2025-32103 | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions. | MEDIUM 5.0EPSS 16.9% | 15 April 2025 |
| CVE-2025-2563 | The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges | HIGH 8.1EPSS 48.8% | 14 April 2025 |
| CVE-2025-3538 | A vulnerability was found in D-Link DI-8100 16.07.26A1. | HIGH 8.7EPSS 13.2% | 13 April 2025 |
| CVE-2025-2636 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. | HIGH 8.1EPSS 10.4% | 11 April 2025 |
| CVE-2025-3102 | The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in… | HIGH 8.1EPSS 76.1% | 10 April 2025 |
| CVE-2024-58136 | Yiiframework Yii Improper Protection of Alternate Path Vulnerability | KEVCRITICAL 9.8EPSS 87.6% | 10 April 2025 |
| CVE-2025-32375 | Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. | CRITICAL 9.8EPSS 52.1% | 9 April 2025 |
| CVE-2025-30294 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. | MEDIUM 6.8EPSS 17.2% | 8 April 2025 |
| CVE-2025-30292 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | MEDIUM 6.1EPSS 15.5% | 8 April 2025 |
| CVE-2025-30290 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. | HIGH 8.7EPSS 19.5% | 8 April 2025 |
| CVE-2025-30285 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 8.4EPSS 30.9% | 8 April 2025 |
| CVE-2025-30281 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. | CRITICAL 9.1EPSS 23.6% | 8 April 2025 |
| CVE-2025-29824 | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 13.9% | 8 April 2025 |
| CVE-2025-29793 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | HIGH 7.2EPSS 23.6% | 8 April 2025 |
| CVE-2025-27480 | Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | HIGH 8.1EPSS 12.5% | 8 April 2025 |
| CVE-2025-26670 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | HIGH 8.1EPSS 11.1% | 8 April 2025 |
| CVE-2024-48887 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request | CRITICAL 9.8EPSS 15.7% | 8 April 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.