SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 30 of 348

CVESummaryPriorityPublished
CVE-2024-6269A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical.MEDIUM 5.1EPSS 20.6%23 June 2024
CVE-2024-21518A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations.HIGH 7.2EPSS 14.1%22 June 2024
CVE-2024-21514An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9.HIGH 8.1EPSS 19.1%22 June 2024
CVE-2014-5470Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.CRITICAL 9.8EPSS 10.0%21 June 2024
CVE-2012-6664Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a ..CRITICAL 9.1EPSS 29.5%21 June 2024
CVE-2024-5182A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files.CRITICAL 9.1EPSS 25.5%20 June 2024
CVE-2024-36680In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection.HIGH 7.5EPSS 10.1%19 June 2024
CVE-2024-32030Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port.HIGH 8.1EPSS 39.4%19 June 2024
CVE-2024-22263However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.HIGH 8.8EPSS 17.5%19 June 2024
CVE-2023-40004Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This…HIGH 7.3EPSS 11.0%19 June 2024
CVE-2024-37080vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.CRITICAL 9.8EPSS 12.5%18 June 2024
CVE-2024-37079Broadcom VMware vCenter Server Out-of-bounds Write VulnerabilityKEVCRITICAL 9.8EPSS 22.4%18 June 2024
CVE-2024-6047GeoVision Devices OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 10.1%17 June 2024
CVE-2024-37642TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .CRITICAL 9.1EPSS 11.4%14 June 2024
CVE-2024-27172Remote Command program allows an attacker to get Remote Code Execution.CRITICAL 9.8EPSS 26.8%14 June 2024
CVE-2024-27162The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer.MEDIUM 6.1EPSS 21.2%14 June 2024
CVE-2024-3080Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.CRITICAL 9.8EPSS 43.5%14 June 2024
CVE-2024-34112ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read.HIGH 7.5EPSS 23.7%13 June 2024
CVE-2024-34102Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) VulnerabilityKEVCRITICAL 9.8EPSS 100.0%13 June 2024
CVE-2024-3552The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION,…CRITICAL 9.8EPSS 67.1%13 June 2024
CVE-2024-3922The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…CRITICAL 9.8EPSS 52.9%13 June 2024
CVE-2024-35250Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability KEVHIGH 7.8EPSS 25.0%11 June 2024
CVE-2024-30088Microsoft Windows Kernel TOCTOU Race Condition VulnerabilityKEVHIGH 7.0EPSS 68.2%11 June 2024
CVE-2024-30085Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHIGH 7.8EPSS 14.3%11 June 2024
CVE-2024-30080Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 43.1%11 June 2024
CVE-2024-29855Hard-coded JWT secret allows authentication bypass in Veeam Recovery OrchestratorCRITICAL 9.0EPSS 21.6%11 June 2024
CVE-2024-37014Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.CRITICAL 9.8EPSS 63.0%10 June 2024
CVE-2024-4577PHP-CGI OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%9 June 2024
CVE-2024-5585Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows…HIGH 8.8EPSS 28.8%9 June 2024
CVE-2024-5458In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user…MEDIUM 5.3EPSS 12.1%9 June 2024
CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 73.3%7 June 2024
CVE-2024-4320A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler.CRITICAL 9.8EPSS 34.4%6 June 2024
CVE-2024-3429A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`.CRITICAL 9.8EPSS 28.3%6 June 2024
CVE-2024-3408man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation.CRITICAL 9.8EPSS 78.0%6 June 2024
CVE-2024-2928A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3.HIGH 7.5EPSS 21.8%6 June 2024
CVE-2024-1873parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0.CRITICAL 9.1EPSS 13.4%6 June 2024
CVE-2024-5505NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability.HIGH 8.8EPSS 47.0%6 June 2024
CVE-2024-5452A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library.CRITICAL 9.8EPSS 26.8%6 June 2024
CVE-2024-4325A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function.HIGH 8.6EPSS 37.4%6 June 2024
CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability KEVHIGH 7.5EPSS 99.6%6 June 2024
CVE-2024-20404A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.MEDIUM 5.3EPSS 22.6%5 June 2024
CVE-2024-4295The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient…CRITICAL 9.8EPSS 10.2%5 June 2024
CVE-2024-28999The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.HIGH 7.5EPSS 13.9%4 June 2024
CVE-2024-25600Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.CRITICAL 10.0EPSS 88.2%4 June 2024
CVE-2024-36104Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.CRITICAL 9.1EPSS 87.8%4 June 2024
CVE-2024-29974** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated…CRITICAL 9.8EPSS 22.8%4 June 2024
CVE-2024-29973** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to…CRITICAL 9.8EPSS 86.1%4 June 2024
CVE-2024-29972** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated…CRITICAL 9.8EPSS 89.3%4 June 2024
CVE-2024-34051A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.MEDIUM 4.6EPSS 12.0%3 June 2024
CVE-2024-29848An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.HIGH 7.2EPSS 64.4%31 May 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.