SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,123 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 35 of 348

CVESummaryPriorityPublished
CVE-2023-45288An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.HIGH 7.5EPSS 92.0%4 April 2024
CVE-2024-30255The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames.HIGH 7.5EPSS 87.8%4 April 2024
CVE-2024-27316HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response.HIGH 7.5EPSS 91.3%4 April 2024
CVE-2024-3116pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API.CRITICAL 9.8EPSS 65.1%4 April 2024
CVE-2024-28182This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream.MEDIUM 5.3EPSS 85.0%4 April 2024
CVE-2024-27919In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames.HIGH 7.5EPSS 86.7%4 April 2024
CVE-2024-3274** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic.MEDIUM 5.3EPSS 33.5%4 April 2024
CVE-2024-3273D-Link Multiple NAS Devices Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%4 April 2024
CVE-2024-3272D-Link Multiple NAS Devices Use of Hard-Coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 98.0%4 April 2024
CVE-2024-2758Tempesta FW rate limits are not enabled by default.MEDIUM 6.3EPSS 72.8%3 April 2024
CVE-2024-2653amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.HIGH 8.2EPSS 83.4%3 April 2024
CVE-2024-30571An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.HIGH 7.5EPSS 13.8%3 April 2024
CVE-2024-30568Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.CRITICAL 9.8EPSS 46.9%3 April 2024
CVE-2024-2879The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.HIGH 7.5EPSS 18.4%3 April 2024
CVE-2024-24724Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.CRITICAL 9.8EPSS 26.1%3 April 2024
CVE-2024-2389In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.CRITICAL 9.8EPSS 93.0%2 April 2024
CVE-2024-29276An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.CRITICAL 9.8EPSS 32.8%2 April 2024
CVE-2024-23118Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability.HIGH 7.2EPSS 53.4%1 April 2024
CVE-2024-23117Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability.HIGH 7.2EPSS 53.4%1 April 2024
CVE-2024-23116Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability.HIGH 7.2EPSS 53.4%1 April 2024
CVE-2024-23115Centreon updateGroups SQL Injection Remote Code Execution Vulnerability.HIGH 7.2EPSS 67.5%1 April 2024
CVE-2024-0637Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability.HIGH 8.8EPSS 72.3%1 April 2024
CVE-2023-51573Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability.CRITICAL 9.8EPSS 45.7%1 April 2024
CVE-2023-51572Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 38.4%1 April 2024
CVE-2023-41724A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.HIGH 8.8EPSS 12.8%31 March 2024
CVE-2024-3094Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.CRITICAL 10.0EPSS 86.0%29 March 2024
CVE-2023-49231An authentication bypass vulnerability was found in Stilog Visual Planning 8.CRITICAL 9.8EPSS 42.9%29 March 2024
CVE-2024-30491Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.HIGH 8.8EPSS 32.0%29 March 2024
CVE-2024-31138In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settingsMEDIUM 5.4EPSS 74.5%28 March 2024
CVE-2024-3013Executing manipulation can lead to improper authorization.LOW 2.1EPSS 23.0%28 March 2024
CVE-2024-2398When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push.HIGH 8.6EPSS 36.1%27 March 2024
CVE-2023-40289A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices.HIGH 7.2EPSS 17.8%27 March 2024
CVE-2024-25735Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.CRITICAL 9.1EPSS 50.6%27 March 2024
CVE-2024-2887Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page.HIGH 7.7EPSS 17.9%26 March 2024
CVE-2024-2863This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.CRITICAL 9.8EPSS 64.0%25 March 2024
CVE-2024-2862This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.CRITICAL 9.8EPSS 51.0%25 March 2024
CVE-2024-24725Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.HIGH 8.8EPSS 51.3%23 March 2024
CVE-2024-29059Microsoft .NET Framework Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 98.6%23 March 2024
CVE-2024-2449A cross-site request forgery vulnerability has been identified in LoadMaster.HIGH 7.5EPSS 12.9%22 March 2024
CVE-2024-2448An OS command injection vulnerability has been identified in LoadMaster.HIGH 8.8EPSS 55.4%22 March 2024
CVE-2024-29943An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.CRITICAL 9.8EPSS 22.9%22 March 2024
CVE-2024-27921A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc.HIGH 8.8EPSS 60.6%21 March 2024
CVE-2024-27956Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.CRITICAL 9.8EPSS 94.0%21 March 2024
CVE-2024-1538The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4.HIGH 8.8EPSS 10.7%21 March 2024
CVE-2024-2054The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.CRITICAL 9.8EPSS 81.3%21 March 2024
CVE-2024-2053The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.HIGH 7.5EPSS 44.6%21 March 2024
CVE-2024-27292The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation.HIGH 7.5EPSS 69.5%21 March 2024
CVE-2024-2625Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.HIGH 8.8EPSS 21.4%20 March 2024
CVE-2024-1800In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.HIGH 8.8EPSS 40.4%20 March 2024
CVE-2024-23333LAM's log configuration allows to specify arbitrary paths for log files.MEDIUM 6.6EPSS 17.9%18 March 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.