SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 36 of 348

CVESummaryPriorityPublished
CVE-2024-27098An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation.CRITICAL 9.6EPSS 35.7%18 March 2024
CVE-2024-27096An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database.MEDIUM 6.5EPSS 58.8%18 March 2024
CVE-2024-27937GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.MEDIUM 4.3EPSS 27.1%18 March 2024
CVE-2024-20767Adobe ColdFusion Improper Access Control VulnerabilityKEVHIGH 7.4EPSS 98.5%18 March 2024
CVE-2024-28640Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.HIGH 7.5EPSS 14.2%16 March 2024
CVE-2024-28255Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings.CRITICAL 9.8EPSS 73.3%15 March 2024
CVE-2024-28254The `‎AlertUtil::validateExpression` method evaluates an SpEL expression using `getValue` which by default uses the `StandardEvaluationContext`, allowing the expression to reach and interact with Java classes such as `java.lang.Runtime`, leading to…HIGH 8.8EPSS 45.7%15 March 2024
CVE-2024-28253In order to reach this method, an attacker can send a PUT request to `/api/v1/policies` which gets handled by `PolicyResource.createOrUpdate()`.HIGH 8.8EPSS 12.5%15 March 2024
CVE-2024-1884This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.MEDIUM 6.5EPSS 37.9%14 March 2024
CVE-2024-1883This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server.MEDIUM 6.1EPSS 61.5%14 March 2024
CVE-2024-1222This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges.CRITICAL 9.8EPSS 64.0%14 March 2024
CVE-2024-25228Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.HIGH 8.8EPSS 25.9%14 March 2024
CVE-2024-0801A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.HIGH 7.5EPSS 41.8%13 March 2024
CVE-2024-2194The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping.HIGH 7.2EPSS 67.7%13 March 2024
CVE-2024-24549Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat.HIGH 7.5EPSS 23.1%13 March 2024
CVE-2024-1380The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium).MEDIUM 5.3EPSS 50.2%13 March 2024
CVE-2024-1071The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on…CRITICAL 9.8EPSS 89.4%13 March 2024
CVE-2024-25153A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request.CRITICAL 9.8EPSS 41.7%13 March 2024
CVE-2024-2123The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3…MEDIUM 6.1EPSS 26.7%13 March 2024
CVE-2024-27317However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability.CRITICAL 9.9EPSS 56.9%12 March 2024
CVE-2024-26185Windows Compressed Folder Tampering VulnerabilityMEDIUM 6.5EPSS 30.3%12 March 2024
CVE-2024-26160Windows Cloud Files Mini Filter Driver Information Disclosure VulnerabilityMEDIUM 5.5EPSS 11.4%12 March 2024
CVE-2024-21407Windows Hyper-V Remote Code Execution VulnerabilityHIGH 8.1EPSS 16.3%12 March 2024
CVE-2024-21334Open Management Infrastructure (OMI) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 20.2%12 March 2024
CVE-2023-48788Fortinet FortiClient EMS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 98.4%12 March 2024
CVE-2023-49785Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting.CRITICAL 9.8EPSS 83.2%12 March 2024
CVE-2024-2330A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3.CRITICAL 9.8EPSS 17.6%9 March 2024
CVE-2024-21901A SQL injection vulnerability has been reported to affect myQNAPcloud.MEDIUM 4.7EPSS 18.7%8 March 2024
CVE-2024-21899An improper authentication vulnerability has been reported to affect several QNAP operating system versions.CRITICAL 9.8EPSS 24.4%8 March 2024
CVE-2024-27612Numbas editor before 7.3 mishandles editing of themes and extensions.MEDIUM 6.2EPSS 10.7%8 March 2024
CVE-2024-2044pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code.CRITICAL 9.9EPSS 79.5%7 March 2024
CVE-2023-48725A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78.HIGH 8.8EPSS 19.4%7 March 2024
CVE-2023-47415Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.HIGH 7.5EPSS 13.8%7 March 2024
CVE-2024-2174Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 12.7%6 March 2024
CVE-2024-2173Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.HIGH 8.8EPSS 13.7%6 March 2024
CVE-2024-25111Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug.HIGH 7.5EPSS 65.3%6 March 2024
CVE-2024-28156Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views.MEDIUM 5.4EPSS 80.2%6 March 2024
CVE-2024-20337A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user.HIGH 8.2EPSS 29.9%6 March 2024
CVE-2023-38944An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.CRITICAL 9.8EPSS 15.5%6 March 2024
CVE-2024-2056Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo.CRITICAL 9.8EPSS 16.7%5 March 2024
CVE-2024-27564pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter.MEDIUM 6.5EPSS 40.6%5 March 2024
CVE-2024-27199JetBrains TeamCity Relative Path Traversal VulnerabilityKEVHIGH 7.3EPSS 100.0%4 March 2024
CVE-2024-27198JetBrains TeamCity Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.9%4 March 2024
CVE-2024-20017In wlan service, there is a possible out of bounds write due to improper input validation.CRITICAL 9.8EPSS 46.6%4 March 2024
CVE-2024-27747File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.CRITICAL 9.8EPSS 23.6%1 March 2024
CVE-2024-27746SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.CRITICAL 9.8EPSS 12.9%1 March 2024
CVE-2024-20328A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerability is due to unsafe handling of file names.MEDIUM 5.3EPSS 84.8%1 March 2024
CVE-2024-27497Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.HIGH 8.8EPSS 26.7%1 March 2024
CVE-2024-0692The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability.HIGH 8.8EPSS 92.2%1 March 2024
CVE-2024-25832F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.HIGH 8.8EPSS 12.8%29 February 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.