SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 9 of 348

CVESummaryPriorityPublished
CVE-2025-6978Diagnostics command injection vulnerabilityHIGH 7.2EPSS 13.8%23 October 2025
CVE-2025-8677Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.HIGH 7.5EPSS 11.2%22 October 2025
CVE-2024-58274Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.HIGH 8.3EPSS 17.9%22 October 2025
CVE-2025-61757Oracle Fusion Middleware Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 88.3%21 October 2025
CVE-2025-60344A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”).HIGH 8.6EPSS 10.2%21 October 2025
CVE-2025-9428Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.HIGH 8.8EPSS 25.7%21 October 2025
CVE-2025-57738Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter…HIGH 7.2EPSS 23.1%20 October 2025
CVE-2025-62168In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure.HIGH 7.5EPSS 62.9%17 October 2025
CVE-2025-62411LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality.MEDIUM 4.8EPSS 11.9%16 October 2025
CVE-2025-61678In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter.HIGH 8.6EPSS 43.7%14 October 2025
CVE-2025-61675In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom…HIGH 8.6EPSS 38.5%14 October 2025
CVE-2025-59287Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 100.0%14 October 2025
CVE-2025-55315Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.CRITICAL 9.9EPSS 65.9%14 October 2025
CVE-2025-5946Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection.HIGH 7.2EPSS 13.5%14 October 2025
CVE-2025-10985OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 20.4%14 October 2025
CVE-2025-10243OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 20.4%14 October 2025
CVE-2025-10242OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.HIGH 7.2EPSS 20.4%14 October 2025
CVE-2025-9713Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution.HIGH 8.8EPSS 15.3%13 October 2025
CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 7.5EPSS 95.9%12 October 2025
CVE-2025-61928In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ??CRITICAL 9.3EPSS 17.9%9 October 2025
CVE-2025-11371Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties VulnerabilityKEVHIGH 7.5EPSS 92.1%9 October 2025
CVE-2025-61913In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading…CRITICAL 9.9EPSS 13.0%8 October 2025
CVE-2025-44823Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call.HIGH 8.8EPSS 16.1%7 October 2025
CVE-2025-61687A file upload vulnerability in version 3.0.7 of FlowiseAI allows authenticated users to upload arbitrary files without proper validation.HIGH 8.8EPSS 11.1%6 October 2025
CVE-2025-11331A vulnerability was found in IdeaCMS up to 1.8.LOW 2.0EPSS 17.5%6 October 2025
CVE-2025-50538Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.MEDIUM 6.1EPSS 14.0%6 October 2025
CVE-2025-61882Oracle E-Business Suite Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 99.7%5 October 2025
CVE-2025-49844Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution.CRITICAL 9.9EPSS 82.3%3 October 2025
CVE-2025-60787MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name.HIGH 7.2EPSS 18.5%3 October 2025
CVE-2025-59536Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation.HIGH 8.7EPSS 26.4%3 October 2025
CVE-2025-61734Files or Directories Accessible to External Parties vulnerability in Apache Kylin.HIGH 7.5EPSS 19.8%2 October 2025
CVE-2025-61622Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution.CRITICAL 9.8EPSS 43.5%1 October 2025
CVE-2025-8868In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command…HIGH 8.8EPSS 24.3%29 September 2025
CVE-2025-9985The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files.MEDIUM 5.3EPSS 11.8%26 September 2025
CVE-2025-34227Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards.HIGH 8.6EPSS 24.3%25 September 2025
CVE-2025-20362Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization VulnerabilityKEVHIGH 8.6EPSS 87.1%25 September 2025
CVE-2025-20333Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow VulnerabilityKEVCRITICAL 9.9EPSS 70.7%25 September 2025
CVE-2025-52906Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.CRITICAL 9.3EPSS 12.8%24 September 2025
CVE-2025-20352Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution VulnerabilityKEVHIGH 7.7EPSS 39.4%24 September 2025
CVE-2025-26399SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 89.5%23 September 2025
CVE-2025-59528In version 3.0.5, Flowise is vulnerable to remote code execution.CRITICAL 10.0EPSS 86.2%22 September 2025
CVE-2025-10775A security vulnerability has been detected in Wavlink WL-NU516U1 240425.LOW 2.0EPSS 20.0%22 September 2025
CVE-2025-48703CWP Control Web Panel OS Command Injection VulnerabilityKEVCRITICAL 9.0EPSS 99.7%19 September 2025
CVE-2025-10035Fortra GoAnywhere MFT Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 99.8%18 September 2025
CVE-2025-59456In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive uploadMEDIUM 5.5EPSS 13.0%17 September 2025
CVE-2025-9242WatchGuard Firebox Out-of-Bounds Write VulnerabilityKEVCRITICAL 9.3EPSS 91.3%17 September 2025
CVE-2025-10441A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1.LOW 2.1EPSS 11.8%15 September 2025
CVE-2025-10440A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1.LOW 2.1EPSS 11.8%15 September 2025
CVE-2025-10327A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.LOW 2.1EPSS 10.2%12 September 2025
CVE-2025-58434This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO).CRITICAL 9.8EPSS 49.9%12 September 2025

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.