SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 28 of 348

CVESummaryPriorityPublished
CVE-2024-38878A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions).MEDIUM 6.9EPSS 11.5%2 August 2024
CVE-2024-7339A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic.MEDIUM 6.9EPSS 32.0%1 August 2024
CVE-2024-7332A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224.CRITICAL 9.3EPSS 20.7%1 August 2024
CVE-2024-37900When uploading an attachment with a malicious filename, malicious JavaScript code could be executed.MEDIUM 4.6EPSS 15.8%31 July 2024
CVE-2024-7264This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.MEDIUM 6.5EPSS 17.3%31 July 2024
CVE-2024-6255A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`.CRITICAL 9.1EPSS 13.1%31 July 2024
CVE-2024-7297Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.HIGH 8.8EPSS 21.3%30 July 2024
CVE-2024-5765The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injectionCRITICAL 9.8EPSS 27.2%30 July 2024
CVE-2024-6748Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.HIGH 8.3EPSS 23.8%29 July 2024
CVE-2024-6366The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.CRITICAL 9.1EPSS 29.0%29 July 2024
CVE-2024-7156A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic.MEDIUM 6.9EPSS 13.3%28 July 2024
CVE-2024-6922Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component.MEDIUM 6.9EPSS 30.2%26 July 2024
CVE-2024-7120A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90.MEDIUM 5.3EPSS 93.4%26 July 2024
CVE-2024-38289A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted…CRITICAL 9.8EPSS 40.6%25 July 2024
CVE-2024-37084In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the serverHIGH 8.8EPSS 35.2%25 July 2024
CVE-2024-41110A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances.CRITICAL 9.9EPSS 16.5%24 July 2024
CVE-2024-40422The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack.CRITICAL 9.1EPSS 11.3%24 July 2024
CVE-2023-45249Acronis Cyber Infrastructure (ACI) Insecure Default Password VulnerabilityKEVCRITICAL 9.8EPSS 53.3%24 July 2024
CVE-2024-32484An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.HIGH 8.2EPSS 21.4%22 July 2024
CVE-2024-32152A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04.MEDIUM 4.3EPSS 12.2%22 July 2024
CVE-2024-29073An vulnerability in the handling of Latex exists in Ankitects Anki 24.04.MEDIUM 6.5EPSS 11.8%22 July 2024
CVE-2024-26020An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04.HIGH 8.8EPSS 15.2%22 July 2024
CVE-2024-6497The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping.MEDIUM 6.1EPSS 11.0%20 July 2024
CVE-2024-39123In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function.MEDIUM 5.4EPSS 23.1%19 July 2024
CVE-2024-41107In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication by submitting a spoofed SAML response with no signature and known or guessed…HIGH 8.1EPSS 17.8%19 July 2024
CVE-2024-39907There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs.CRITICAL 9.8EPSS 29.2%18 July 2024
CVE-2024-20419A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.CRITICAL 10.0EPSS 80.6%17 July 2024
CVE-2024-28074It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager.HIGH 8.8EPSS 10.9%17 July 2024
CVE-2024-23472SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability.HIGH 8.0EPSS 18.6%17 July 2024
CVE-2024-23469SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability.HIGH 8.8EPSS 17.9%17 July 2024
CVE-2024-6220The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2.CRITICAL 9.8EPSS 35.5%17 July 2024
CVE-2024-21182Oracle WebLogic Server Unspecified VulnerabilityKEVHIGH 7.5EPSS 74.2%16 July 2024
CVE-2024-6457The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied…HIGH 7.5EPSS 19.7%16 July 2024
CVE-2024-39914Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php.CRITICAL 9.8EPSS 23.2%12 July 2024
CVE-2024-6396A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data.CRITICAL 9.8EPSS 53.1%12 July 2024
CVE-2024-6037A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir).CRITICAL 9.1EPSS 10.7%10 July 2024
CVE-2024-6036A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`.CRITICAL 9.1EPSS 10.9%10 July 2024
CVE-2024-37149An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script.HIGH 8.8EPSS 21.1%10 July 2024
CVE-2024-37148An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take control of it.HIGH 8.1EPSS 20.2%10 July 2024
CVE-2024-6235Sensitive information disclosure in NetScaler ConsoleCRITICAL 9.4EPSS 21.2%10 July 2024
CVE-2024-5910Palo Alto Networks Expedition Missing Authentication VulnerabilityKEVCRITICAL 9.3EPSS 91.8%10 July 2024
CVE-2024-6646A vulnerability was found in Netgear WN604 up to 20240710.MEDIUM 6.9EPSS 45.7%10 July 2024
CVE-2024-5217ServiceNow Incomplete List of Disallowed Inputs VulnerabilityKEVCRITICAL 9.2EPSS 99.6%10 July 2024
CVE-2024-5178ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases.MEDIUM 6.9EPSS 33.6%10 July 2024
CVE-2024-4879ServiceNow Improper Input Validation VulnerabilityKEVCRITICAL 9.3EPSS 100.0%10 July 2024
CVE-2024-3799Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts…HIGH 8.7EPSS 14.6%10 July 2024
CVE-2024-39614An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.HIGH 7.5EPSS 28.6%10 July 2024
CVE-2024-38112Microsoft Windows MSHTML Platform Spoofing VulnerabilityKEVHIGH 7.5EPSS 84.2%9 July 2024
CVE-2024-38094Microsoft SharePoint Deserialization VulnerabilityKEVHIGH 7.2EPSS 50.9%9 July 2024
CVE-2024-38077Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 84.1%9 July 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.