SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 38 of 348

CVESummaryPriorityPublished
CVE-2024-20290A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.HIGH 7.5EPSS 33.6%7 February 2024
CVE-2024-1283Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.CRITICAL 9.8EPSS 18.7%7 February 2024
CVE-2024-22241Aria Operations for Networks contains a cross site scripting vulnerability.MEDIUM 4.8EPSS 37.8%6 February 2024
CVE-2024-24942In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archivesMEDIUM 5.3EPSS 32.0%6 February 2024
CVE-2024-23917In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleCRITICAL 9.8EPSS 53.7%6 February 2024
CVE-2023-46359An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity…CRITICAL 9.8EPSS 87.6%6 February 2024
CVE-2023-6989The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter.CRITICAL 9.8EPSS 56.6%5 February 2024
CVE-2023-6933The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input.HIGH 8.8EPSS 68.0%5 February 2024
CVE-2023-6846The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function.HIGH 8.8EPSS 15.9%5 February 2024
CVE-2024-22567File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.HIGH 8.8EPSS 17.8%5 February 2024
CVE-2024-23108An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.CRITICAL 9.8EPSS 78.4%5 February 2024
CVE-2024-22320IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization.HIGH 8.8EPSS 73.4%2 February 2024
CVE-2024-22319IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API.CRITICAL 9.8EPSS 76.4%2 February 2024
CVE-2024-24747The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.HIGH 8.8EPSS 34.1%31 January 2024
CVE-2024-21626In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving…HIGH 8.6EPSS 18.1%31 January 2024
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 8.2EPSS 100.0%31 January 2024
CVE-2024-21888A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.HIGH 8.8EPSS 86.8%31 January 2024
CVE-2024-1086Linux Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 28.1%31 January 2024
CVE-2024-21388Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityMEDIUM 6.5EPSS 32.0%30 January 2024
CVE-2024-1061The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.CRITICAL 9.8EPSS 11.2%30 January 2024
CVE-2023-5372The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator privileges to execute some…HIGH 7.2EPSS 28.5%30 January 2024
CVE-2024-23334This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present.HIGH 7.5EPSS 76.9%29 January 2024
CVE-2024-1021A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5.CRITICAL 9.8EPSS 34.7%29 January 2024
CVE-2023-6389This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.MEDIUM 6.1EPSS 26.8%29 January 2024
CVE-2024-0986A vulnerability was found in Issabel PBX 4.0.0.CRITICAL 9.8EPSS 58.2%29 January 2024
CVE-2024-0939A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical.CRITICAL 9.8EPSS 43.8%26 January 2024
CVE-2024-0930A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01.CRITICAL 9.8EPSS 15.2%26 January 2024
CVE-2024-0921A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical.CRITICAL 9.8EPSS 37.6%26 January 2024
CVE-2024-0919A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0.HIGH 7.2EPSS 22.5%26 January 2024
CVE-2024-0918A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical.HIGH 7.2EPSS 25.4%26 January 2024
CVE-2024-23625A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages.CRITICAL 9.8EPSS 22.8%26 January 2024
CVE-2024-23624A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices.CRITICAL 9.8EPSS 26.0%26 January 2024
CVE-2024-24399An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.HIGH 7.2EPSS 15.6%25 January 2024
CVE-2023-52251An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.HIGH 8.8EPSS 86.8%25 January 2024
CVE-2023-41474Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.MEDIUM 6.5EPSS 37.6%25 January 2024
CVE-2024-22729NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.CRITICAL 9.8EPSS 70.8%25 January 2024
CVE-2024-23898Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability,…HIGH 8.8EPSS 67.2%24 January 2024
CVE-2024-23897Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%24 January 2024
CVE-2024-22651There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.CRITICAL 9.8EPSS 20.2%24 January 2024
CVE-2024-23638Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses.MEDIUM 6.5EPSS 60.1%24 January 2024
CVE-2023-36177An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.CRITICAL 9.8EPSS 27.5%23 January 2024
CVE-2024-23222Apple Multiple Products WebKit Type Confusion VulnerabilityKEVHIGH 8.8EPSS 10.6%23 January 2024
CVE-2024-0204Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.CRITICAL 9.8EPSS 95.1%22 January 2024
CVE-2024-0778** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930.CRITICAL 9.8EPSS 32.1%22 January 2024
CVE-2024-0769 D-Link DIR-859 Router Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 82.7%21 January 2024
CVE-2024-0717A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1,…MEDIUM 5.3EPSS 18.2%19 January 2024
CVE-2024-21733Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.MEDIUM 5.3EPSS 14.3%19 January 2024
CVE-2023-6184Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site ScriptingHIGH 7.2EPSS 46.6%18 January 2024
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 57.6%17 January 2024
CVE-2023-5914Cross-site scripting (XSS)MEDIUM 6.1EPSS 73.1%17 January 2024

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.