SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 20 of 348

CVESummaryPriorityPublished
CVE-2024-12084A heap-based buffer overflow flaw was found in the rsync daemon.CRITICAL 9.8EPSS 72.1%15 January 2025
CVE-2024-48760An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function.CRITICAL 9.8EPSS 45.1%14 January 2025
CVE-2025-21309Windows Remote Desktop Services Remote Code Execution VulnerabilityHIGH 8.1EPSS 14.9%14 January 2025
CVE-2025-21298Windows OLE Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 80.9%14 January 2025
CVE-2025-21293Active Directory Domain Services Elevation of Privilege VulnerabilityHIGH 8.8EPSS 19.0%14 January 2025
CVE-2025-21285Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityHIGH 7.5EPSS 55.7%14 January 2025
CVE-2025-21277Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityHIGH 7.5EPSS 38.6%14 January 2025
CVE-2024-13171Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution.HIGH 7.8EPSS 17.6%14 January 2025
CVE-2024-13162SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 64.2%14 January 2025
CVE-2024-13161Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityKEVHIGH 7.5EPSS 90.1%14 January 2025
CVE-2024-13160Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityKEVHIGH 7.5EPSS 91.2%14 January 2025
CVE-2024-13159Ivanti Endpoint Manager (EPM) Absolute Path Traversal VulnerabilityKEVHIGH 7.5EPSS 100.0%14 January 2025
CVE-2024-13181Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.CRITICAL 9.8EPSS 32.4%14 January 2025
CVE-2024-13180Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information.HIGH 7.5EPSS 27.8%14 January 2025
CVE-2024-13179Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.CRITICAL 9.8EPSS 63.0%14 January 2025
CVE-2024-39760Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505.CRITICAL 9.8EPSS 17.4%14 January 2025
CVE-2024-39363A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505.MEDIUM 6.1EPSS 48.1%14 January 2025
CVE-2024-39360An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505.HIGH 7.2EPSS 11.7%14 January 2025
CVE-2024-39288A buffer overflow vulnerability exists in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505.HIGH 7.2EPSS 13.5%14 January 2025
CVE-2024-39280An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505.CRITICAL 9.1EPSS 34.2%14 January 2025
CVE-2024-38666An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505.CRITICAL 9.1EPSS 18.9%14 January 2025
CVE-2024-37186An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505.HIGH 7.2EPSS 22.8%14 January 2025
CVE-2024-36295A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505.HIGH 7.2EPSS 20.8%14 January 2025
CVE-2024-36258A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505.CRITICAL 9.8EPSS 12.4%14 January 2025
CVE-2024-34166An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505.CRITICAL 9.8EPSS 15.8%14 January 2025
CVE-2024-21797A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505.HIGH 7.2EPSS 20.8%14 January 2025
CVE-2024-55591Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 98.3%14 January 2025
CVE-2024-48884A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through…CRITICAL 9.1EPSS 15.3%14 January 2025
CVE-2025-0107An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device…HIGH 7.7EPSS 78.5%11 January 2025
CVE-2025-0105An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.MEDIUM 6.9EPSS 13.3%11 January 2025
CVE-2024-12847NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability.CRITICAL 9.8EPSS 29.9%10 January 2025
CVE-2024-56511Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access.CRITICAL 9.3EPSS 44.5%10 January 2025
CVE-2025-21385A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.MEDIUM 6.5EPSS 24.4%9 January 2025
CVE-2024-53704SonicWall SonicOS SSLVPN Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 95.1%9 January 2025
CVE-2025-0283A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.HIGH 7.0EPSS 17.4%8 January 2025
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.0EPSS 100.0%8 January 2025
CVE-2024-55656There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis.HIGH 8.8EPSS 15.0%8 January 2025
CVE-2024-54676Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this…CRITICAL 9.8EPSS 65.2%8 January 2025
CVE-2024-50603Aviatrix Controllers OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.5%8 January 2025
CVE-2024-54819I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.phpCRITICAL 9.1EPSS 18.0%7 January 2025
CVE-2025-0242Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.MEDIUM 6.5EPSS 13.1%7 January 2025
CVE-2024-55556A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted…CRITICAL 9.8EPSS 44.1%7 January 2025
CVE-2024-12849The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action.HIGH 7.5EPSS 46.9%7 January 2025
CVE-2024-48456An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi…HIGH 7.5EPSS 17.3%6 January 2025
CVE-2024-13129A vulnerability was found in Roxy-WI up to 8.1.3.HIGH 8.7EPSS 17.8%3 January 2025
CVE-2024-11716While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition…MEDIUM 5.3EPSS 11.7%2 January 2025
CVE-2024-13106A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical.MEDIUM 6.9EPSS 27.2%2 January 2025
CVE-2024-56067Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.HIGH 7.5EPSS 10.0%31 December 2024
CVE-2024-56064Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.CRITICAL 10.0EPSS 30.8%31 December 2024
CVE-2024-12105In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.MEDIUM 6.5EPSS 42.4%31 December 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.