Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 25 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-7855 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. | HIGH 8.8EPSS 17.7% | 2 October 2024 |
| CVE-2024-47525 | A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. | MEDIUM 5.4EPSS 29.6% | 1 October 2024 |
| CVE-2024-8353 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and… | CRITICAL 9.8EPSS 28.7% | 28 September 2024 |
| CVE-2024-6931 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. | MEDIUM 6.1EPSS 16.7% | 27 September 2024 |
| CVE-2024-47176 | CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it… | MEDIUM 5.3EPSS 50.6% | 26 September 2024 |
| CVE-2024-47175 | When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. | CRITICAL 9.8EPSS 63.6% | 26 September 2024 |
| CVE-2024-47076 | When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system. | HIGH 8.6EPSS 77.6% | 26 September 2024 |
| CVE-2024-46628 | Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. | CRITICAL 9.8EPSS 11.7% | 26 September 2024 |
| CVE-2024-0132 | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. | HIGH 8.3EPSS 40.8% | 26 September 2024 |
| CVE-2024-8275 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack… | CRITICAL 9.8EPSS 49.9% | 25 September 2024 |
| CVE-2024-8877 | Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. | MEDIUM 6.9EPSS 77.3% | 25 September 2024 |
| CVE-2024-47066 | Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a… | HIGH 8.8EPSS 11.8% | 23 September 2024 |
| CVE-2024-43989 | Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a through <= 4.6.1. | HIGH 7.5EPSS 12.4% | 23 September 2024 |
| CVE-2024-9076 | A vulnerability was found in DedeCMS up to 5.7.115. | MEDIUM 5.1EPSS 20.8% | 22 September 2024 |
| CVE-2023-27584 | However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. | CRITICAL 9.8EPSS 33.6% | 19 September 2024 |
| CVE-2024-9004 | A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. | MEDIUM 5.3EPSS 16.6% | 19 September 2024 |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | KEVCRITICAL 9.1EPSS 98.6% | 19 September 2024 |
| CVE-2024-46987 | A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions). | HIGH 7.7EPSS 14.6% | 18 September 2024 |
| CVE-2024-46986 | An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the… | CRITICAL 9.9EPSS 41.0% | 18 September 2024 |
| CVE-2024-46982 | This vulnerability was resolved in Next.js v13.5.7, v14.2.10, and later. | HIGH 7.5EPSS 59.2% | 17 September 2024 |
| CVE-2024-8957 | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 81.0% | 17 September 2024 |
| CVE-2024-8956 | PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability | KEVCRITICAL 9.1EPSS 61.3% | 17 September 2024 |
| CVE-2024-8945 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. | MEDIUM 5.3EPSS 16.0% | 17 September 2024 |
| CVE-2024-38813 | VMware vCenter Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 17.4% | 17 September 2024 |
| CVE-2024-38812 | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 54.6% | 17 September 2024 |
| CVE-2024-8752 | The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system. | CRITICAL 9.3EPSS 11.8% | 16 September 2024 |
| CVE-2024-46938 | An unauthenticated attacker can read arbitrary files. | HIGH 7.5EPSS 46.8% | 15 September 2024 |
| CVE-2024-8669 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on… | HIGH 7.2EPSS 16.6% | 14 September 2024 |
| CVE-2024-39924 | A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. | HIGH 8.8EPSS 13.3% | 13 September 2024 |
| CVE-2024-6587 | A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. | HIGH 7.5EPSS 35.3% | 13 September 2024 |
| CVE-2024-46048 | Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i | CRITICAL 9.8EPSS 10.5% | 13 September 2024 |
| CVE-2024-41874 | ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 30.3% | 13 September 2024 |
| CVE-2024-38816 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. | HIGH 7.5EPSS 14.7% | 13 September 2024 |
| CVE-2024-45607 | This vulnerability is fixed in 4.0.3. | MEDIUM 5.3EPSS 14.5% | 12 September 2024 |
| CVE-2024-8124 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request. | HIGH 7.5EPSS 40.0% | 12 September 2024 |
| CVE-2024-45826 | CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. | HIGH 8.5EPSS 12.3% | 12 September 2024 |
| CVE-2024-8529 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient… | HIGH 7.5EPSS 11.8% | 12 September 2024 |
| CVE-2024-8522 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping… | HIGH 7.5EPSS 62.9% | 12 September 2024 |
| CVE-2024-37397 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets. | HIGH 8.2EPSS 59.3% | 12 September 2024 |
| CVE-2024-34785 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 25.4% | 12 September 2024 |
| CVE-2024-34783 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 43.4% | 12 September 2024 |
| CVE-2024-34779 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 24.0% | 12 September 2024 |
| CVE-2024-32848 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 43.4% | 12 September 2024 |
| CVE-2024-32845 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 24.0% | 12 September 2024 |
| CVE-2024-32840 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 25.4% | 12 September 2024 |
| CVE-2024-29847 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | CRITICAL 9.8EPSS 52.9% | 12 September 2024 |
| CVE-2024-44466 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. | CRITICAL 9.8EPSS 10.7% | 11 September 2024 |
| CVE-2024-8191 | SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution. | CRITICAL 9.8EPSS 20.3% | 10 September 2024 |
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 88.5% | 10 September 2024 |
| CVE-2024-8504 | An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. | HIGH 8.8EPSS 76.2% | 10 September 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.