SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,191 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

17,380 results · page 39 of 348

CVESummaryPriorityPublished
CVE-2024-0517Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 21.7%16 January 2024
CVE-2024-0507An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console.HIGH 8.8EPSS 65.8%16 January 2024
CVE-2024-0200An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection.CRITICAL 9.8EPSS 71.7%16 January 2024
CVE-2023-22512This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server.HIGH 7.5EPSS 14.9%16 January 2024
CVE-2024-0235The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blogMEDIUM 5.3EPSS 38.0%16 January 2024
CVE-2022-1609The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.CRITICAL 9.8EPSS 64.1%16 January 2024
CVE-2024-0582A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it.HIGH 7.8EPSS 12.8%16 January 2024
CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%16 January 2024
CVE-2023-6623The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.CRITICAL 9.8EPSS 50.7%15 January 2024
CVE-2023-6620The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.HIGH 7.2EPSS 14.1%15 January 2024
CVE-2023-50290Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.MEDIUM 6.5EPSS 68.4%15 January 2024
CVE-2024-21887Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityKEVCRITICAL 9.1EPSS 100.0%12 January 2024
CVE-2023-46805Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityKEVHIGH 8.2EPSS 100.0%12 January 2024
CVE-2023-7028GitLab Community and Enterprise Editions Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 94.6%12 January 2024
CVE-2023-50919There is an NGINX authentication bypass via Lua string pattern matching.CRITICAL 9.8EPSS 47.8%12 January 2024
CVE-2024-21591An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the…CRITICAL 9.8EPSS 17.7%12 January 2024
CVE-2023-46474File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.HIGH 7.2EPSS 21.2%11 January 2024
CVE-2023-6875The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in…CRITICAL 9.8EPSS 90.3%11 January 2024
CVE-2023-6567The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…HIGH 7.5EPSS 51.4%11 January 2024
CVE-2023-4372The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes.MEDIUM 5.4EPSS 16.8%11 January 2024
CVE-2023-51123An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.CRITICAL 9.8EPSS 24.4%10 January 2024
CVE-2023-51126Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter.CRITICAL 9.8EPSS 31.1%10 January 2024
CVE-2023-48783An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least…MEDIUM 5.4EPSS 22.2%10 January 2024
CVE-2023-31446In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized.CRITICAL 9.8EPSS 61.1%10 January 2024
CVE-2024-0352A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311.CRITICAL 9.8EPSS 72.9%9 January 2024
CVE-2024-21320Windows Themes Spoofing VulnerabilityMEDIUM 6.5EPSS 22.8%9 January 2024
CVE-2024-21318Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 30.8%9 January 2024
CVE-2024-21310Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHIGH 7.8EPSS 11.5%9 January 2024
CVE-2024-20697Windows libarchive Remote Code Execution VulnerabilityHIGH 7.3EPSS 72.2%9 January 2024
CVE-2024-20674Windows Kerberos Security Feature Bypass VulnerabilityHIGH 8.8EPSS 17.2%9 January 2024
CVE-2023-49237Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.CRITICAL 9.8EPSS 18.6%9 January 2024
CVE-2022-45354Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.HIGH 7.5EPSS 38.1%8 January 2024
CVE-2023-6505The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.HIGH 7.5EPSS 39.9%8 January 2024
CVE-2022-2586Linux Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 10.5%8 January 2024
CVE-2024-21650XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature.CRITICAL 9.8EPSS 93.5%8 January 2024
CVE-2023-47211A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258.HIGH 8.6EPSS 47.0%8 January 2024
CVE-2024-21645A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by `pyload`.MEDIUM 5.3EPSS 24.7%8 January 2024
CVE-2024-21644Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable.HIGH 7.5EPSS 42.4%8 January 2024
CVE-2024-0305A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic.HIGH 7.5EPSS 66.9%8 January 2024
CVE-2024-0265A vulnerability was found in SourceCodester Clinic Queuing System 1.0.HIGH 8.8EPSS 20.9%7 January 2024
CVE-2024-0264A vulnerability was found in SourceCodester Clinic Queuing System 1.0.CRITICAL 9.8EPSS 18.2%7 January 2024
CVE-2024-0223Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 10.2%4 January 2024
CVE-2023-49442Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.CRITICAL 9.8EPSS 38.5%3 January 2024
CVE-2024-21907Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability.HIGH 7.5EPSS 32.9%3 January 2024
CVE-2024-0195A vulnerability, which was classified as critical, was found in spider-flow 0.4.3.CRITICAL 9.8EPSS 19.4%2 January 2024
CVE-2023-50094reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID.HIGH 8.8EPSS 13.5%1 January 2024
CVE-2023-50071Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.HIGH 8.8EPSS 13.8%29 December 2023
CVE-2023-52085This had the potential to lead to a Local File Inclusion vulnerability.MEDIUM 5.4EPSS 30.2%29 December 2023
CVE-2023-7137A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0.HIGH 8.8EPSS 17.0%28 December 2023
CVE-2023-6114The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files…HIGH 7.5EPSS 30.9%26 December 2023

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.