Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 22 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-53676 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | CRITICAL 9.8EPSS 56.3% | 27 November 2024 |
| CVE-2024-53675 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | HIGH 7.5EPSS 83.6% | 26 November 2024 |
| CVE-2024-53674 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | HIGH 7.5EPSS 46.7% | 26 November 2024 |
| CVE-2024-32965 | Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. | HIGH 8.6EPSS 27.9% | 26 November 2024 |
| CVE-2024-11680 | ProjectSend Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 91.7% | 26 November 2024 |
| CVE-2024-33610 | "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. | CRITICAL 9.1EPSS 50.0% | 26 November 2024 |
| CVE-2024-10542 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and… | HIGH 7.5EPSS 15.4% | 26 November 2024 |
| CVE-2024-11659 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. | MEDIUM 5.1EPSS 29.1% | 25 November 2024 |
| CVE-2024-11658 | A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. | MEDIUM 5.1EPSS 29.1% | 25 November 2024 |
| CVE-2024-11657 | A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 29.1% | 25 November 2024 |
| CVE-2024-11656 | A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 28.8% | 25 November 2024 |
| CVE-2024-11655 | A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 28.8% | 25 November 2024 |
| CVE-2024-11654 | A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 29.1% | 25 November 2024 |
| CVE-2024-11653 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 29.1% | 25 November 2024 |
| CVE-2024-11652 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 30.2% | 25 November 2024 |
| CVE-2024-11651 | A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. | MEDIUM 5.1EPSS 27.4% | 25 November 2024 |
| CVE-2024-47407 | A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands. | CRITICAL 10.0EPSS 64.0% | 22 November 2024 |
| CVE-2024-11477 | 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. | HIGH 7.8EPSS 22.6% | 22 November 2024 |
| CVE-2024-53333 | TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. | MEDIUM 6.3EPSS 19.4% | 21 November 2024 |
| CVE-2024-48288 | TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend. | HIGH 8.0EPSS 10.6% | 21 November 2024 |
| CVE-2024-48286 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. | HIGH 8.0EPSS 12.8% | 21 November 2024 |
| CVE-2024-21786 | An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. | HIGH 7.2EPSS 10.4% | 21 November 2024 |
| CVE-2024-11320 | Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. | MEDIUM 6.9EPSS 91.0% | 21 November 2024 |
| CVE-2024-10400 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | HIGH 7.5EPSS 83.1% | 21 November 2024 |
| CVE-2024-51151 | D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter. | CRITICAL 9.8EPSS 30.4% | 21 November 2024 |
| CVE-2024-52765 | H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. | CRITICAL 9.8EPSS 11.6% | 20 November 2024 |
| CVE-2024-44309 | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.3EPSS 22.6% | 20 November 2024 |
| CVE-2024-44308 | Apple Multiple Products Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.2% | 20 November 2024 |
| CVE-2024-48990 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable. | HIGH 7.8EPSS 20.5% | 19 November 2024 |
| CVE-2024-11003 | This could allow a local attacker to execute arbitrary shell commands. | HIGH 7.8EPSS 11.5% | 19 November 2024 |
| CVE-2024-9474 | Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | KEVMEDIUM 6.9EPSS 94.7% | 18 November 2024 |
| CVE-2024-0012 | Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | KEVCRITICAL 9.3EPSS 99.7% | 18 November 2024 |
| CVE-2020-26073 | A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. | HIGH 7.5EPSS 12.6% | 18 November 2024 |
| CVE-2024-8856 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including,… | CRITICAL 9.8EPSS 94.0% | 16 November 2024 |
| CVE-2024-10728 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up… | HIGH 8.8EPSS 38.2% | 16 November 2024 |
| CVE-2024-40638 | An authenticated user can exploit multiple SQL injection vulnerabilities. | HIGH 8.8EPSS 37.2% | 15 November 2024 |
| CVE-2024-44625 | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. | HIGH 8.8EPSS 15.9% | 15 November 2024 |
| CVE-2024-50352 | A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding a service to a device. | MEDIUM 5.4EPSS 37.6% | 15 November 2024 |
| CVE-2024-49754 | A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a new API token. | MEDIUM 5.4EPSS 71.1% | 15 November 2024 |
| CVE-2023-20036 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. | CRITICAL 9.9EPSS 13.1% | 15 November 2024 |
| CVE-2022-20649 | A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container. | HIGH 8.1EPSS 12.0% | 15 November 2024 |
| CVE-2024-11182 | MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 5.3EPSS 17.7% | 15 November 2024 |
| CVE-2024-10443 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows… | CRITICAL 9.8EPSS 28.0% | 15 November 2024 |
| CVE-2024-10924 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. | CRITICAL 9.8EPSS 82.0% | 15 November 2024 |
| CVE-2024-11120 | GeoVision Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 28.4% | 15 November 2024 |
| CVE-2024-34787 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. | HIGH 7.8EPSS 17.8% | 13 November 2024 |
| CVE-2024-34781 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 68.5% | 13 November 2024 |
| CVE-2024-52301 | The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. | HIGH 8.7EPSS 44.8% | 12 November 2024 |
| CVE-2024-8069 | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | KEVMEDIUM 5.1EPSS 14.6% | 12 November 2024 |
| CVE-2024-49039 | Microsoft Windows Task Scheduler Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 14.2% | 12 November 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.