Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 7 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2017-20216 | FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. | CRITICAL 9.3EPSS 12.0% | 8 January 2026 |
| CVE-2017-20215 | FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute shell commands with root privileges. | HIGH 8.7EPSS 15.8% | 8 January 2026 |
| CVE-2025-15472 | This manipulation of the argument DeviceURL causes os command injection. | HIGH 7.3EPSS 22.6% | 7 January 2026 |
| CVE-2025-15471 | A vulnerability was detected in TRENDnet TEW-713RE 1.02. | HIGH 8.9EPSS 13.8% | 7 January 2026 |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 19.6% | 5 January 2026 |
| CVE-2025-15029 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. | CRITICAL 9.8EPSS 12.7% | 5 January 2026 |
| CVE-2025-5965 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra… | HIGH 7.2EPSS 28.6% | 5 January 2026 |
| CVE-2026-21445 | Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. | HIGH 8.8EPSS 33.7% | 2 January 2026 |
| CVE-2025-66398 | Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. | HIGH 8.8EPSS 20.1% | 1 January 2026 |
| CVE-2025-47411 | A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. | HIGH 8.1EPSS 16.2% | 1 January 2026 |
| CVE-2025-68926 | In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no… | CRITICAL 9.8EPSS 31.1% | 30 December 2025 |
| CVE-2025-52691 | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 85.7% | 29 December 2025 |
| CVE-2025-15139 | A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. | LOW 2.1EPSS 13.3% | 28 December 2025 |
| CVE-2025-15137 | A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. | HIGH 7.4EPSS 11.4% | 28 December 2025 |
| CVE-2025-15136 | A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. | HIGH 7.4EPSS 10.7% | 28 December 2025 |
| CVE-2025-54322 | Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. | CRITICAL 9.8EPSS 15.5% | 27 December 2025 |
| CVE-2025-68668 | From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. | CRITICAL 9.9EPSS 13.4% | 26 December 2025 |
| CVE-2019-25246 | Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. | HIGH 7.1EPSS 18.9% | 24 December 2025 |
| CVE-2025-68664 | Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. | HIGH 8.2EPSS 43.4% | 23 December 2025 |
| CVE-2025-15048 | A vulnerability was determined in Tenda WH450 1.0.0.18. | MEDIUM 5.5EPSS 12.5% | 23 December 2025 |
| CVE-2025-68615 | Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. | CRITICAL 9.8EPSS 42.8% | 23 December 2025 |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | KEVHIGH 8.8EPSS 49.4% | 22 December 2025 |
| CVE-2025-68613 | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability | KEVHIGH 8.8EPSS 99.1% | 19 December 2025 |
| CVE-2025-14847 | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | KEVHIGH 8.7EPSS 83.2% | 19 December 2025 |
| CVE-2025-14733 | WatchGuard Firebox Out of Bounds Write Vulnerability | KEVCRITICAL 9.3EPSS 26.5% | 19 December 2025 |
| CVE-2025-63387 | Dify v1.9.1 is vulnerable to Insecure Permissions. | HIGH 7.5EPSS 29.9% | 18 December 2025 |
| CVE-2025-14884 | A vulnerability was detected in D-Link DIR-605 202WWB03. | HIGH 7.3EPSS 11.0% | 18 December 2025 |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 26.8% | 18 December 2025 |
| CVE-2025-43541 | Processing maliciously crafted web content may lead to an unexpected Safari crash. | MEDIUM 4.3EPSS 34.1% | 17 December 2025 |
| CVE-2025-20393 | Cisco Multiple Products Improper Input Validation Vulnerability | KEVCRITICAL 10.0EPSS 29.9% | 17 December 2025 |
| CVE-2025-68154 | In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. | HIGH 8.1EPSS 13.0% | 16 December 2025 |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 90.2% | 16 December 2025 |
| CVE-2025-14707 | Performing manipulation of the argument params results in command injection. | HIGH 8.9EPSS 18.6% | 15 December 2025 |
| CVE-2025-14706 | A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. | HIGH 8.9EPSS 18.6% | 15 December 2025 |
| CVE-2025-14705 | A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. | HIGH 8.9EPSS 16.5% | 15 December 2025 |
| CVE-2025-14704 | A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. | MEDIUM 5.5EPSS 12.5% | 15 December 2025 |
| CVE-2025-14611 | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | KEVHIGH 7.1EPSS 53.3% | 12 December 2025 |
| CVE-2025-14174 | Google Chromium Out of Bounds Memory Access Vulnerability | KEVHIGH 8.8EPSS 22.3% | 12 December 2025 |
| CVE-2025-67779 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. | HIGH 7.5EPSS 20.0% | 12 December 2025 |
| CVE-2025-55184 | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and… | HIGH 7.5EPSS 66.9% | 11 December 2025 |
| CVE-2025-55183 | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and… | MEDIUM 5.3EPSS 64.2% | 11 December 2025 |
| CVE-2025-34392 | Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. | CRITICAL 10.0EPSS 24.7% | 10 December 2025 |
| CVE-2025-8110 | Gogs Path Traversal Vulnerability | KEVHIGH 8.7EPSS 82.5% | 10 December 2025 |
| CVE-2025-13184 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). | CRITICAL 9.8EPSS 11.3% | 10 December 2025 |
| CVE-2025-61808 | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. | CRITICAL 9.1EPSS 10.5% | 10 December 2025 |
| CVE-2025-59719 | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a… | CRITICAL 9.8EPSS 29.2% | 9 December 2025 |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | KEVCRITICAL 9.8EPSS 68.3% | 9 December 2025 |
| CVE-2025-53949 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions,… | HIGH 8.8EPSS 17.2% | 9 December 2025 |
| CVE-2025-53679 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions,… | HIGH 7.2EPSS 12.3% | 9 December 2025 |
| CVE-2025-10573 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. | MEDIUM 6.1EPSS 33.5% | 9 December 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.