Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 33 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2023-38098 | NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. | HIGH 8.8EPSS 12.7% | 3 May 2024 |
| CVE-2023-38096 | NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. | CRITICAL 9.8EPSS 82.0% | 3 May 2024 |
| CVE-2023-38095 | NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. | HIGH 8.8EPSS 65.5% | 3 May 2024 |
| CVE-2023-32169 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. | CRITICAL 9.8EPSS 56.1% | 3 May 2024 |
| CVE-2023-32167 | D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability. | MEDIUM 6.5EPSS 76.5% | 3 May 2024 |
| CVE-2023-32166 | D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability. | HIGH 8.1EPSS 74.3% | 3 May 2024 |
| CVE-2023-32165 | D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 73.3% | 3 May 2024 |
| CVE-2023-32164 | D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. | HIGH 7.5EPSS 84.9% | 3 May 2024 |
| CVE-2023-32153 | D-Link DIR-2640 EmailFrom Command Injection Remote Code Execution Vulnerability. | MEDIUM 6.8EPSS 23.4% | 3 May 2024 |
| CVE-2023-32152 | D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability. | MEDIUM 6.5EPSS 28.9% | 3 May 2024 |
| CVE-2023-32150 | D-Link DIR-2640 PrefixLen Command Injection Remote Code Execution Vulnerability. | MEDIUM 6.8EPSS 23.7% | 3 May 2024 |
| CVE-2023-32148 | D-Link DIR-2640 HNAP PrivateLogin Authentication Bypass Vulnerability. | MEDIUM 6.5EPSS 28.9% | 3 May 2024 |
| CVE-2023-27363 | Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. | HIGH 7.8EPSS 47.0% | 3 May 2024 |
| CVE-2024-2876 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and… | CRITICAL 9.8EPSS 80.6% | 2 May 2024 |
| CVE-2024-34144 | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox… | CRITICAL 9.8EPSS 48.1% | 2 May 2024 |
| CVE-2023-49606 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. | CRITICAL 9.8EPSS 63.1% | 1 May 2024 |
| CVE-2024-33512 | There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management… | CRITICAL 9.8EPSS 14.6% | 1 May 2024 |
| CVE-2024-33511 | There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port… | CRITICAL 9.8EPSS 14.6% | 1 May 2024 |
| CVE-2024-26305 | There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). | CRITICAL 9.8EPSS 15.2% | 1 May 2024 |
| CVE-2024-26304 | There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port… | CRITICAL 9.8EPSS 44.0% | 1 May 2024 |
| CVE-2024-26331 | Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. | HIGH 7.5EPSS 51.3% | 30 April 2024 |
| CVE-2024-25938 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. | HIGH 8.8EPSS 15.6% | 30 April 2024 |
| CVE-2024-25648 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. | HIGH 8.8EPSS 15.6% | 30 April 2024 |
| CVE-2024-25575 | A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. | HIGH 8.8EPSS 17.7% | 30 April 2024 |
| CVE-2024-31621 | An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. | HIGH 7.6EPSS 59.9% | 29 April 2024 |
| CVE-2024-27322 | Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary… | HIGH 8.8EPSS 23.6% | 29 April 2024 |
| CVE-2024-2756 | Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP… | MEDIUM 6.5EPSS 38.1% | 29 April 2024 |
| CVE-2024-1874 | In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can… | CRITICAL 9.4EPSS 32.6% | 29 April 2024 |
| CVE-2024-4257 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. | MEDIUM 6.5EPSS 12.1% | 27 April 2024 |
| CVE-2024-4236 | A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. | HIGH 8.8EPSS 14.9% | 26 April 2024 |
| CVE-2024-33344 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell. | CRITICAL 9.8EPSS 19.9% | 26 April 2024 |
| CVE-2023-51365 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. | HIGH 7.5EPSS 34.8% | 26 April 2024 |
| CVE-2023-51364 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. | HIGH 7.5EPSS 41.6% | 26 April 2024 |
| CVE-2024-32651 | There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. | CRITICAL 10.0EPSS 83.6% | 26 April 2024 |
| CVE-2024-4024 | Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab. | HIGH 8.8EPSS 14.9% | 25 April 2024 |
| CVE-2024-2829 | A crafted wildcard filter in FileFinder may lead to a denial of service. | HIGH 7.5EPSS 26.0% | 25 April 2024 |
| CVE-2024-2434 | An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read. | HIGH 8.1EPSS 23.2% | 25 April 2024 |
| CVE-2024-20356 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and… | HIGH 8.7EPSS 32.7% | 24 April 2024 |
| CVE-2024-20359 | Cisco ASA and FTD Privilege Escalation Vulnerability | KEVMEDIUM 6.0EPSS 19.4% | 24 April 2024 |
| CVE-2024-20353 | Cisco ASA and FTD Denial of Service Vulnerability | KEVHIGH 8.6EPSS 70.7% | 24 April 2024 |
| CVE-2024-31077 | Forminator prior to 1.29.3 contains a SQL injection vulnerability. | HIGH 7.2EPSS 30.4% | 23 April 2024 |
| CVE-2024-32480 | Versions prior to 24.4.0 are vulnerable to SQL injection. | HIGH 7.2EPSS 20.3% | 22 April 2024 |
| CVE-2024-32479 | Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. | MEDIUM 5.4EPSS 34.1% | 22 April 2024 |
| CVE-2024-32461 | A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. | HIGH 8.8EPSS 19.1% | 22 April 2024 |
| CVE-2024-32394 | An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 allows a remote attacker to execute arbitrary code via a crafted HTTP request. | HIGH 8.8EPSS 12.6% | 22 April 2024 |
| CVE-2024-4040 | CrushFTP VFS Sandbox Escape Vulnerability | KEVCRITICAL 10.0EPSS 99.5% | 22 April 2024 |
| CVE-2024-32238 | H3C ER8300G2-X is vulnerable to Incorrect Access Control. | CRITICAL 9.8EPSS 52.9% | 22 April 2024 |
| CVE-2024-27348 | Apache HugeGraph-Server Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 22 April 2024 |
| CVE-2023-50260 | A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system. | HIGH 8.8EPSS 41.2% | 19 April 2024 |
| CVE-2024-24996 | A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands. | CRITICAL 9.8EPSS 32.2% | 19 April 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.