Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 27 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-28000 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | CRITICAL 9.8EPSS 68.3% | 21 August 2024 |
| CVE-2024-5932 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. | CRITICAL 9.8EPSS 76.8% | 20 August 2024 |
| CVE-2024-7928 | A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. | MEDIUM 5.3EPSS 16.9% | 19 August 2024 |
| CVE-2024-42812 | In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. | CRITICAL 9.8EPSS 15.5% | 19 August 2024 |
| CVE-2024-7922 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814… | MEDIUM 5.3EPSS 19.5% | 19 August 2024 |
| CVE-2024-7646 | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of… | HIGH 8.8EPSS 27.0% | 16 August 2024 |
| CVE-2024-42948 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. | HIGH 7.5EPSS 10.6% | 15 August 2024 |
| CVE-2024-7828 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4,… | HIGH 8.7EPSS 16.2% | 15 August 2024 |
| CVE-2024-38653 | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. | HIGH 7.5EPSS 92.0% | 14 August 2024 |
| CVE-2024-37399 | A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS. | HIGH 7.5EPSS 27.8% | 14 August 2024 |
| CVE-2024-28986 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 84.6% | 13 August 2024 |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 13 August 2024 |
| CVE-2024-38213 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVMEDIUM 6.5EPSS 13.6% | 13 August 2024 |
| CVE-2024-38197 | Microsoft Teams for iOS Spoofing Vulnerability | MEDIUM 6.5EPSS 16.1% | 13 August 2024 |
| CVE-2024-38193 | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 28.5% | 13 August 2024 |
| CVE-2024-38178 | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 41.4% | 13 August 2024 |
| CVE-2024-38148 | Windows Secure Channel Denial of Service Vulnerability | HIGH 7.5EPSS 31.8% | 13 August 2024 |
| CVE-2024-38144 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | HIGH 8.8EPSS 32.3% | 13 August 2024 |
| CVE-2024-38063 | Windows TCP/IP Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 70.6% | 13 August 2024 |
| CVE-2024-7715 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4,… | MEDIUM 5.3EPSS 25.1% | 13 August 2024 |
| CVE-2024-41730 | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. | CRITICAL 9.8EPSS 75.9% | 13 August 2024 |
| CVE-2024-7094 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. | CRITICAL 9.8EPSS 37.6% | 13 August 2024 |
| CVE-2024-41710 | Mitel SIP Phones Argument Injection Vulnerability | KEVHIGH 7.2EPSS 41.6% | 12 August 2024 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 23.6% | 12 August 2024 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 12 August 2024 |
| CVE-2024-38200 | Microsoft Office Spoofing Vulnerability | MEDIUM 6.5EPSS 20.3% | 12 August 2024 |
| CVE-2024-6893 | The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. | HIGH 7.5EPSS 32.9% | 8 August 2024 |
| CVE-2024-43044 | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library. | HIGH 8.8EPSS 28.8% | 7 August 2024 |
| CVE-2024-38206 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | MEDIUM 6.5EPSS 12.3% | 6 August 2024 |
| CVE-2024-28739 | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter. | HIGH 7.2EPSS 18.9% | 6 August 2024 |
| CVE-2024-39226 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a… | CRITICAL 9.8EPSS 20.4% | 6 August 2024 |
| CVE-2024-39225 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote… | CRITICAL 9.8EPSS 14.4% | 6 August 2024 |
| CVE-2024-6651 | The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | MEDIUM 6.1EPSS 15.0% | 6 August 2024 |
| CVE-2024-7009 | Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database. | HIGH 7.1EPSS 13.9% | 6 August 2024 |
| CVE-2024-7008 | Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. | MEDIUM 6.1EPSS 25.6% | 6 August 2024 |
| CVE-2024-6886 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0. | CRITICAL 10.0EPSS 33.0% | 6 August 2024 |
| CVE-2024-6782 | Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. | CRITICAL 9.8EPSS 84.1% | 6 August 2024 |
| CVE-2024-6781 | Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. | HIGH 7.5EPSS 62.4% | 6 August 2024 |
| CVE-2024-42010 | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information. | HIGH 7.5EPSS 52.8% | 5 August 2024 |
| CVE-2024-42009 | RoundCube Webmail Cross-Site Scripting Vulnerability | KEVCRITICAL 9.3EPSS 82.9% | 5 August 2024 |
| CVE-2024-42008 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type… | CRITICAL 9.3EPSS 35.9% | 5 August 2024 |
| CVE-2024-38856 | Apache OFBiz Incorrect Authorization Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 5 August 2024 |
| CVE-2024-7470 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. | MEDIUM 5.3EPSS 24.9% | 5 August 2024 |
| CVE-2024-7469 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. | MEDIUM 5.3EPSS 24.9% | 5 August 2024 |
| CVE-2024-7468 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. | MEDIUM 5.3EPSS 24.9% | 5 August 2024 |
| CVE-2024-7467 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. | MEDIUM 5.3EPSS 23.4% | 5 August 2024 |
| CVE-2024-7464 | A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. | MEDIUM 5.3EPSS 19.9% | 5 August 2024 |
| CVE-2024-7463 | A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. | HIGH 8.7EPSS 11.0% | 5 August 2024 |
| CVE-2024-7314 | anji-plus AJ-Report is affected by an authentication bypass vulnerability. | CRITICAL 9.8EPSS 51.7% | 2 August 2024 |
| CVE-2024-7029 | Commands can be injected over the network and executed without authentication. | HIGH 8.7EPSS 39.0% | 2 August 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.