Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
17,380 results · page 37 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-25830 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. | CRITICAL 9.8EPSS 24.0% | 29 February 2024 |
| CVE-2024-25065 | Possible path traversal in Apache OFBiz allowing authentication bypass. | CRITICAL 9.1EPSS 47.7% | 29 February 2024 |
| CVE-2024-21726 | Inadequate content filtering leads to XSS vulnerabilities in various components. | MEDIUM 6.5EPSS 48.8% | 29 February 2024 |
| CVE-2024-21725 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. | MEDIUM 6.1EPSS 32.2% | 29 February 2024 |
| CVE-2024-25126 | Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). | HIGH 7.5EPSS 35.4% | 29 February 2024 |
| CVE-2024-25869 | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component. | HIGH 8.8EPSS 18.7% | 28 February 2024 |
| CVE-2024-25723 | ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new… | HIGH 8.8EPSS 70.8% | 27 February 2024 |
| CVE-2024-1698 | The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient… | CRITICAL 9.8EPSS 77.6% | 27 February 2024 |
| CVE-2024-27356 | Attackers can download files such as logs via commands, potentially obtaining critical user information. | HIGH 7.5EPSS 23.9% | 27 February 2024 |
| CVE-2024-24401 | SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component. | CRITICAL 9.8EPSS 45.9% | 26 February 2024 |
| CVE-2024-26594 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid. | HIGH 7.1EPSS 51.0% | 23 February 2024 |
| CVE-2024-1781 | A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. | CRITICAL 9.8EPSS 14.8% | 23 February 2024 |
| CVE-2024-25850 | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter | CRITICAL 9.8EPSS 19.1% | 22 February 2024 |
| CVE-2024-1451 | A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims." | HIGH 8.7EPSS 51.5% | 22 February 2024 |
| CVE-2024-1212 | Progress Kemp LoadMaster OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 95.4% | 21 February 2024 |
| CVE-2024-1709 | ConnectWise ScreenConnect Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 21 February 2024 |
| CVE-2024-1708 | ConnectWise ScreenConnect Path Traversal Vulnerability | KEVHIGH 8.4EPSS 95.5% | 21 February 2024 |
| CVE-2023-52442 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header in a… | MEDIUM 5.5EPSS 29.6% | 21 February 2024 |
| CVE-2023-52440 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange… | HIGH 7.8EPSS 21.9% | 21 February 2024 |
| CVE-2024-1676 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. | MEDIUM 5.4EPSS 18.8% | 21 February 2024 |
| CVE-2024-1675 | Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | HIGH 8.8EPSS 10.6% | 21 February 2024 |
| CVE-2024-1651 | Torrentpier version 2.4.1 allows executing arbitrary commands on the server. | CRITICAL 9.8EPSS 34.2% | 20 February 2024 |
| CVE-2024-1512 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due… | CRITICAL 9.8EPSS 77.6% | 17 February 2024 |
| CVE-2024-20931 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | HIGH 7.5EPSS 59.4% | 17 February 2024 |
| CVE-2024-25415 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | HIGH 7.2EPSS 27.2% | 16 February 2024 |
| CVE-2024-23478 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. | HIGH 8.0EPSS 81.6% | 15 February 2024 |
| CVE-2024-23113 | Fortinet Multiple Products Format String Vulnerability | KEVCRITICAL 9.8EPSS 61.7% | 15 February 2024 |
| CVE-2024-25617 | Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. | HIGH 7.5EPSS 88.1% | 14 February 2024 |
| CVE-2023-50868 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka… | HIGH 7.5EPSS 81.7% | 14 February 2024 |
| CVE-2023-50387 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. | HIGH 7.5EPSS 100.0% | 14 February 2024 |
| CVE-2024-25125 | Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. | MEDIUM 5.3EPSS 29.6% | 14 February 2024 |
| CVE-2024-21413 | Microsoft Outlook Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 94.7% | 13 February 2024 |
| CVE-2024-21412 | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | KEVHIGH 8.1EPSS 95.4% | 13 February 2024 |
| CVE-2024-21410 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 12.6% | 13 February 2024 |
| CVE-2024-21378 | Microsoft Outlook Remote Code Execution Vulnerability | HIGH 8.8EPSS 11.0% | 13 February 2024 |
| CVE-2024-21371 | Windows Kernel Elevation of Privilege Vulnerability | HIGH 7.0EPSS 10.9% | 13 February 2024 |
| CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | HIGH 8.1EPSS 26.9% | 13 February 2024 |
| CVE-2024-21351 | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | KEVHIGH 7.6EPSS 30.3% | 13 February 2024 |
| CVE-2024-21345 | Windows Kernel Elevation of Privilege Vulnerability | HIGH 8.8EPSS 20.4% | 13 February 2024 |
| CVE-2024-21338 | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | KEVHIGH 7.8EPSS 59.8% | 13 February 2024 |
| CVE-2024-22024 | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication. | HIGH 8.3EPSS 94.7% | 13 February 2024 |
| CVE-2023-50358 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. | MEDIUM 5.8EPSS 13.5% | 13 February 2024 |
| CVE-2023-47218 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. | HIGH 8.3EPSS 89.9% | 13 February 2024 |
| CVE-2024-23759 | Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function. | CRITICAL 9.8EPSS 47.5% | 12 February 2024 |
| CVE-2023-50386 | Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2,… | HIGH 8.8EPSS 83.7% | 9 February 2024 |
| CVE-2024-21762 | Fortinet FortiOS Out-of-Bound Write Vulnerability | KEVCRITICAL 9.8EPSS 84.3% | 9 February 2024 |
| CVE-2024-24496 | An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components. | CRITICAL 9.8EPSS 19.5% | 8 February 2024 |
| CVE-2024-24494 | Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php… | MEDIUM 6.1EPSS 25.9% | 8 February 2024 |
| CVE-2024-22836 | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. | CRITICAL 9.8EPSS 30.0% | 8 February 2024 |
| CVE-2024-24824 | Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. | HIGH 8.8EPSS 34.7% | 7 February 2024 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.