Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 21 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-11972 | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo,… | CRITICAL 9.8EPSS 54.5% | 31 December 2024 |
| CVE-2024-12828 | Webmin CGI Command Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 33.5% | 30 December 2024 |
| CVE-2024-12987 | DrayTek Vigor Routers OS Command Injection Vulnerability | KEVMEDIUM 6.9EPSS 98.1% | 27 December 2024 |
| CVE-2024-12986 | A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. | MEDIUM 6.9EPSS 32.8% | 27 December 2024 |
| CVE-2024-12856 | The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. | HIGH 7.2EPSS 84.2% | 27 December 2024 |
| CVE-2024-3393 | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | KEVHIGH 8.7EPSS 28.4% | 27 December 2024 |
| CVE-2024-52046 | The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. | CRITICAL 10.0EPSS 23.9% | 25 December 2024 |
| CVE-2024-43441 | Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. | CRITICAL 9.8EPSS 69.4% | 24 December 2024 |
| CVE-2024-53961 | ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. | HIGH 8.1EPSS 14.2% | 23 December 2024 |
| CVE-2024-55947 | A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. | HIGH 8.7EPSS 75.2% | 23 December 2024 |
| CVE-2024-45387 | An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a… | HIGH 8.8EPSS 41.5% | 23 December 2024 |
| CVE-2024-53991 | This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. | MEDIUM 5.9EPSS 26.8% | 19 December 2024 |
| CVE-2024-38819 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. | HIGH 7.5EPSS 54.9% | 19 December 2024 |
| CVE-2021-26102 | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. | CRITICAL 9.1EPSS 16.8% | 19 December 2024 |
| CVE-2024-56145 | Craft CMS Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 97.4% | 18 December 2024 |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 13.8% | 18 December 2024 |
| CVE-2023-34990 | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests. | CRITICAL 9.8EPSS 24.9% | 18 December 2024 |
| CVE-2024-50379 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). | CRITICAL 9.8EPSS 44.3% | 17 December 2024 |
| CVE-2024-12356 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 88.0% | 17 December 2024 |
| CVE-2024-29671 | Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component. | CRITICAL 9.8EPSS 20.9% | 16 December 2024 |
| CVE-2024-53376 | CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI. | HIGH 8.8EPSS 11.0% | 16 December 2024 |
| CVE-2024-55956 | Cleo Multiple Products Unauthenticated File Upload Vulnerability | KEVCRITICAL 9.8EPSS 94.0% | 13 December 2024 |
| CVE-2024-55661 | A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Concerns\RemembersQueries` trait. | HIGH 8.7EPSS 29.7% | 13 December 2024 |
| CVE-2024-10124 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and… | CRITICAL 9.8EPSS 31.2% | 12 December 2024 |
| CVE-2024-54502 | Processing maliciously crafted web content may lead to an unexpected process crash. | MEDIUM 6.5EPSS 15.0% | 12 December 2024 |
| CVE-2024-50339 | GLPI is a free asset and IT management software package. | CRITICAL 9.3EPSS 19.6% | 12 December 2024 |
| CVE-2024-49138 | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 25.4% | 12 December 2024 |
| CVE-2024-49122 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | HIGH 8.1EPSS 20.4% | 12 December 2024 |
| CVE-2024-49116 | Windows Remote Desktop Services Remote Code Execution Vulnerability | HIGH 8.1EPSS 10.0% | 12 December 2024 |
| CVE-2024-49113 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | HIGH 7.5EPSS 83.0% | 12 December 2024 |
| CVE-2024-49112 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 70.9% | 12 December 2024 |
| CVE-2024-42448 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. | CRITICAL 9.9EPSS 20.1% | 12 December 2024 |
| CVE-2024-53677 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. | CRITICAL 9.5EPSS 78.2% | 11 December 2024 |
| CVE-2024-55550 | Mitel MiCollab Path Traversal Vulnerability | KEVLOW 2.7EPSS 37.8% | 10 December 2024 |
| CVE-2024-11773 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | HIGH 7.2EPSS 23.6% | 10 December 2024 |
| CVE-2024-55547 | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. | CRITICAL 9.3EPSS 16.9% | 10 December 2024 |
| CVE-2024-55544 | Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below. | HIGH 8.7EPSS 11.7% | 10 December 2024 |
| CVE-2024-12209 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. | CRITICAL 9.8EPSS 23.2% | 8 December 2024 |
| CVE-2024-53691 | A link following vulnerability has been reported to affect several QNAP operating system versions. | HIGH 8.7EPSS 22.9% | 6 December 2024 |
| CVE-2024-11728 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient… | HIGH 7.5EPSS 13.6% | 6 December 2024 |
| CVE-2024-53457 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter. | MEDIUM 5.4EPSS 44.6% | 5 December 2024 |
| CVE-2024-53703 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution. | HIGH 8.1EPSS 12.6% | 5 December 2024 |
| CVE-2024-51544 | Service Control vulnerabilities allow access to service restart requests and vm configuration settings. | HIGH 8.8EPSS 13.2% | 5 December 2024 |
| CVE-2024-42455 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. | HIGH 8.1EPSS 15.2% | 4 December 2024 |
| CVE-2024-53375 | An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. | HIGH 8.0EPSS 40.5% | 2 December 2024 |
| CVE-2024-46909 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account. | CRITICAL 9.8EPSS 48.9% | 2 December 2024 |
| CVE-2024-46906 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | HIGH 8.8EPSS 40.4% | 2 December 2024 |
| CVE-2024-8672 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. | CRITICAL 9.9EPSS 43.6% | 28 November 2024 |
| CVE-2024-54003 | Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission. | HIGH 8.0EPSS 79.6% | 27 November 2024 |
| CVE-2024-42327 | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. | CRITICAL 9.9EPSS 78.7% | 27 November 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.