SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 19 of 348

CVESummaryPriorityPublished
CVE-2025-1094Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.HIGH 8.1EPSS 90.0%13 February 2025
CVE-2025-0108Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityKEVHIGH 8.8EPSS 98.5%12 February 2025
CVE-2025-1240WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.HIGH 8.8EPSS 10.3%11 February 2025
CVE-2025-1044Logsign Unified SecOps Platform Authentication Bypass Vulnerability.CRITICAL 9.8EPSS 75.3%11 February 2025
CVE-2025-24434Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation.CRITICAL 9.1EPSS 17.2%11 February 2025
CVE-2025-21400Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.0EPSS 34.5%11 February 2025
CVE-2025-21377NTLM Hash Disclosure Spoofing VulnerabilityMEDIUM 6.5EPSS 24.5%11 February 2025
CVE-2024-27781An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions,…CRITICAL 9.0EPSS 28.2%11 February 2025
CVE-2024-47908OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 22.3%11 February 2025
CVE-2025-24016Wazuh Server Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.9EPSS 93.8%10 February 2025
CVE-2024-13059A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library.HIGH 7.2EPSS 21.3%10 February 2025
CVE-2025-1103A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802.HIGH 7.1EPSS 14.1%7 February 2025
CVE-2025-0994Trimble Cityworks Deserialization VulnerabilityKEVHIGH 8.6EPSS 31.3%6 February 2025
CVE-2025-20125A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.HIGH 7.2EPSS 16.7%5 February 2025
CVE-2025-20124A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.HIGH 7.2EPSS 18.5%5 February 2025
CVE-2024-2878It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.HIGH 7.5EPSS 19.7%5 February 2025
CVE-2025-1025Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.HIGH 7.7EPSS 18.7%5 February 2025
CVE-2025-0890**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have…CRITICAL 9.8EPSS 13.5%4 February 2025
CVE-2024-40891Zyxel DSL CPE OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 21.5%4 February 2025
CVE-2024-40890Zyxel DSL CPE OS Command Injection VulnerabilityKEVHIGH 8.8EPSS 22.3%4 February 2025
CVE-2024-56902Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.HIGH 7.5EPSS 23.4%3 February 2025
CVE-2023-52163Digiever DS-2105 Pro Missing Authorization VulnerabilityKEVHIGH 8.8EPSS 96.9%3 February 2025
CVE-2025-25181 Advantive VeraCore SQL Injection VulnerabilityKEVHIGH 7.5EPSS 57.0%3 February 2025
CVE-2025-25064SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter.HIGH 8.8EPSS 36.7%3 February 2025
CVE-2024-57968Advantive VeraCore Unrestricted File Upload VulnerabilityKEVHIGH 8.8EPSS 32.3%3 February 2025
CVE-2024-57004Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.MEDIUM 6.1EPSS 28.8%3 February 2025
CVE-2024-53942The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via crafted input.MEDIUM 4.8EPSS 15.0%3 February 2025
CVE-2024-52875This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS).HIGH 8.8EPSS 29.6%31 January 2025
CVE-2024-55417DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload.MEDIUM 4.3EPSS 14.1%30 January 2025
CVE-2024-55416DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass.LOW 3.5EPSS 20.3%30 January 2025
CVE-2024-55415DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.MEDIUM 5.7EPSS 15.5%30 January 2025
CVE-2025-0851A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.CRITICAL 9.3EPSS 23.3%29 January 2025
CVE-2024-12705Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.HIGH 7.5EPSS 18.4%29 January 2025
CVE-2024-11187An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries.HIGH 7.5EPSS 16.7%29 January 2025
CVE-2025-24085Apple Multiple Products Use-After-Free VulnerabilityKEVCRITICAL 10.0EPSS 17.6%27 January 2025
CVE-2025-24367An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server.HIGH 8.7EPSS 54.0%27 January 2025
CVE-2024-54146Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter.HIGH 8.8EPSS 41.0%27 January 2025
CVE-2024-52012Relative Path Traversal vulnerability in Apache Solr.MEDIUM 5.4EPSS 47.2%27 January 2025
CVE-2025-04117-Zip Mark of the Web Bypass VulnerabilityKEVHIGH 7.0EPSS 67.1%25 January 2025
CVE-2024-57041A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.MEDIUM 4.6EPSS 39.3%24 January 2025
CVE-2025-24587Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe allows Blind SQL Injection.This issue affects Email Subscription Popup: from n/a through <= 1.2.23.HIGH 7.6EPSS 32.2%24 January 2025
CVE-2025-23006SonicWall SMA1000 Appliances Deserialization VulnerabilityKEVCRITICAL 9.8EPSS 23.4%23 January 2025
CVE-2024-54794The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.CRITICAL 9.1EPSS 12.8%21 January 2025
CVE-2024-51818Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.CRITICAL 9.3EPSS 16.3%21 January 2025
CVE-2025-23209Craft CMS Code Injection VulnerabilityKEVHIGH 8.1EPSS 21.8%18 January 2025
CVE-2025-23200Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state.MEDIUM 5.4EPSS 30.9%16 January 2025
CVE-2024-57684An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.CRITICAL 9.8EPSS 14.4%16 January 2025
CVE-2024-57727SimpleHelp Path Traversal VulnerabilityKEVHIGH 7.5EPSS 95.2%15 January 2025
CVE-2024-57726SimpleHelp Missing Authorization VulnerabilityKEVCRITICAL 9.9EPSS 66.6%15 January 2025
CVE-2024-47002A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528.MEDIUM 5.4EPSS 15.4%15 January 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.