Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 32 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-34219 | TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet. | HIGH 8.6EPSS 20.8% | 14 May 2024 |
| CVE-2024-34218 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. | LOW 3.8EPSS 17.6% | 14 May 2024 |
| CVE-2024-32964 | Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. | CRITICAL 9.0EPSS 53.0% | 14 May 2024 |
| CVE-2024-31458 | Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from… | HIGH 8.0EPSS 12.6% | 14 May 2024 |
| CVE-2024-31445 | Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. | HIGH 8.8EPSS 26.2% | 14 May 2024 |
| CVE-2024-31444 | Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` ,… | MEDIUM 5.4EPSS 14.7% | 14 May 2024 |
| CVE-2024-2651 | It was possible for an attacker to cause a denial of service using maliciously crafted markdown content. | MEDIUM 6.5EPSS 33.3% | 14 May 2024 |
| CVE-2024-2454 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. | MEDIUM 6.5EPSS 33.3% | 14 May 2024 |
| CVE-2024-29895 | A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. | CRITICAL 10.0EPSS 98.5% | 14 May 2024 |
| CVE-2024-28075 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. | HIGH 8.0EPSS 78.0% | 14 May 2024 |
| CVE-2024-25641 | Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. | HIGH 7.2EPSS 86.3% | 14 May 2024 |
| CVE-2024-0088 | NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. | HIGH 8.1EPSS 18.9% | 14 May 2024 |
| CVE-2024-0087 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. | HIGH 8.8EPSS 19.9% | 14 May 2024 |
| CVE-2024-32113 | Apache OFBiz Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 8 May 2024 |
| CVE-2024-31456 | Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. | MEDIUM 6.5EPSS 59.1% | 7 May 2024 |
| CVE-2024-29889 | Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. | HIGH 8.1EPSS 63.0% | 7 May 2024 |
| CVE-2024-4548 | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. | CRITICAL 9.8EPSS 29.4% | 6 May 2024 |
| CVE-2024-4439 | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. | MEDIUM 6.1EPSS 71.0% | 3 May 2024 |
| CVE-2023-51595 | Voltronic Power ViewPower Pro selectDeviceListBy SQL Injection Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 48.2% | 3 May 2024 |
| CVE-2023-51587 | Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. | HIGH 7.5EPSS 36.0% | 3 May 2024 |
| CVE-2023-50231 | NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. | CRITICAL 9.6EPSS 53.3% | 3 May 2024 |
| CVE-2023-50224 | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | KEVMEDIUM 6.5EPSS 15.6% | 3 May 2024 |
| CVE-2023-50223 | Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. | HIGH 8.8EPSS 55.2% | 3 May 2024 |
| CVE-2023-50218 | Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. | HIGH 8.8EPSS 55.0% | 3 May 2024 |
| CVE-2023-44450 | NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 53.6% | 3 May 2024 |
| CVE-2023-44449 | NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. | HIGH 8.8EPSS 52.6% | 3 May 2024 |
| CVE-2023-44444 | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. | HIGH 7.8EPSS 56.4% | 3 May 2024 |
| CVE-2023-44443 | GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. | HIGH 7.8EPSS 93.6% | 3 May 2024 |
| CVE-2023-44442 | GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. | HIGH 7.8EPSS 61.4% | 3 May 2024 |
| CVE-2023-44441 | GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. | HIGH 7.8EPSS 27.3% | 3 May 2024 |
| CVE-2023-44412 | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. | HIGH 8.2EPSS 83.7% | 3 May 2024 |
| CVE-2023-42118 | Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. | HIGH 8.8EPSS 51.8% | 3 May 2024 |
| CVE-2023-42114 | Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. | MEDIUM 5.3EPSS 28.1% | 3 May 2024 |
| CVE-2023-41183 | NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. | HIGH 8.8EPSS 13.6% | 3 May 2024 |
| CVE-2023-41182 | NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. | HIGH 8.8EPSS 62.3% | 3 May 2024 |
| CVE-2023-40504 | LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 88.7% | 3 May 2024 |
| CVE-2023-40502 | LG Simple Editor cropImage Directory Traversal Arbitrary File Deletion Vulnerability. | CRITICAL 9.1EPSS 83.1% | 3 May 2024 |
| CVE-2023-40498 | LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 85.1% | 3 May 2024 |
| CVE-2023-40497 | LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 69.4% | 3 May 2024 |
| CVE-2023-40496 | LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. | HIGH 7.5EPSS 75.7% | 3 May 2024 |
| CVE-2023-40495 | LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. | HIGH 7.5EPSS 75.7% | 3 May 2024 |
| CVE-2023-40494 | LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. | CRITICAL 9.1EPSS 83.1% | 3 May 2024 |
| CVE-2023-40492 | LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. | CRITICAL 9.1EPSS 83.1% | 3 May 2024 |
| CVE-2023-40481 | 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. | HIGH 7.8EPSS 13.9% | 3 May 2024 |
| CVE-2023-40477 | RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. | HIGH 7.8EPSS 11.4% | 3 May 2024 |
| CVE-2023-39475 | Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 64.1% | 3 May 2024 |
| CVE-2023-39473 | Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. | HIGH 8.8EPSS 62.5% | 3 May 2024 |
| CVE-2023-39469 | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. | HIGH 7.2EPSS 61.4% | 3 May 2024 |
| CVE-2023-38124 | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. | HIGH 8.8EPSS 59.6% | 3 May 2024 |
| CVE-2023-38099 | NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 56.8% | 3 May 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.