Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 26 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-8503 | An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. | CRITICAL 9.8EPSS 80.2% | 10 September 2024 |
| CVE-2024-8232 | SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication. | HIGH 8.7EPSS 13.1% | 10 September 2024 |
| CVE-2024-45409 | An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. | CRITICAL 9.8EPSS 10.7% | 10 September 2024 |
| CVE-2024-44871 | An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. | HIGH 7.2EPSS 16.2% | 10 September 2024 |
| CVE-2024-43491 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). | CRITICAL 9.8EPSS 12.4% | 10 September 2024 |
| CVE-2024-43464 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 7.2EPSS 36.3% | 10 September 2024 |
| CVE-2024-43461 | Microsoft Windows MSHTML Platform Spoofing Vulnerability | KEVHIGH 8.8EPSS 54.5% | 10 September 2024 |
| CVE-2024-43454 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | HIGH 7.1EPSS 21.9% | 10 September 2024 |
| CVE-2024-38217 | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability | KEVMEDIUM 5.4EPSS 10.0% | 10 September 2024 |
| CVE-2024-38018 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 51.5% | 10 September 2024 |
| CVE-2024-44087 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). | CRITICAL 9.2EPSS 10.9% | 10 September 2024 |
| CVE-2024-44849 | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. | CRITICAL 9.8EPSS 46.3% | 9 September 2024 |
| CVE-2024-44335 | D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp. | HIGH 8.8EPSS 12.4% | 9 September 2024 |
| CVE-2024-44334 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI… | HIGH 8.8EPSS 31.8% | 9 September 2024 |
| CVE-2024-44333 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. | HIGH 8.8EPSS 12.4% | 9 September 2024 |
| CVE-2024-40711 | Veeam Backup and Replication Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 90.4% | 7 September 2024 |
| CVE-2024-8517 | SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. | CRITICAL 9.8EPSS 94.6% | 6 September 2024 |
| CVE-2024-7591 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above | HIGH 7.2EPSS 43.8% | 5 September 2024 |
| CVE-2024-20440 | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. | HIGH 7.5EPSS 51.9% | 4 September 2024 |
| CVE-2024-20439 | Cisco Smart Licensing Utility Static Credential Vulnerability | KEVCRITICAL 9.8EPSS 92.1% | 4 September 2024 |
| CVE-2024-44400 | A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. | CRITICAL 9.8EPSS 14.5% | 4 September 2024 |
| CVE-2024-45507 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. | CRITICAL 9.8EPSS 93.2% | 4 September 2024 |
| CVE-2024-45195 | Apache OFBiz Forced Browsing Vulnerability | KEVHIGH 7.5EPSS 100.0% | 4 September 2024 |
| CVE-2024-6119 | Impact summary: Abnormal termination of an application can a cause a denial of service. | HIGH 7.5EPSS 66.6% | 3 September 2024 |
| CVE-2024-7261 | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and… | CRITICAL 9.8EPSS 11.4% | 3 September 2024 |
| CVE-2024-45622 | ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass. | CRITICAL 9.8EPSS 36.7% | 2 September 2024 |
| CVE-2024-45388 | The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. | HIGH 7.5EPSS 55.6% | 2 September 2024 |
| CVE-2024-45488 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. | CRITICAL 9.8EPSS 50.6% | 30 August 2024 |
| CVE-2024-6671 | In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | CRITICAL 9.8EPSS 19.0% | 29 August 2024 |
| CVE-2024-6670 | Progress WhatsUp Gold SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 93.0% | 29 August 2024 |
| CVE-2024-43917 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2. | CRITICAL 9.8EPSS 23.0% | 29 August 2024 |
| CVE-2024-7856 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the… | HIGH 8.1EPSS 19.2% | 29 August 2024 |
| CVE-2024-42905 | DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file. | CRITICAL 9.8EPSS 15.4% | 28 August 2024 |
| CVE-2024-8182 | An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api… | HIGH 7.5EPSS 13.9% | 27 August 2024 |
| CVE-2024-8181 | An Authentication Bypass vulnerability exists in Flowise version 1.8.2. | HIGH 8.1EPSS 45.1% | 27 August 2024 |
| CVE-2023-26315 | The Xiaomi router AX9000 has a post-authentication command injection vulnerability. | HIGH 8.8EPSS 19.4% | 26 August 2024 |
| CVE-2024-45241 | A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of… | HIGH 7.5EPSS 13.6% | 26 August 2024 |
| CVE-2024-8132 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. | MEDIUM 5.3EPSS 23.4% | 24 August 2024 |
| CVE-2024-8129 | A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4,… | MEDIUM 5.3EPSS 22.9% | 24 August 2024 |
| CVE-2024-7954 | The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. | CRITICAL 9.8EPSS 90.1% | 23 August 2024 |
| CVE-2024-32501 | A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23. | CRITICAL 9.8EPSS 19.2% | 23 August 2024 |
| CVE-2024-42756 | An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page | HIGH 8.8EPSS 13.5% | 23 August 2024 |
| CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 18.2% | 23 August 2024 |
| CVE-2024-28987 | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | KEVCRITICAL 9.1EPSS 93.2% | 21 August 2024 |
| CVE-2024-7971 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.6EPSS 20.7% | 21 August 2024 |
| CVE-2024-7965 | Google Chromium V8 Inappropriate Implementation Vulnerability | KEVHIGH 8.8EPSS 18.5% | 21 August 2024 |
| CVE-2024-6386 | The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. | HIGH 8.8EPSS 25.5% | 21 August 2024 |
| CVE-2024-5762 | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. | HIGH 8.1EPSS 71.6% | 21 August 2024 |
| CVE-2024-5725 | Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 47.4% | 21 August 2024 |
| CVE-2024-5723 | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 40.7% | 21 August 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.