SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 25 of 348

CVESummaryPriorityPublished
CVE-2024-7855The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2.HIGH 8.8EPSS 17.7%2 October 2024
CVE-2024-47525A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field.MEDIUM 5.4EPSS 29.6%1 October 2024
CVE-2024-8353The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and…CRITICAL 9.8EPSS 28.7%28 September 2024
CVE-2024-6931The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping.MEDIUM 6.1EPSS 16.7%27 September 2024
CVE-2024-47176CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it…MEDIUM 5.3EPSS 50.6%26 September 2024
CVE-2024-47175When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic.CRITICAL 9.8EPSS 63.6%26 September 2024
CVE-2024-47076When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.HIGH 8.6EPSS 77.6%26 September 2024
CVE-2024-46628Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.CRITICAL 9.8EPSS 11.7%26 September 2024
CVE-2024-0132NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system.HIGH 8.3EPSS 40.8%26 September 2024
CVE-2024-8275The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack…CRITICAL 9.8EPSS 49.9%25 September 2024
CVE-2024-8877Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204.MEDIUM 6.9EPSS 77.3%25 September 2024
CVE-2024-47066Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a…HIGH 8.8EPSS 11.8%23 September 2024
CVE-2024-43989Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a through <= 4.6.1.HIGH 7.5EPSS 12.4%23 September 2024
CVE-2024-9076A vulnerability was found in DedeCMS up to 5.7.115.MEDIUM 5.1EPSS 20.8%22 September 2024
CVE-2023-27584However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass.CRITICAL 9.8EPSS 33.6%19 September 2024
CVE-2024-9004A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912.MEDIUM 5.3EPSS 16.6%19 September 2024
CVE-2024-8963Ivanti Cloud Services Appliance (CSA) Path Traversal VulnerabilityKEVCRITICAL 9.1EPSS 98.6%19 September 2024
CVE-2024-46987A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions).HIGH 7.7EPSS 14.6%18 September 2024
CVE-2024-46986An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the…CRITICAL 9.9EPSS 41.0%18 September 2024
CVE-2024-46982This vulnerability was resolved in Next.js v13.5.7, v14.2.10, and later.HIGH 7.5EPSS 59.2%17 September 2024
CVE-2024-8957PTZOptics PT30X-SDI/NDI Cameras OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 81.0%17 September 2024
CVE-2024-8956PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass VulnerabilityKEVCRITICAL 9.1EPSS 61.3%17 September 2024
CVE-2024-8945A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical.MEDIUM 5.3EPSS 16.0%17 September 2024
CVE-2024-38813VMware vCenter Server Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 17.4%17 September 2024
CVE-2024-38812VMware vCenter Server Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 54.6%17 September 2024
CVE-2024-8752The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.CRITICAL 9.3EPSS 11.8%16 September 2024
CVE-2024-46938An unauthenticated attacker can read arbitrary files.HIGH 7.5EPSS 46.8%15 September 2024
CVE-2024-8669The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on…HIGH 7.2EPSS 16.6%14 September 2024
CVE-2024-39924A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access.HIGH 8.8EPSS 13.3%13 September 2024
CVE-2024-6587A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10.HIGH 7.5EPSS 35.3%13 September 2024
CVE-2024-46048Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function iCRITICAL 9.8EPSS 10.5%13 September 2024
CVE-2024-41874ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.8EPSS 30.3%13 September 2024
CVE-2024-38816Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks.HIGH 7.5EPSS 14.7%13 September 2024
CVE-2024-45607This vulnerability is fixed in 4.0.3.MEDIUM 5.3EPSS 14.5%12 September 2024
CVE-2024-8124An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.HIGH 7.5EPSS 40.0%12 September 2024
CVE-2024-45826CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request.HIGH 8.5EPSS 12.3%12 September 2024
CVE-2024-8529The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient…HIGH 7.5EPSS 11.8%12 September 2024
CVE-2024-8522The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping…HIGH 7.5EPSS 62.9%12 September 2024
CVE-2024-37397An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.HIGH 8.2EPSS 59.3%12 September 2024
CVE-2024-34785An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 25.4%12 September 2024
CVE-2024-34783An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 43.4%12 September 2024
CVE-2024-34779An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 24.0%12 September 2024
CVE-2024-32848An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 43.4%12 September 2024
CVE-2024-32845An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 24.0%12 September 2024
CVE-2024-32840An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 25.4%12 September 2024
CVE-2024-29847Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.CRITICAL 9.8EPSS 52.9%12 September 2024
CVE-2024-44466COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4.CRITICAL 9.8EPSS 10.7%11 September 2024
CVE-2024-8191SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.CRITICAL 9.8EPSS 20.3%10 September 2024
CVE-2024-8190Ivanti Cloud Services Appliance OS Command Injection VulnerabilityKEVHIGH 7.2EPSS 88.5%10 September 2024
CVE-2024-8504An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user.HIGH 8.8EPSS 76.2%10 September 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.