SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 23 of 348

CVESummaryPriorityPublished
CVE-2024-43642Windows SMB Denial of Service VulnerabilityHIGH 7.5EPSS 62.7%12 November 2024
CVE-2024-43452Windows Registry Elevation of Privilege VulnerabilityHIGH 7.5EPSS 28.1%12 November 2024
CVE-2024-43451Microsoft Windows NTLMv2 Hash Disclosure Spoofing VulnerabilityKEVMEDIUM 6.5EPSS 84.1%12 November 2024
CVE-2024-50330SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.CRITICAL 9.8EPSS 40.3%12 November 2024
CVE-2024-50326SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 26.5%12 November 2024
CVE-2024-50324Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 18.7%12 November 2024
CVE-2024-50320An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.HIGH 7.5EPSS 39.7%12 November 2024
CVE-2024-10470The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions…CRITICAL 9.8EPSS 34.4%9 November 2024
CVE-2024-50599A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints.MEDIUM 6.1EPSS 60.7%7 November 2024
CVE-2024-43425Additional restrictions are required to avoid a remote code execution risk in calculated question types.HIGH 8.1EPSS 87.4%7 November 2024
CVE-2024-50340There are no known workarounds for this vulnerability.HIGH 7.3EPSS 64.4%6 November 2024
CVE-2024-10081Authentication bypass occurs when the API URL ends with Authentication.CRITICAL 10.0EPSS 39.1%6 November 2024
CVE-2024-10915A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.CRITICAL 9.2EPSS 79.4%6 November 2024
CVE-2024-10914A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.CRITICAL 9.2EPSS 96.2%6 November 2024
CVE-2024-10697A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical.MEDIUM 5.3EPSS 26.2%2 November 2024
CVE-2024-43919Access Control vulnerability in YARPP YARPP allows .CRITICAL 9.8EPSS 44.9%1 November 2024
CVE-2024-51482ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php.CRITICAL 9.9EPSS 36.6%31 October 2024
CVE-2024-10392The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89.CRITICAL 9.8EPSS 15.0%31 October 2024
CVE-2024-48307JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.CRITICAL 9.8EPSS 44.3%31 October 2024
CVE-2024-10456Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.CRITICAL 9.3EPSS 17.6%30 October 2024
CVE-2024-33699The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.HIGH 8.8EPSS 11.2%30 October 2024
CVE-2024-33623A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6.HIGH 7.5EPSS 11.9%30 October 2024
CVE-2024-31152The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot.HIGH 7.5EPSS 17.8%30 October 2024
CVE-2024-10525In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback.HIGH 7.2EPSS 59.5%30 October 2024
CVE-2024-51568CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink.CRITICAL 9.8EPSS 45.7%29 October 2024
CVE-2024-51567CyberPanel Incorrect Default Permissions VulnerabilityKEVCRITICAL 9.8EPSS 86.6%29 October 2024
CVE-2024-51378CyberPanel Incorrect Default Permissions VulnerabilityKEVCRITICAL 9.8EPSS 94.7%29 October 2024
CVE-2024-8309A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection.CRITICAL 9.8EPSS 13.7%29 October 2024
CVE-2024-5982A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt.CRITICAL 9.8EPSS 31.3%29 October 2024
CVE-2024-44236An out-of-bounds access issue was addressed with improved bounds checking.MEDIUM 5.5EPSS 11.0%28 October 2024
CVE-2024-39205An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.CRITICAL 9.8EPSS 16.5%28 October 2024
CVE-2024-45802Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy.HIGH 7.5EPSS 47.9%28 October 2024
CVE-2024-50498Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.CRITICAL 9.8EPSS 52.9%28 October 2024
CVE-2024-50623Cleo Multiple Products Unrestricted File Upload VulnerabilityKEVCRITICAL 9.8EPSS 98.6%28 October 2024
CVE-2024-10429A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028.HIGH 8.6EPSS 18.2%27 October 2024
CVE-2024-10428A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028.HIGH 8.6EPSS 14.8%27 October 2024
CVE-2024-9932The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0.CRITICAL 9.8EPSS 36.4%26 October 2024
CVE-2024-10386CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product.CRITICAL 9.3EPSS 19.3%25 October 2024
CVE-2024-49357In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data…HIGH 7.5EPSS 23.7%24 October 2024
CVE-2024-45242EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility.HIGH 7.8EPSS 35.4%24 October 2024
CVE-2024-20481Cisco ASA and FTD Denial-of-Service VulnerabilityKEVMEDIUM 5.8EPSS 15.8%23 October 2024
CVE-2024-47575Fortinet FortiManager Missing Authentication VulnerabilityKEVCRITICAL 9.8EPSS 95.1%23 October 2024
CVE-2024-46538A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.MEDIUM 4.8EPSS 81.6%22 October 2024
CVE-2024-45518It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting.HIGH 8.8EPSS 20.7%22 October 2024
CVE-2024-41713Mitel MiCollab Path Traversal VulnerabilityKEVCRITICAL 9.1EPSS 98.1%21 October 2024
CVE-2024-35286A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input.CRITICAL 9.8EPSS 65.7%21 October 2024
CVE-2024-49368Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution.HIGH 8.9EPSS 27.7%21 October 2024
CVE-2024-45309A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process.HIGH 8.7EPSS 24.5%21 October 2024
CVE-2024-44000Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.CRITICAL 9.8EPSS 82.3%20 October 2024
CVE-2024-10193A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical.MEDIUM 5.1EPSS 15.5%20 October 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.