Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,006 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 9 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-6978 | Diagnostics command injection vulnerability | HIGH 7.2EPSS 13.8% | 23 October 2025 |
| CVE-2025-8677 | Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. | HIGH 7.5EPSS 11.2% | 22 October 2025 |
| CVE-2024-58274 | Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025. | HIGH 8.3EPSS 17.9% | 22 October 2025 |
| CVE-2025-61757 | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 88.3% | 21 October 2025 |
| CVE-2025-60344 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). | HIGH 8.6EPSS 10.2% | 21 October 2025 |
| CVE-2025-9428 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. | HIGH 8.8EPSS 25.7% | 21 October 2025 |
| CVE-2025-57738 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter… | HIGH 7.2EPSS 23.1% | 20 October 2025 |
| CVE-2025-62168 | In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. | HIGH 7.5EPSS 62.9% | 17 October 2025 |
| CVE-2025-62411 | LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. | MEDIUM 4.8EPSS 11.9% | 16 October 2025 |
| CVE-2025-61678 | In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. | HIGH 8.6EPSS 43.7% | 14 October 2025 |
| CVE-2025-61675 | In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom… | HIGH 8.6EPSS 38.5% | 14 October 2025 |
| CVE-2025-59287 | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 14 October 2025 |
| CVE-2025-55315 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | CRITICAL 9.9EPSS 65.9% | 14 October 2025 |
| CVE-2025-5946 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. | HIGH 7.2EPSS 13.5% | 14 October 2025 |
| CVE-2025-10985 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 20.4% | 14 October 2025 |
| CVE-2025-10243 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 20.4% | 14 October 2025 |
| CVE-2025-10242 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | HIGH 7.2EPSS 20.4% | 14 October 2025 |
| CVE-2025-9713 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. | HIGH 8.8EPSS 15.3% | 13 October 2025 |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 7.5EPSS 95.9% | 12 October 2025 |
| CVE-2025-61928 | In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? | CRITICAL 9.3EPSS 17.9% | 9 October 2025 |
| CVE-2025-11371 | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | KEVHIGH 7.5EPSS 92.1% | 9 October 2025 |
| CVE-2025-61913 | In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file system, potentially leading… | CRITICAL 9.9EPSS 13.0% | 8 October 2025 |
| CVE-2025-44823 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. | HIGH 8.8EPSS 16.1% | 7 October 2025 |
| CVE-2025-61687 | A file upload vulnerability in version 3.0.7 of FlowiseAI allows authenticated users to upload arbitrary files without proper validation. | HIGH 8.8EPSS 11.1% | 6 October 2025 |
| CVE-2025-11331 | A vulnerability was found in IdeaCMS up to 1.8. | LOW 2.0EPSS 17.5% | 6 October 2025 |
| CVE-2025-50538 | Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log. | MEDIUM 6.1EPSS 14.0% | 6 October 2025 |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 5 October 2025 |
| CVE-2025-49844 | Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. | CRITICAL 9.9EPSS 82.3% | 3 October 2025 |
| CVE-2025-60787 | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. | HIGH 7.2EPSS 18.5% | 3 October 2025 |
| CVE-2025-59536 | Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. | HIGH 8.7EPSS 26.4% | 3 October 2025 |
| CVE-2025-61734 | Files or Directories Accessible to External Parties vulnerability in Apache Kylin. | HIGH 7.5EPSS 19.8% | 2 October 2025 |
| CVE-2025-61622 | Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. | CRITICAL 9.8EPSS 43.5% | 1 October 2025 |
| CVE-2025-8868 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command… | HIGH 8.8EPSS 24.3% | 29 September 2025 |
| CVE-2025-9985 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. | MEDIUM 5.3EPSS 11.8% | 26 September 2025 |
| CVE-2025-34227 | Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. | HIGH 8.6EPSS 24.3% | 25 September 2025 |
| CVE-2025-20362 | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | KEVHIGH 8.6EPSS 87.1% | 25 September 2025 |
| CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | KEVCRITICAL 9.9EPSS 70.7% | 25 September 2025 |
| CVE-2025-52906 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | CRITICAL 9.3EPSS 12.8% | 24 September 2025 |
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | KEVHIGH 7.7EPSS 39.4% | 24 September 2025 |
| CVE-2025-26399 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 89.5% | 23 September 2025 |
| CVE-2025-59528 | In version 3.0.5, Flowise is vulnerable to remote code execution. | CRITICAL 10.0EPSS 86.2% | 22 September 2025 |
| CVE-2025-10775 | A security vulnerability has been detected in Wavlink WL-NU516U1 240425. | LOW 2.0EPSS 20.0% | 22 September 2025 |
| CVE-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | KEVCRITICAL 9.0EPSS 99.7% | 19 September 2025 |
| CVE-2025-10035 | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 18 September 2025 |
| CVE-2025-59456 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | MEDIUM 5.5EPSS 13.0% | 17 September 2025 |
| CVE-2025-9242 | WatchGuard Firebox Out-of-Bounds Write Vulnerability | KEVCRITICAL 9.3EPSS 91.3% | 17 September 2025 |
| CVE-2025-10441 | A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. | LOW 2.1EPSS 11.8% | 15 September 2025 |
| CVE-2025-10440 | A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. | LOW 2.1EPSS 11.8% | 15 September 2025 |
| CVE-2025-10327 | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. | LOW 2.1EPSS 10.2% | 12 September 2025 |
| CVE-2025-58434 | This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). | CRITICAL 9.8EPSS 49.9% | 12 September 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.