SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 34 of 348

CVESummaryPriorityPublished
CVE-2024-24994A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.HIGH 8.8EPSS 68.1%19 April 2024
CVE-2024-24992A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.HIGH 8.8EPSS 70.9%19 April 2024
CVE-2024-23535A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.HIGH 8.8EPSS 68.1%19 April 2024
CVE-2024-31750SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.CRITICAL 9.8EPSS 19.3%19 April 2024
CVE-2024-29021Judge0 is an open-source online code execution system.CRITICAL 9.0EPSS 20.2%18 April 2024
CVE-2024-2961The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a…HIGH 7.3EPSS 88.3%17 April 2024
CVE-2023-39367An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU).HIGH 7.2EPSS 37.7%17 April 2024
CVE-2024-3833Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.HIGH 8.8EPSS 17.6%17 April 2024
CVE-2023-40000Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.MEDIUM 6.1EPSS 54.9%16 April 2024
CVE-2024-2083A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint.CRITICAL 9.9EPSS 37.5%16 April 2024
CVE-2024-1601An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message data.CRITICAL 9.8EPSS 40.4%16 April 2024
CVE-2024-3721A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical.MEDIUM 6.3EPSS 86.5%13 April 2024
CVE-2023-51409Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.CRITICAL 9.8EPSS 63.1%12 April 2024
CVE-2024-3054WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action.HIGH 7.2EPSS 41.5%12 April 2024
CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityKEVCRITICAL 10.0EPSS 100.0%12 April 2024
CVE-2024-25852Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point.HIGH 8.8EPSS 16.5%11 April 2024
CVE-2024-0881The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX…MEDIUM 5.4EPSS 16.9%11 April 2024
CVE-2024-31997Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights.HIGH 8.8EPSS 73.9%10 April 2024
CVE-2024-31984Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) search in XWiki.HIGH 8.8EPSS 83.0%10 April 2024
CVE-2024-31982Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text.CRITICAL 9.8EPSS 34.3%10 April 2024
CVE-2024-31819An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.CRITICAL 9.8EPSS 15.6%10 April 2024
CVE-2024-31465Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSourceClass` to their user profile or any other…HIGH 8.8EPSS 75.6%10 April 2024
CVE-2024-31214Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API.CRITICAL 9.6EPSS 17.6%10 April 2024
CVE-2024-1728gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component.HIGH 7.5EPSS 85.4%10 April 2024
CVE-2024-1600A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route.CRITICAL 9.3EPSS 32.5%10 April 2024
CVE-2024-1520An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter.CRITICAL 9.8EPSS 48.2%10 April 2024
CVE-2024-24809Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type.HIGH 8.5EPSS 54.4%10 April 2024
CVE-2024-31309HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.HIGH 7.5EPSS 94.6%10 April 2024
CVE-2024-3097The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59.MEDIUM 5.3EPSS 38.0%9 April 2024
CVE-2024-2340The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory.MEDIUM 5.3EPSS 28.0%9 April 2024
CVE-2024-24576An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping.CRITICAL 10.0EPSS 20.3%9 April 2024
CVE-2024-29990Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityCRITICAL 9.0EPSS 18.0%9 April 2024
CVE-2024-29988Microsoft SmartScreen Prompt Security Feature Bypass VulnerabilityKEVHIGH 8.8EPSS 44.9%9 April 2024
CVE-2024-26256Libarchive Remote Code Execution VulnerabilityHIGH 7.8EPSS 84.8%9 April 2024
CVE-2024-26230Windows Telephony Server Elevation of Privilege VulnerabilityHIGH 7.8EPSS 24.1%9 April 2024
CVE-2024-26218Windows Kernel Elevation of Privilege VulnerabilityHIGH 7.8EPSS 12.9%9 April 2024
CVE-2024-26212DHCP Server Service Denial of Service VulnerabilityHIGH 7.5EPSS 62.6%9 April 2024
CVE-2024-26209Microsoft Local Security Authority Subsystem Service Information Disclosure VulnerabilityMEDIUM 5.5EPSS 14.8%9 April 2024
CVE-2024-26158Microsoft Install Service Elevation of Privilege VulnerabilityHIGH 7.8EPSS 12.3%9 April 2024
CVE-2023-49074A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926.HIGH 7.5EPSS 13.5%9 April 2024
CVE-2024-27983An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside.HIGH 8.2EPSS 87.2%9 April 2024
CVE-2024-30269DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0.MEDIUM 5.3EPSS 15.9%8 April 2024
CVE-2024-2511Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a…MEDIUM 5.9EPSS 54.0%8 April 2024
CVE-2024-31817In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.HIGH 7.5EPSS 55.3%8 April 2024
CVE-2024-28741Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.HIGH 8.8EPSS 78.2%6 April 2024
CVE-2024-3156Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.HIGH 8.8EPSS 12.9%6 April 2024
CVE-2024-3378A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic.MEDIUM 6.1EPSS 22.0%6 April 2024
CVE-2024-3346A vulnerability was found in Byzoro Smart S80 up to 20240328.MEDIUM 6.3EPSS 49.3%5 April 2024
CVE-2024-21894A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack.CRITICAL 9.8EPSS 19.0%4 April 2024
CVE-2024-30270A security vulnerability has been identified in mailcow affecting versions prior to 2024-04.MEDIUM 6.2EPSS 27.3%4 April 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.