Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 18 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-4990 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. | CRITICAL 9.1EPSS 80.2% | 20 March 2025 |
| CVE-2024-50631 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL… | HIGH 7.5EPSS 26.2% | 19 March 2025 |
| CVE-2024-50630 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors. | HIGH 7.5EPSS 24.6% | 19 March 2025 |
| CVE-2024-50629 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote… | MEDIUM 5.3EPSS 28.9% | 19 March 2025 |
| CVE-2025-24801 | An authenticated user can upload and force the execution of *.php files located on the GLPI server. | HIGH 8.8EPSS 21.0% | 18 March 2025 |
| CVE-2025-24799 | An unauthenticated user can perform a SQL injection through the inventory endpoint. | CRITICAL 9.8EPSS 86.3% | 18 March 2025 |
| CVE-2025-2449 | NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. | HIGH 8.8EPSS 33.7% | 18 March 2025 |
| CVE-2024-12971 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6 | HIGH 8.6EPSS 60.6% | 17 March 2025 |
| CVE-2025-2359 | A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. | MEDIUM 6.9EPSS 15.4% | 17 March 2025 |
| CVE-2025-30066 | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability | KEVHIGH 8.6EPSS 69.8% | 15 March 2025 |
| CVE-2023-33300 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server… | MEDIUM 5.3EPSS 13.7% | 14 March 2025 |
| CVE-2025-2264 | A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". | HIGH 7.5EPSS 34.8% | 13 March 2025 |
| CVE-2025-25292 | An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. | CRITICAL 9.3EPSS 65.1% | 12 March 2025 |
| CVE-2025-25291 | An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. | CRITICAL 9.3EPSS 20.6% | 12 March 2025 |
| CVE-2025-29891 | Bypass/Injection vulnerability in Apache Camel. | MEDIUM 4.8EPSS 73.4% | 12 March 2025 |
| CVE-2025-22954 | GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter. | CRITICAL 10.0EPSS 25.6% | 12 March 2025 |
| CVE-2025-26633 | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability | KEVHIGH 7.0EPSS 30.4% | 11 March 2025 |
| CVE-2025-24071 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | MEDIUM 6.5EPSS 22.9% | 11 March 2025 |
| CVE-2025-24054 | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability | KEVMEDIUM 5.4EPSS 58.9% | 11 March 2025 |
| CVE-2024-54018 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. | HIGH 7.2EPSS 10.0% | 11 March 2025 |
| CVE-2025-27363 | FreeType Out-of-Bounds Write Vulnerability | KEVHIGH 8.1EPSS 27.8% | 11 March 2025 |
| CVE-2024-54085 | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | KEVCRITICAL 10.0EPSS 60.7% | 11 March 2025 |
| CVE-2025-1661 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. | CRITICAL 9.8EPSS 56.4% | 11 March 2025 |
| CVE-2025-24813 | Apache Tomcat Path Equivalence Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 10 March 2025 |
| CVE-2025-2126 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. | MEDIUM 5.3EPSS 11.2% | 9 March 2025 |
| CVE-2025-27636 | Bypass/Injection vulnerability in Apache Camel components under particular conditions. | MEDIUM 5.6EPSS 81.1% | 9 March 2025 |
| CVE-2025-2094 | A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. | MEDIUM 5.3EPSS 13.0% | 7 March 2025 |
| CVE-2025-1316 | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | KEVCRITICAL 9.3EPSS 74.5% | 5 March 2025 |
| CVE-2025-26319 | FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. | CRITICAL 9.8EPSS 55.9% | 4 March 2025 |
| CVE-2025-0370 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. | MEDIUM 5.4EPSS 35.6% | 4 March 2025 |
| CVE-2024-48248 | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | KEVHIGH 8.6EPSS 94.4% | 4 March 2025 |
| CVE-2025-27423 | Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. | HIGH 7.1EPSS 22.5% | 3 March 2025 |
| CVE-2025-27590 | In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. | CRITICAL 9.8EPSS 27.6% | 3 March 2025 |
| CVE-2025-1829 | A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. | MEDIUM 5.3EPSS 12.1% | 2 March 2025 |
| CVE-2025-26466 | A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. | MEDIUM 5.9EPSS 39.8% | 28 February 2025 |
| CVE-2025-26264 | GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. | HIGH 8.8EPSS 23.0% | 27 February 2025 |
| CVE-2024-53944 | A unauthenticated remote attacker with network access can exploit a command injection vulnerability. | CRITICAL 9.8EPSS 39.7% | 27 February 2025 |
| CVE-2025-21760 | In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. | HIGH 8.1EPSS 36.8% | 27 February 2025 |
| CVE-2025-21758 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. | MEDIUM 5.5EPSS 13.7% | 27 February 2025 |
| CVE-2025-1128 | The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the… | CRITICAL 9.8EPSS 28.8% | 25 February 2025 |
| CVE-2025-27364 | In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. | CRITICAL 10.0EPSS 25.9% | 24 February 2025 |
| CVE-2025-25279 | Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a… | HIGH 7.5EPSS 24.2% | 24 February 2025 |
| CVE-2025-1610 | A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. | MEDIUM 5.3EPSS 12.9% | 24 February 2025 |
| CVE-2019-8900 | A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. | MEDIUM 6.8EPSS 68.8% | 21 February 2025 |
| CVE-2025-26794 | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. | CRITICAL 9.8EPSS 77.2% | 21 February 2025 |
| CVE-2025-24893 | XWiki Platform Eval Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 20 February 2025 |
| CVE-2025-0868 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. | CRITICAL 9.3EPSS 17.1% | 20 February 2025 |
| CVE-2025-27218 | Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization. | MEDIUM 5.3EPSS 65.0% | 20 February 2025 |
| CVE-2024-12284 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | HIGH 8.8EPSS 13.3% | 20 February 2025 |
| CVE-2024-57045 | A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. | CRITICAL 9.8EPSS 32.2% | 18 February 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.