SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 33 of 348

CVESummaryPriorityPublished
CVE-2023-38098NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability.HIGH 8.8EPSS 12.7%3 May 2024
CVE-2023-38096NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability.CRITICAL 9.8EPSS 82.0%3 May 2024
CVE-2023-38095NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability.HIGH 8.8EPSS 65.5%3 May 2024
CVE-2023-32169D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability.CRITICAL 9.8EPSS 56.1%3 May 2024
CVE-2023-32167D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability.MEDIUM 6.5EPSS 76.5%3 May 2024
CVE-2023-32166D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability.HIGH 8.1EPSS 74.3%3 May 2024
CVE-2023-32165D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 73.3%3 May 2024
CVE-2023-32164D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability.HIGH 7.5EPSS 84.9%3 May 2024
CVE-2023-32153D-Link DIR-2640 EmailFrom Command Injection Remote Code Execution Vulnerability.MEDIUM 6.8EPSS 23.4%3 May 2024
CVE-2023-32152D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability.MEDIUM 6.5EPSS 28.9%3 May 2024
CVE-2023-32150D-Link DIR-2640 PrefixLen Command Injection Remote Code Execution Vulnerability.MEDIUM 6.8EPSS 23.7%3 May 2024
CVE-2023-32148D-Link DIR-2640 HNAP PrivateLogin Authentication Bypass Vulnerability.MEDIUM 6.5EPSS 28.9%3 May 2024
CVE-2023-27363Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability.HIGH 7.8EPSS 47.0%3 May 2024
CVE-2024-2876The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and…CRITICAL 9.8EPSS 80.6%2 May 2024
CVE-2024-34144A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox…CRITICAL 9.8EPSS 48.1%2 May 2024
CVE-2023-49606A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0.CRITICAL 9.8EPSS 63.1%1 May 2024
CVE-2024-33512There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management…CRITICAL 9.8EPSS 14.6%1 May 2024
CVE-2024-33511There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port…CRITICAL 9.8EPSS 14.6%1 May 2024
CVE-2024-26305There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211).CRITICAL 9.8EPSS 15.2%1 May 2024
CVE-2024-26304There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port…CRITICAL 9.8EPSS 44.0%1 May 2024
CVE-2024-26331Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser.HIGH 7.5EPSS 51.3%30 April 2024
CVE-2024-25938A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget.HIGH 8.8EPSS 15.6%30 April 2024
CVE-2024-25648A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget.HIGH 8.8EPSS 15.6%30 April 2024
CVE-2024-25575A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object.HIGH 8.8EPSS 17.7%30 April 2024
CVE-2024-31621An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.HIGH 7.6EPSS 59.9%29 April 2024
CVE-2024-27322Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary…HIGH 8.8EPSS 23.6%29 April 2024
CVE-2024-2756Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP…MEDIUM 6.5EPSS 38.1%29 April 2024
CVE-2024-1874In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can…CRITICAL 9.4EPSS 32.6%29 April 2024
CVE-2024-4257A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1.MEDIUM 6.5EPSS 12.1%27 April 2024
CVE-2024-4236A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1.HIGH 8.8EPSS 14.9%26 April 2024
CVE-2024-33344D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.CRITICAL 9.8EPSS 19.9%26 April 2024
CVE-2023-51365A path traversal vulnerability has been reported to affect several QNAP operating system versions.HIGH 7.5EPSS 34.8%26 April 2024
CVE-2023-51364A path traversal vulnerability has been reported to affect several QNAP operating system versions.HIGH 7.5EPSS 41.6%26 April 2024
CVE-2024-32651There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host.CRITICAL 10.0EPSS 83.6%26 April 2024
CVE-2024-4024Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.HIGH 8.8EPSS 14.9%25 April 2024
CVE-2024-2829A crafted wildcard filter in FileFinder may lead to a denial of service.HIGH 7.5EPSS 26.0%25 April 2024
CVE-2024-2434An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.HIGH 8.1EPSS 23.2%25 April 2024
CVE-2024-20356A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and…HIGH 8.7EPSS 32.7%24 April 2024
CVE-2024-20359Cisco ASA and FTD Privilege Escalation VulnerabilityKEVMEDIUM 6.0EPSS 19.4%24 April 2024
CVE-2024-20353Cisco ASA and FTD Denial of Service VulnerabilityKEVHIGH 8.6EPSS 70.7%24 April 2024
CVE-2024-31077Forminator prior to 1.29.3 contains a SQL injection vulnerability.HIGH 7.2EPSS 30.4%23 April 2024
CVE-2024-32480Versions prior to 24.4.0 are vulnerable to SQL injection.HIGH 7.2EPSS 20.3%22 April 2024
CVE-2024-32479Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting.MEDIUM 5.4EPSS 34.1%22 April 2024
CVE-2024-32461A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter.HIGH 8.8EPSS 19.1%22 April 2024
CVE-2024-32394An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 allows a remote attacker to execute arbitrary code via a crafted HTTP request.HIGH 8.8EPSS 12.6%22 April 2024
CVE-2024-4040CrushFTP VFS Sandbox Escape VulnerabilityKEVCRITICAL 10.0EPSS 99.5%22 April 2024
CVE-2024-32238H3C ER8300G2-X is vulnerable to Incorrect Access Control.CRITICAL 9.8EPSS 52.9%22 April 2024
CVE-2024-27348Apache HugeGraph-Server Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 99.2%22 April 2024
CVE-2023-50260A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system.HIGH 8.8EPSS 41.2%19 April 2024
CVE-2024-24996A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.CRITICAL 9.8EPSS 32.2%19 April 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.