SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 29 of 348

CVESummaryPriorityPublished
CVE-2024-38071Windows Remote Desktop Licensing Service Denial of Service VulnerabilityHIGH 7.5EPSS 35.9%9 July 2024
CVE-2024-38060Windows Imaging Component Remote Code Execution VulnerabilityHIGH 8.8EPSS 15.9%9 July 2024
CVE-2024-38054Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityHIGH 7.8EPSS 10.4%9 July 2024
CVE-2024-38030Windows Themes Spoofing VulnerabilityMEDIUM 6.5EPSS 51.1%9 July 2024
CVE-2024-38024Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 7.2EPSS 45.2%9 July 2024
CVE-2024-38023Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 7.2EPSS 52.9%9 July 2024
CVE-2024-30081Windows NTLM Spoofing VulnerabilityHIGH 7.1EPSS 23.8%9 July 2024
CVE-2024-3596RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response…CRITICAL 9.0EPSS 14.9%9 July 2024
CVE-2024-6409A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd).HIGH 7.0EPSS 27.9%8 July 2024
CVE-2024-1305tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel spaceCRITICAL 9.8EPSS 15.4%8 July 2024
CVE-2024-37389Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting.MEDIUM 5.4EPSS 24.0%8 July 2024
CVE-2024-6298Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotelyCRITICAL 9.4EPSS 19.0%5 July 2024
CVE-2024-6209Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorizedCRITICAL 9.4EPSS 17.2%5 July 2024
CVE-2024-39943rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions).HIGH 8.8EPSS 39.5%4 July 2024
CVE-2024-39932Gogs through 0.13.0 allows argument injection during the previewing of changes.CRITICAL 9.9EPSS 17.3%4 July 2024
CVE-2024-39931Gogs through 0.13.0 allows deletion of internal files.CRITICAL 9.9EPSS 52.7%4 July 2024
CVE-2024-39929Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.MEDIUM 5.4EPSS 41.2%4 July 2024
CVE-2024-29510Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.MEDIUM 6.3EPSS 28.0%3 July 2024
CVE-2024-32937An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.CRITICAL 9.8EPSS 26.3%3 July 2024
CVE-2024-36404Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input.CRITICAL 9.8EPSS 76.1%2 July 2024
CVE-2024-39309A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database.CRITICAL 9.8EPSS 20.2%1 July 2024
CVE-2024-38368A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk.CRITICAL 9.3EPSS 14.9%1 July 2024
CVE-2024-38367trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.CRITICAL 9.6EPSS 11.1%1 July 2024
CVE-2024-38366The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity.CRITICAL 10.0EPSS 17.8%1 July 2024
CVE-2024-39573Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.HIGH 7.5EPSS 37.2%1 July 2024
CVE-2024-38476Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.CRITICAL 9.8EPSS 41.6%1 July 2024
CVE-2024-38475Apache HTTP Server Improper Escaping of Output VulnerabilityKEVCRITICAL 9.1EPSS 100.0%1 July 2024
CVE-2024-38473Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.HIGH 8.1EPSS 25.9%1 July 2024
CVE-2024-38472SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.HIGH 7.5EPSS 69.5%1 July 2024
CVE-2024-36991In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows.HIGH 7.5EPSS 13.0%1 July 2024
CVE-2024-36401OSGeo GeoServer GeoTools Eval Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.8%1 July 2024
CVE-2024-6387There is a race condition which can lead sshd to handle some signals in an unsafe manner.HIGH 8.1EPSS 99.5%1 July 2024
CVE-2024-6127BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution.CRITICAL 9.8EPSS 10.3%27 June 2024
CVE-2024-5936An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter.MEDIUM 6.1EPSS 30.1%27 June 2024
CVE-2024-4901An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with…MEDIUM 5.4EPSS 33.0%27 June 2024
CVE-2024-5016In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.HIGH 7.2EPSS 22.4%25 June 2024
CVE-2024-37843Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.CRITICAL 9.8EPSS 53.2%25 June 2024
CVE-2024-5276A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.CRITICAL 9.1EPSS 90.1%25 June 2024
CVE-2024-5011In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists.HIGH 7.5EPSS 47.1%25 June 2024
CVE-2024-5010In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.HIGH 7.5EPSS 70.0%25 June 2024
CVE-2024-5009In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.HIGH 8.4EPSS 17.4%25 June 2024
CVE-2024-5008In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.HIGH 8.8EPSS 17.3%25 June 2024
CVE-2024-4885Progress WhatsUp Gold Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 99.3%25 June 2024
CVE-2024-4884In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.CRITICAL 9.8EPSS 24.3%25 June 2024
CVE-2024-4883In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold.CRITICAL 9.8EPSS 64.8%25 June 2024
CVE-2024-5806Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.CRITICAL 9.8EPSS 81.5%25 June 2024
CVE-2024-37085VMware ESXi Authentication Bypass VulnerabilityKEVHIGH 7.2EPSS 26.8%25 June 2024
CVE-2024-6028The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…CRITICAL 9.8EPSS 11.8%25 June 2024
CVE-2024-37732Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.MEDIUM 6.1EPSS 16.6%24 June 2024
CVE-2024-27136XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.MEDIUM 6.1EPSS 60.8%24 June 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.