Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 30 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-6269 | A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. | MEDIUM 5.1EPSS 20.6% | 23 June 2024 |
| CVE-2024-21518 | A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations. | HIGH 7.2EPSS 14.1% | 22 June 2024 |
| CVE-2024-21514 | An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. | HIGH 8.1EPSS 19.1% | 22 June 2024 |
| CVE-2014-5470 | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation. | CRITICAL 9.8EPSS 10.0% | 21 June 2024 |
| CVE-2012-6664 | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. | CRITICAL 9.1EPSS 29.5% | 21 June 2024 |
| CVE-2024-5182 | A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. | CRITICAL 9.1EPSS 25.5% | 20 June 2024 |
| CVE-2024-36680 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. | HIGH 7.5EPSS 10.1% | 19 June 2024 |
| CVE-2024-32030 | Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. | HIGH 8.1EPSS 39.4% | 19 June 2024 |
| CVE-2024-22263 | However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server. | HIGH 8.8EPSS 17.5% | 19 June 2024 |
| CVE-2023-40004 | Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This… | HIGH 7.3EPSS 11.0% | 19 June 2024 |
| CVE-2024-37080 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. | CRITICAL 9.8EPSS 12.5% | 18 June 2024 |
| CVE-2024-37079 | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 22.4% | 18 June 2024 |
| CVE-2024-6047 | GeoVision Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 10.1% | 17 June 2024 |
| CVE-2024-37642 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck . | CRITICAL 9.1EPSS 11.4% | 14 June 2024 |
| CVE-2024-27172 | Remote Command program allows an attacker to get Remote Code Execution. | CRITICAL 9.8EPSS 26.8% | 14 June 2024 |
| CVE-2024-27162 | The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. | MEDIUM 6.1EPSS 21.2% | 14 June 2024 |
| CVE-2024-3080 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. | CRITICAL 9.8EPSS 43.5% | 14 June 2024 |
| CVE-2024-34112 | ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. | HIGH 7.5EPSS 23.7% | 13 June 2024 |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 13 June 2024 |
| CVE-2024-3552 | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION,… | CRITICAL 9.8EPSS 67.1% | 13 June 2024 |
| CVE-2024-3922 | The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | CRITICAL 9.8EPSS 52.9% | 13 June 2024 |
| CVE-2024-35250 | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | KEVHIGH 7.8EPSS 25.0% | 11 June 2024 |
| CVE-2024-30088 | Microsoft Windows Kernel TOCTOU Race Condition Vulnerability | KEVHIGH 7.0EPSS 68.2% | 11 June 2024 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH 7.8EPSS 14.3% | 11 June 2024 |
| CVE-2024-30080 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 43.1% | 11 June 2024 |
| CVE-2024-29855 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator | CRITICAL 9.0EPSS 21.6% | 11 June 2024 |
| CVE-2024-37014 | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script. | CRITICAL 9.8EPSS 63.0% | 10 June 2024 |
| CVE-2024-4577 | PHP-CGI OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 9 June 2024 |
| CVE-2024-5585 | Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows… | HIGH 8.8EPSS 28.8% | 9 June 2024 |
| CVE-2024-5458 | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user… | MEDIUM 5.3EPSS 12.1% | 9 June 2024 |
| CVE-2024-37383 | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 73.3% | 7 June 2024 |
| CVE-2024-4320 | A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. | CRITICAL 9.8EPSS 34.4% | 6 June 2024 |
| CVE-2024-3429 | A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. | CRITICAL 9.8EPSS 28.3% | 6 June 2024 |
| CVE-2024-3408 | man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. | CRITICAL 9.8EPSS 78.0% | 6 June 2024 |
| CVE-2024-2928 | A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. | HIGH 7.5EPSS 21.8% | 6 June 2024 |
| CVE-2024-1873 | parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. | CRITICAL 9.1EPSS 13.4% | 6 June 2024 |
| CVE-2024-5505 | NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. | HIGH 8.8EPSS 47.0% | 6 June 2024 |
| CVE-2024-5452 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. | CRITICAL 9.8EPSS 26.8% | 6 June 2024 |
| CVE-2024-4325 | A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. | HIGH 8.6EPSS 37.4% | 6 June 2024 |
| CVE-2024-28995 | SolarWinds Serv-U Path Traversal Vulnerability | KEVHIGH 7.5EPSS 99.6% | 6 June 2024 |
| CVE-2024-20404 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. | MEDIUM 5.3EPSS 22.6% | 5 June 2024 |
| CVE-2024-4295 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient… | CRITICAL 9.8EPSS 10.2% | 5 June 2024 |
| CVE-2024-28999 | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | HIGH 7.5EPSS 13.9% | 4 June 2024 |
| CVE-2024-25600 | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6. | CRITICAL 10.0EPSS 88.2% | 4 June 2024 |
| CVE-2024-36104 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. | CRITICAL 9.1EPSS 87.8% | 4 June 2024 |
| CVE-2024-29974 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated… | CRITICAL 9.8EPSS 22.8% | 4 June 2024 |
| CVE-2024-29973 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to… | CRITICAL 9.8EPSS 86.1% | 4 June 2024 |
| CVE-2024-29972 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated… | CRITICAL 9.8EPSS 89.3% | 4 June 2024 |
| CVE-2024-34051 | A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter. | MEDIUM 4.6EPSS 12.0% | 3 June 2024 |
| CVE-2024-29848 | An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM. | HIGH 7.2EPSS 64.4% | 31 May 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.