Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 8 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-13065 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. | HIGH 8.8EPSS 13.5% | 6 December 2025 |
| CVE-2025-34291 | Langflow Origin Validation Error Vulnerability | KEVCRITICAL 9.4EPSS 83.6% | 5 December 2025 |
| CVE-2025-14108 | A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. | HIGH 7.4EPSS 10.5% | 5 December 2025 |
| CVE-2025-14107 | Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. | HIGH 7.4EPSS 12.2% | 5 December 2025 |
| CVE-2025-14106 | A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. | HIGH 7.4EPSS 12.1% | 5 December 2025 |
| CVE-2025-14094 | This manipulation of the argument sysCmd causes os command injection. | LOW 2.0EPSS 20.3% | 5 December 2025 |
| CVE-2025-14093 | A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. | LOW 2.0EPSS 19.6% | 5 December 2025 |
| CVE-2025-14092 | A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. | LOW 2.0EPSS 16.9% | 5 December 2025 |
| CVE-2025-66516 | Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. | CRITICAL 9.8EPSS 87.7% | 4 December 2025 |
| CVE-2024-32641 | Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. | CRITICAL 9.8EPSS 12.3% | 3 December 2025 |
| CVE-2025-57201 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. | HIGH 8.8EPSS 17.2% | 3 December 2025 |
| CVE-2025-55182 | Meta React Server Components Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 3 December 2025 |
| CVE-2025-13486 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. | CRITICAL 9.8EPSS 67.6% | 3 December 2025 |
| CVE-2025-66399 | In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. | HIGH 7.4EPSS 10.8% | 2 December 2025 |
| CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | KEVCRITICAL 9.4EPSS 16.9% | 26 November 2025 |
| CVE-2025-58360 | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability | KEVCRITICAL 9.8EPSS 64.9% | 25 November 2025 |
| CVE-2025-59366 | An authentication-bypass vulnerability exists in AiCloud. | CRITICAL 9.2EPSS 15.8% | 25 November 2025 |
| CVE-2025-6389 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. | CRITICAL 9.8EPSS 76.1% | 25 November 2025 |
| CVE-2025-41115 | In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override… | CRITICAL 9.8EPSS 18.8% | 21 November 2025 |
| CVE-2025-13442 | A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. | MEDIUM 5.5EPSS 19.5% | 20 November 2025 |
| CVE-2025-11001 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. | HIGH 7.8EPSS 27.0% | 19 November 2025 |
| CVE-2025-13315 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. | CRITICAL 9.3EPSS 32.5% | 19 November 2025 |
| CVE-2025-64408 | Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. | MEDIUM 6.3EPSS 10.8% | 19 November 2025 |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 55.6% | 18 November 2025 |
| CVE-2025-9501 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post. | CRITICAL 9.0EPSS 20.5% | 17 November 2025 |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 91.8% | 14 November 2025 |
| CVE-2025-60689 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). | MEDIUM 5.4EPSS 17.5% | 13 November 2025 |
| CVE-2025-12762 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. | CRITICAL 9.8EPSS 12.3% | 13 November 2025 |
| CVE-2025-9316 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. | MEDIUM 6.9EPSS 36.3% | 12 November 2025 |
| CVE-2025-11700 | N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure | HIGH 8.4EPSS 30.7% | 12 November 2025 |
| CVE-2025-12101 | Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | MEDIUM 5.9EPSS 25.4% | 11 November 2025 |
| CVE-2025-12480 | Gladinet Triofox Improper Access Control Vulnerability | KEVCRITICAL 9.1EPSS 90.5% | 10 November 2025 |
| CVE-2025-10230 | Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as… | CRITICAL 10.0EPSS 39.7% | 7 November 2025 |
| CVE-2025-34299 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. | CRITICAL 9.3EPSS 72.9% | 7 November 2025 |
| CVE-2025-64328 | Sangoma FreePBX OS Command Injection Vulnerability | KEVHIGH 8.6EPSS 84.6% | 7 November 2025 |
| CVE-2025-12490 | Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. | HIGH 8.8EPSS 20.1% | 6 November 2025 |
| CVE-2025-64459 | The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. | CRITICAL 9.1EPSS 19.4% | 5 November 2025 |
| CVE-2025-11749 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. | CRITICAL 9.8EPSS 74.8% | 5 November 2025 |
| CVE-2025-12197 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | HIGH 7.5EPSS 17.1% | 5 November 2025 |
| CVE-2025-11953 | React Native Community CLI OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.0% | 3 November 2025 |
| CVE-2025-11833 | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. | CRITICAL 9.8EPSS 51.0% | 1 November 2025 |
| CVE-2025-52665 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. | CRITICAL 10.0EPSS 41.0% | 31 October 2025 |
| CVE-2025-11201 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 27.0% | 29 October 2025 |
| CVE-2025-64095 | Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. | CRITICAL 9.8EPSS 44.7% | 28 October 2025 |
| CVE-2025-34311 | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report. | HIGH 8.7EPSS 13.8% | 28 October 2025 |
| CVE-2025-62725 | Docker Compose trusts the path information embedded in remote OCI compose artifacts. | HIGH 8.9EPSS 13.7% | 27 October 2025 |
| CVE-2025-55754 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. | CRITICAL 9.6EPSS 10.1% | 27 October 2025 |
| CVE-2025-55752 | Relative Path Traversal vulnerability in Apache Tomcat. | HIGH 7.5EPSS 66.5% | 27 October 2025 |
| CVE-2025-27225 | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. | HIGH 7.5EPSS 17.2% | 27 October 2025 |
| CVE-2025-6440 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all… | CRITICAL 9.8EPSS 31.4% | 24 October 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.