Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 31 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-29827 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | HIGH 8.8EPSS 71.7% | 31 May 2024 |
| CVE-2024-29826 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | HIGH 8.8EPSS 99.9% | 31 May 2024 |
| CVE-2024-29825 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | HIGH 8.8EPSS 99.9% | 31 May 2024 |
| CVE-2024-29824 | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | KEVHIGH 8.8EPSS 100.0% | 31 May 2024 |
| CVE-2024-29823 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | HIGH 8.8EPSS 99.9% | 31 May 2024 |
| CVE-2024-29822 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | HIGH 8.8EPSS 64.4% | 31 May 2024 |
| CVE-2024-5565 | The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. | HIGH 8.1EPSS 15.0% | 31 May 2024 |
| CVE-2024-23692 | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | KEVCRITICAL 9.8EPSS 99.5% | 31 May 2024 |
| CVE-2024-37032 | Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../… | HIGH 8.8EPSS 89.6% | 31 May 2024 |
| CVE-2024-4358 | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | KEVCRITICAL 9.8EPSS 97.5% | 29 May 2024 |
| CVE-2024-24919 | Check Point Quantum Security Gateways Information Disclosure Vulnerability | KEVHIGH 8.6EPSS 100.0% | 28 May 2024 |
| CVE-2024-34854 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` | CRITICAL 9.8EPSS 12.8% | 28 May 2024 |
| CVE-2024-35397 | TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. | HIGH 8.8EPSS 15.1% | 28 May 2024 |
| CVE-2024-5411 | Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below. | HIGH 8.7EPSS 23.4% | 28 May 2024 |
| CVE-2024-5410 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | HIGH 8.3EPSS 13.7% | 28 May 2024 |
| CVE-2024-5315 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. | CRITICAL 9.1EPSS 34.5% | 24 May 2024 |
| CVE-2024-5247 | NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. | HIGH 8.8EPSS 26.9% | 23 May 2024 |
| CVE-2024-5246 | NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. | HIGH 8.8EPSS 31.3% | 23 May 2024 |
| CVE-2024-5084 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. | CRITICAL 9.8EPSS 50.7% | 23 May 2024 |
| CVE-2024-5230 | A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. | MEDIUM 6.9EPSS 18.8% | 23 May 2024 |
| CVE-2024-4978 | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | KEVHIGH 8.7EPSS 26.9% | 23 May 2024 |
| CVE-2024-29849 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | CRITICAL 9.8EPSS 38.4% | 22 May 2024 |
| CVE-2024-5196 | A vulnerability classified as critical has been found in Arris VAP2500 08.50. | MEDIUM 5.1EPSS 23.4% | 22 May 2024 |
| CVE-2024-5195 | A vulnerability was found in Arris VAP2500 08.50. | MEDIUM 5.1EPSS 23.4% | 22 May 2024 |
| CVE-2024-3495 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient… | CRITICAL 9.8EPSS 13.6% | 22 May 2024 |
| CVE-2024-4443 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user… | HIGH 7.5EPSS 10.4% | 22 May 2024 |
| CVE-2024-21683 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. | HIGH 8.8EPSS 88.3% | 21 May 2024 |
| CVE-2024-27130 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. | HIGH 8.8EPSS 37.5% | 21 May 2024 |
| CVE-2023-52755 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. | CRITICAL 9.8EPSS 27.9% | 21 May 2024 |
| CVE-2024-4323 | A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. | CRITICAL 9.8EPSS 27.2% | 20 May 2024 |
| CVE-2024-22120 | Zabbix server can perform command execution for configured scripts. | HIGH 8.8EPSS 76.6% | 17 May 2024 |
| CVE-2024-27954 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0. | CRITICAL 9.3EPSS 72.8% | 17 May 2024 |
| CVE-2024-22476 | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access. | CRITICAL 10.0EPSS 36.0% | 16 May 2024 |
| CVE-2024-4956 | Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. | HIGH 7.5EPSS 18.2% | 16 May 2024 |
| CVE-2024-31142 | XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. | HIGH 7.5EPSS 17.4% | 16 May 2024 |
| CVE-2024-4999 | A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883;… | CRITICAL 9.4EPSS 12.2% | 16 May 2024 |
| CVE-2024-4322 | A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. | HIGH 7.5EPSS 31.0% | 16 May 2024 |
| CVE-2024-3848 | A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. | HIGH 7.5EPSS 43.3% | 16 May 2024 |
| CVE-2024-4947 | Google Chromium V8 Type Confusion Vulnerability | KEVCRITICAL 9.6EPSS 15.2% | 15 May 2024 |
| CVE-2024-32002 | This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. | CRITICAL 9.0EPSS 29.2% | 14 May 2024 |
| CVE-2024-4367 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. | HIGH 8.8EPSS 70.7% | 14 May 2024 |
| CVE-2024-30050 | Windows Mark of the Web Security Feature Bypass Vulnerability | MEDIUM 5.4EPSS 11.5% | 14 May 2024 |
| CVE-2024-30044 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 7.2EPSS 84.0% | 14 May 2024 |
| CVE-2024-30043 | Microsoft SharePoint Server Information Disclosure Vulnerability | HIGH 7.5EPSS 54.7% | 14 May 2024 |
| CVE-2024-4761 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | KEVHIGH 8.8EPSS 11.0% | 14 May 2024 |
| CVE-2024-34716 | A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. | MEDIUM 6.1EPSS 56.4% | 14 May 2024 |
| CVE-2024-4701 | A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18 | CRITICAL 9.9EPSS 24.6% | 14 May 2024 |
| CVE-2024-4434 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | CRITICAL 9.8EPSS 36.9% | 14 May 2024 |
| CVE-2024-4044 | A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. | HIGH 7.8EPSS 14.7% | 14 May 2024 |
| CVE-2024-34359 | This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload. | CRITICAL 9.6EPSS 28.4% | 14 May 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.