Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 24 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-37404 | Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. | HIGH 8.8EPSS 71.0% | 18 October 2024 |
| CVE-2024-9593 | The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. | HIGH 8.3EPSS 12.4% | 18 October 2024 |
| CVE-2024-9264 | The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. | CRITICAL 9.4EPSS 94.9% | 18 October 2024 |
| CVE-2024-48634 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. | HIGH 8.0EPSS 17.6% | 17 October 2024 |
| CVE-2024-38814 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. | HIGH 8.8EPSS 15.4% | 16 October 2024 |
| CVE-2024-45844 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. | HIGH 8.6EPSS 10.6% | 16 October 2024 |
| CVE-2024-9061 | The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. | CRITICAL 9.8EPSS 52.3% | 16 October 2024 |
| CVE-2024-45216 | Improper Authentication vulnerability in Apache Solr. | CRITICAL 9.8EPSS 91.7% | 16 October 2024 |
| CVE-2022-4971 | The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization… | MEDIUM 6.1EPSS 16.2% | 16 October 2024 |
| CVE-2024-48914 | Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as… | CRITICAL 9.1EPSS 60.4% | 15 October 2024 |
| CVE-2024-9977 | A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. | MEDIUM 5.1EPSS 22.9% | 15 October 2024 |
| CVE-2024-45741 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom… | MEDIUM 5.4EPSS 13.9% | 14 October 2024 |
| CVE-2023-50780 | Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. | HIGH 8.8EPSS 17.5% | 14 October 2024 |
| CVE-2024-9916 | A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. | MEDIUM 6.9EPSS 73.6% | 13 October 2024 |
| CVE-2024-9047 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. | CRITICAL 9.8EPSS 93.3% | 12 October 2024 |
| CVE-2024-35517 | Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. | HIGH 7.2EPSS 15.0% | 11 October 2024 |
| CVE-2024-42640 | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. | CRITICAL 9.8EPSS 45.1% | 11 October 2024 |
| CVE-2024-9234 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function… | CRITICAL 9.8EPSS 10.4% | 11 October 2024 |
| CVE-2024-9487 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. | CRITICAL 9.5EPSS 25.6% | 10 October 2024 |
| CVE-2024-9793 | A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. | MEDIUM 5.3EPSS 23.1% | 10 October 2024 |
| CVE-2024-9466 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials. | HIGH 8.2EPSS 13.6% | 9 October 2024 |
| CVE-2024-9465 | Palo Alto Networks Expedition SQL Injection Vulnerability | KEVCRITICAL 9.2EPSS 99.6% | 9 October 2024 |
| CVE-2024-9464 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API… | CRITICAL 9.3EPSS 82.6% | 9 October 2024 |
| CVE-2024-9463 | Palo Alto Networks Expedition OS Command Injection Vulnerability | KEVCRITICAL 9.9EPSS 98.5% | 9 October 2024 |
| CVE-2024-9680 | Mozilla Firefox Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 23.2% | 9 October 2024 |
| CVE-2024-43573 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | KEVHIGH 8.1EPSS 43.8% | 8 October 2024 |
| CVE-2024-43572 | Microsoft Windows Management Console Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 66.7% | 8 October 2024 |
| CVE-2024-43532 | Remote Registry Service Elevation of Privilege Vulnerability | HIGH 8.8EPSS 12.0% | 8 October 2024 |
| CVE-2024-43468 | Microsoft Configuration Manager SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 82.0% | 8 October 2024 |
| CVE-2024-9381 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. | HIGH 7.2EPSS 15.6% | 8 October 2024 |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 63.2% | 8 October 2024 |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | KEVHIGH 7.2EPSS 43.8% | 8 October 2024 |
| CVE-2024-47011 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information | HIGH 7.5EPSS 56.3% | 8 October 2024 |
| CVE-2024-47010 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. | CRITICAL 9.8EPSS 37.8% | 8 October 2024 |
| CVE-2024-47008 | Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information. | HIGH 7.5EPSS 47.1% | 8 October 2024 |
| CVE-2024-47949 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | HIGH 7.5EPSS 23.5% | 8 October 2024 |
| CVE-2024-45230 | The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters. | HIGH 7.5EPSS 25.8% | 8 October 2024 |
| CVE-2024-43365 | Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS. | HIGH 8.2EPSS 25.1% | 7 October 2024 |
| CVE-2024-43364 | Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to stored XSS. | HIGH 8.2EPSS 37.9% | 7 October 2024 |
| CVE-2024-43363 | An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the… | HIGH 7.2EPSS 35.6% | 7 October 2024 |
| CVE-2024-43362 | Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. | MEDIUM 5.4EPSS 38.6% | 7 October 2024 |
| CVE-2024-47841 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X… | MEDIUM 6.9EPSS 34.6% | 5 October 2024 |
| CVE-2024-9054 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This… | HIGH 8.5EPSS 15.6% | 4 October 2024 |
| CVE-2024-43686 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | MEDIUM 5.4EPSS 13.0% | 4 October 2024 |
| CVE-2024-47855 | util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string. | MEDIUM 5.3EPSS 17.6% | 4 October 2024 |
| CVE-2024-46658 | Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability. | HIGH 8.0EPSS 24.4% | 3 October 2024 |
| CVE-2024-41163 | A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. | HIGH 7.5EPSS 52.5% | 3 October 2024 |
| CVE-2024-45519 | Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 2 October 2024 |
| CVE-2024-9441 | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. | CRITICAL 9.8EPSS 53.5% | 2 October 2024 |
| CVE-2024-24116 | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm. | CRITICAL 9.8EPSS 28.4% | 2 October 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.