SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 37 of 348

CVESummaryPriorityPublished
CVE-2024-25830F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.CRITICAL 9.8EPSS 24.0%29 February 2024
CVE-2024-25065Possible path traversal in Apache OFBiz allowing authentication bypass.CRITICAL 9.1EPSS 47.7%29 February 2024
CVE-2024-21726Inadequate content filtering leads to XSS vulnerabilities in various components.MEDIUM 6.5EPSS 48.8%29 February 2024
CVE-2024-21725Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.MEDIUM 6.1EPSS 32.2%29 February 2024
CVE-2024-25126Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial).HIGH 7.5EPSS 35.4%29 February 2024
CVE-2024-25869An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.HIGH 8.8EPSS 18.7%28 February 2024
CVE-2024-25723ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new…HIGH 8.8EPSS 70.8%27 February 2024
CVE-2024-1698The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient…CRITICAL 9.8EPSS 77.6%27 February 2024
CVE-2024-27356Attackers can download files such as logs via commands, potentially obtaining critical user information.HIGH 7.5EPSS 23.9%27 February 2024
CVE-2024-24401SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.CRITICAL 9.8EPSS 45.9%26 February 2024
CVE-2024-26594In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.HIGH 7.1EPSS 51.0%23 February 2024
CVE-2024-1781A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719.CRITICAL 9.8EPSS 14.8%23 February 2024
CVE-2024-25850Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameterCRITICAL 9.8EPSS 19.1%22 February 2024
CVE-2024-1451A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."HIGH 8.7EPSS 51.5%22 February 2024
CVE-2024-1212Progress Kemp LoadMaster OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 95.4%21 February 2024
CVE-2024-1709ConnectWise ScreenConnect Authentication Bypass VulnerabilityKEVCRITICAL 10.0EPSS 100.0%21 February 2024
CVE-2024-1708ConnectWise ScreenConnect Path Traversal VulnerabilityKEVHIGH 8.4EPSS 95.5%21 February 2024
CVE-2023-52442In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header in a…MEDIUM 5.5EPSS 29.6%21 February 2024
CVE-2023-52440In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange…HIGH 7.8EPSS 21.9%21 February 2024
CVE-2024-1676Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page.MEDIUM 5.4EPSS 18.8%21 February 2024
CVE-2024-1675Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.HIGH 8.8EPSS 10.6%21 February 2024
CVE-2024-1651Torrentpier version 2.4.1 allows executing arbitrary commands on the server.CRITICAL 9.8EPSS 34.2%20 February 2024
CVE-2024-1512The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due…CRITICAL 9.8EPSS 77.6%17 February 2024
CVE-2024-20931Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).HIGH 7.5EPSS 59.4%17 February 2024
CVE-2024-25415A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.HIGH 7.2EPSS 27.2%16 February 2024
CVE-2024-23478SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability.HIGH 8.0EPSS 81.6%15 February 2024
CVE-2024-23113Fortinet Multiple Products Format String VulnerabilityKEVCRITICAL 9.8EPSS 61.7%15 February 2024
CVE-2024-25617Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing.HIGH 7.5EPSS 88.1%14 February 2024
CVE-2023-50868The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka…HIGH 7.5EPSS 81.7%14 February 2024
CVE-2023-50387Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.HIGH 7.5EPSS 100.0%14 February 2024
CVE-2024-25125Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally.MEDIUM 5.3EPSS 29.6%14 February 2024
CVE-2024-21413Microsoft Outlook Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 94.7%13 February 2024
CVE-2024-21412Microsoft Windows Internet Shortcut Files Security Feature Bypass VulnerabilityKEVHIGH 8.1EPSS 95.4%13 February 2024
CVE-2024-21410Microsoft Exchange Server Privilege Escalation VulnerabilityKEVCRITICAL 9.8EPSS 12.6%13 February 2024
CVE-2024-21378Microsoft Outlook Remote Code Execution VulnerabilityHIGH 8.8EPSS 11.0%13 February 2024
CVE-2024-21371Windows Kernel Elevation of Privilege VulnerabilityHIGH 7.0EPSS 10.9%13 February 2024
CVE-2024-21357Windows Pragmatic General Multicast (PGM) Remote Code Execution VulnerabilityHIGH 8.1EPSS 26.9%13 February 2024
CVE-2024-21351Microsoft Windows SmartScreen Security Feature Bypass VulnerabilityKEVHIGH 7.6EPSS 30.3%13 February 2024
CVE-2024-21345Windows Kernel Elevation of Privilege VulnerabilityHIGH 8.8EPSS 20.4%13 February 2024
CVE-2024-21338Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control VulnerabilityKEVHIGH 7.8EPSS 59.8%13 February 2024
CVE-2024-22024An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.HIGH 8.3EPSS 94.7%13 February 2024
CVE-2023-50358An OS command injection vulnerability has been reported to affect several QNAP operating system versions.MEDIUM 5.8EPSS 13.5%13 February 2024
CVE-2023-47218An OS command injection vulnerability has been reported to affect several QNAP operating system versions.HIGH 8.3EPSS 89.9%13 February 2024
CVE-2024-23759Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.CRITICAL 9.8EPSS 47.5%12 February 2024
CVE-2023-50386Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2,…HIGH 8.8EPSS 83.7%9 February 2024
CVE-2024-21762Fortinet FortiOS Out-of-Bound Write VulnerabilityKEVCRITICAL 9.8EPSS 84.3%9 February 2024
CVE-2024-24496An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.CRITICAL 9.8EPSS 19.5%8 February 2024
CVE-2024-24494Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php…MEDIUM 6.1EPSS 25.9%8 February 2024
CVE-2024-22836An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier.CRITICAL 9.8EPSS 30.0%8 February 2024
CVE-2024-24824Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint.HIGH 8.8EPSS 34.7%7 February 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.