SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 24 of 348

CVESummaryPriorityPublished
CVE-2024-37404Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.HIGH 8.8EPSS 71.0%18 October 2024
CVE-2024-9593The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function.HIGH 8.3EPSS 12.4%18 October 2024
CVE-2024-9264The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input.CRITICAL 9.4EPSS 94.9%18 October 2024
CVE-2024-48634D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function.HIGH 8.0EPSS 17.6%17 October 2024
CVE-2024-38814An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware.HIGH 8.8EPSS 15.4%16 October 2024
CVE-2024-45844BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.HIGH 8.6EPSS 10.6%16 October 2024
CVE-2024-9061The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5.CRITICAL 9.8EPSS 52.3%16 October 2024
CVE-2024-45216Improper Authentication vulnerability in Apache Solr.CRITICAL 9.8EPSS 91.7%16 October 2024
CVE-2022-4971The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization…MEDIUM 6.1EPSS 16.2%16 October 2024
CVE-2024-48914Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as…CRITICAL 9.1EPSS 60.4%15 October 2024
CVE-2024-9977A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26.MEDIUM 5.1EPSS 22.9%15 October 2024
CVE-2024-45741In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom…MEDIUM 5.4EPSS 13.9%14 October 2024
CVE-2023-50780Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint.HIGH 8.8EPSS 17.5%14 October 2024
CVE-2024-9916A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9.MEDIUM 6.9EPSS 73.6%13 October 2024
CVE-2024-9047The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php.CRITICAL 9.8EPSS 93.3%12 October 2024
CVE-2024-35517Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.HIGH 7.2EPSS 15.0%11 October 2024
CVE-2024-42640angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php.CRITICAL 9.8EPSS 45.1%11 October 2024
CVE-2024-9234The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function…CRITICAL 9.8EPSS 10.4%11 October 2024
CVE-2024-9487An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance.CRITICAL 9.5EPSS 25.6%10 October 2024
CVE-2024-9793A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23.MEDIUM 5.3EPSS 23.1%10 October 2024
CVE-2024-9466A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.HIGH 8.2EPSS 13.6%9 October 2024
CVE-2024-9465Palo Alto Networks Expedition SQL Injection VulnerabilityKEVCRITICAL 9.2EPSS 99.6%9 October 2024
CVE-2024-9464An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API…CRITICAL 9.3EPSS 82.6%9 October 2024
CVE-2024-9463Palo Alto Networks Expedition OS Command Injection VulnerabilityKEVCRITICAL 9.9EPSS 98.5%9 October 2024
CVE-2024-9680Mozilla Firefox Use-After-Free VulnerabilityKEVCRITICAL 9.8EPSS 23.2%9 October 2024
CVE-2024-43573Microsoft Windows MSHTML Platform Spoofing VulnerabilityKEVHIGH 8.1EPSS 43.8%8 October 2024
CVE-2024-43572Microsoft Windows Management Console Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 66.7%8 October 2024
CVE-2024-43532Remote Registry Service Elevation of Privilege VulnerabilityHIGH 8.8EPSS 12.0%8 October 2024
CVE-2024-43468Microsoft Configuration Manager SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 82.0%8 October 2024
CVE-2024-9381Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.HIGH 7.2EPSS 15.6%8 October 2024
CVE-2024-9380Ivanti Cloud Services Appliance (CSA) OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 63.2%8 October 2024
CVE-2024-9379Ivanti Cloud Services Appliance (CSA) SQL Injection VulnerabilityKEVHIGH 7.2EPSS 43.8%8 October 2024
CVE-2024-47011Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive informationHIGH 7.5EPSS 56.3%8 October 2024
CVE-2024-47010Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.CRITICAL 9.8EPSS 37.8%8 October 2024
CVE-2024-47008Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.HIGH 7.5EPSS 47.1%8 October 2024
CVE-2024-47949In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary locationHIGH 7.5EPSS 23.5%8 October 2024
CVE-2024-45230The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.HIGH 7.5EPSS 25.8%8 October 2024
CVE-2024-43365Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS.HIGH 8.2EPSS 25.1%7 October 2024
CVE-2024-43364Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to stored XSS.HIGH 8.2EPSS 37.9%7 October 2024
CVE-2024-43363An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the…HIGH 7.2EPSS 35.6%7 October 2024
CVE-2024-43362Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS.MEDIUM 5.4EPSS 38.6%7 October 2024
CVE-2024-47841Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X…MEDIUM 6.9EPSS 34.6%5 October 2024
CVE-2024-9054Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This…HIGH 8.5EPSS 15.6%4 October 2024
CVE-2024-43686Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.MEDIUM 5.4EPSS 13.0%4 October 2024
CVE-2024-47855util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.MEDIUM 5.3EPSS 17.6%4 October 2024
CVE-2024-46658Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.HIGH 8.0EPSS 24.4%3 October 2024
CVE-2024-41163A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0.HIGH 7.5EPSS 52.5%3 October 2024
CVE-2024-45519Synacor Zimbra Collaboration Suite (ZCS) Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%2 October 2024
CVE-2024-9441The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability.CRITICAL 9.8EPSS 53.5%2 October 2024
CVE-2024-24116An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.CRITICAL 9.8EPSS 28.4%2 October 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.