SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 22 of 348

CVESummaryPriorityPublished
CVE-2024-53676A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.CRITICAL 9.8EPSS 56.3%27 November 2024
CVE-2024-53675An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.HIGH 7.5EPSS 83.6%26 November 2024
CVE-2024-53674An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.HIGH 7.5EPSS 46.7%26 November 2024
CVE-2024-32965Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability.HIGH 8.6EPSS 27.9%26 November 2024
CVE-2024-11680ProjectSend Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 91.7%26 November 2024
CVE-2024-33610"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device.CRITICAL 9.1EPSS 50.0%26 November 2024
CVE-2024-10542The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and…HIGH 7.5EPSS 15.4%26 November 2024
CVE-2024-11659A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical.MEDIUM 5.1EPSS 29.1%25 November 2024
CVE-2024-11658A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical.MEDIUM 5.1EPSS 29.1%25 November 2024
CVE-2024-11657A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 29.1%25 November 2024
CVE-2024-11656A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 28.8%25 November 2024
CVE-2024-11655A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 28.8%25 November 2024
CVE-2024-11654A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 29.1%25 November 2024
CVE-2024-11653A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 29.1%25 November 2024
CVE-2024-11652A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 30.2%25 November 2024
CVE-2024-11651A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118.MEDIUM 5.1EPSS 27.4%25 November 2024
CVE-2024-47407A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.CRITICAL 10.0EPSS 64.0%22 November 2024
CVE-2024-114777-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability.HIGH 7.8EPSS 22.6%22 November 2024
CVE-2024-53333TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function.MEDIUM 6.3EPSS 19.4%21 November 2024
CVE-2024-48288TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.HIGH 8.0EPSS 10.6%21 November 2024
CVE-2024-48286Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.HIGH 8.0EPSS 12.8%21 November 2024
CVE-2024-21786An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5.HIGH 7.2EPSS 10.4%21 November 2024
CVE-2024-11320Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism.MEDIUM 6.9EPSS 91.0%21 November 2024
CVE-2024-10400The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…HIGH 7.5EPSS 83.1%21 November 2024
CVE-2024-51151D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.CRITICAL 9.8EPSS 30.4%21 November 2024
CVE-2024-52765H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.CRITICAL 9.8EPSS 11.6%20 November 2024
CVE-2024-44309Apple Multiple Products Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.3EPSS 22.6%20 November 2024
CVE-2024-44308Apple Multiple Products Code Execution VulnerabilityKEVHIGH 8.8EPSS 10.2%20 November 2024
CVE-2024-48990Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.HIGH 7.8EPSS 20.5%19 November 2024
CVE-2024-11003This could allow a local attacker to execute arbitrary shell commands.HIGH 7.8EPSS 11.5%19 November 2024
CVE-2024-9474Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityKEVMEDIUM 6.9EPSS 94.7%18 November 2024
CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass VulnerabilityKEVCRITICAL 9.3EPSS 99.7%18 November 2024
CVE-2020-26073A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information.HIGH 7.5EPSS 12.6%18 November 2024
CVE-2024-8856The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including,…CRITICAL 9.8EPSS 94.0%16 November 2024
CVE-2024-10728The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up…HIGH 8.8EPSS 38.2%16 November 2024
CVE-2024-40638An authenticated user can exploit multiple SQL injection vulnerabilities.HIGH 8.8EPSS 37.2%15 November 2024
CVE-2024-44625Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.HIGH 8.8EPSS 15.9%15 November 2024
CVE-2024-50352A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding a service to a device.MEDIUM 5.4EPSS 37.6%15 November 2024
CVE-2024-49754A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a new API token.MEDIUM 5.4EPSS 71.1%15 November 2024
CVE-2023-20036A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device.CRITICAL 9.9EPSS 13.1%15 November 2024
CVE-2022-20649A vulnerability in Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges&nbsp;in the context of the configured container.HIGH 8.1EPSS 12.0%15 November 2024
CVE-2024-11182MDaemon Email Server Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 5.3EPSS 17.7%15 November 2024
CVE-2024-10443Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows…CRITICAL 9.8EPSS 28.0%15 November 2024
CVE-2024-10924The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1.CRITICAL 9.8EPSS 82.0%15 November 2024
CVE-2024-11120GeoVision Devices OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 28.4%15 November 2024
CVE-2024-34787Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution.HIGH 7.8EPSS 17.8%13 November 2024
CVE-2024-34781SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 68.5%13 November 2024
CVE-2024-52301The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0.HIGH 8.7EPSS 44.8%12 November 2024
CVE-2024-8069Citrix Session Recording Deserialization of Untrusted Data VulnerabilityKEVMEDIUM 5.1EPSS 14.6%12 November 2024
CVE-2024-49039Microsoft Windows Task Scheduler Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 14.2%12 November 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.