Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 21 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-20837 | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type… | EXPLOIT ✓CRITICAL 9.8EPSS 88.1% | 26 October 2021 |
| CVE-2021-42840 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. | EXPLOIT ✓HIGH 8.8EPSS 58.9% | 22 October 2021 |
| CVE-2021-31682 | The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. | EXPLOITMEDIUM 6.1EPSS 10.5% | 22 October 2021 |
| CVE-2021-35323 | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. | EXPLOITMEDIUM 6.1EPSS 5.62% | 19 October 2021 |
| CVE-2021-42566 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. | EXPLOITMEDIUM 6.1EPSS 5.83% | 18 October 2021 |
| CVE-2021-42565 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. | EXPLOITMEDIUM 6.1EPSS 5.83% | 18 October 2021 |
| CVE-2018-16061 | SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. | EXPLOITMEDIUM 6.1EPSS 4.03% | 15 October 2021 |
| CVE-2018-16060 | SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI. | EXPLOITHIGH 7.5EPSS 19.6% | 15 October 2021 |
| CVE-2021-20031 | A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains. | EXPLOITMEDIUM 6.1EPSS 13.0% | 12 October 2021 |
| CVE-2021-42325 | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | EXPLOITCRITICAL 9.8EPSS 11.8% | 12 October 2021 |
| CVE-2021-40617 | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. | EXPLOITCRITICAL 9.8EPSS 5.21% | 11 October 2021 |
| CVE-2021-24719 | The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). | EXPLOITMEDIUM 6.1EPSS 2.96% | 11 October 2021 |
| CVE-2021-24563 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone… | EXPLOITMEDIUM 6.1EPSS 26.4% | 11 October 2021 |
| CVE-2021-42071 | In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header. | EXPLOITCRITICAL 9.8EPSS 69.9% | 7 October 2021 |
| CVE-2021-42013 | Apache HTTP Server Path Traversal Vulnerability | KEVEXPLOIT ×3 ✓CRITICAL 9.8EPSS 100.0% | 7 October 2021 |
| CVE-2021-32172 | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | EXPLOITCRITICAL 9.8EPSS 66.4% | 7 October 2021 |
| CVE-2021-42053 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | EXPLOITMEDIUM 5.4EPSS 2.52% | 7 October 2021 |
| CVE-2021-41773 | Apache HTTP Server Path Traversal Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 100.0% | 5 October 2021 |
| CVE-2021-41878 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable… | EXPLOITMEDIUM 6.1EPSS 9.91% | 4 October 2021 |
| CVE-2021-22557 | SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. | EXPLOIT ✓HIGH 7.8EPSS 1.58% | 4 October 2021 |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file. | EXPLOITMEDIUM 6.5EPSS 17.9% | 29 September 2021 |
| CVE-2021-41318 | In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser. | EXPLOITMEDIUM 6.1EPSS 5.88% | 28 September 2021 |
| CVE-2021-20034 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. | EXPLOITCRITICAL 9.1EPSS 81.0% | 27 September 2021 |
| CVE-2021-24610 | The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues. | EXPLOITMEDIUM 4.8EPSS 5.43% | 27 September 2021 |
| CVE-2021-41381 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. | EXPLOITHIGH 7.5EPSS 52.9% | 23 September 2021 |
| CVE-2021-40875 | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. | EXPLOITHIGH 7.5EPSS 48.4% | 22 September 2021 |
| CVE-2021-36260 | Hikvision Improper Input Validation | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 22 September 2021 |
| CVE-2021-41382 | Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface. | EXPLOITHIGH 7.5EPSS 8.94% | 22 September 2021 |
| CVE-2021-40868 | In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. | EXPLOITMEDIUM 6.1EPSS 9.07% | 21 September 2021 |
| CVE-2021-39327 | The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of… | EXPLOITMEDIUM 5.3EPSS 71.7% | 17 September 2021 |
| CVE-2021-40964 | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings… | EXPLOITMEDIUM 6.5EPSS 8.24% | 15 September 2021 |
| CVE-2021-24040 | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. | EXPLOITCRITICAL 9.8EPSS 17.4% | 10 September 2021 |
| CVE-2021-40382 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access. | EXPLOITHIGH 7.5EPSS 22.7% | 1 September 2021 |
| CVE-2021-40381 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access. | EXPLOITHIGH 7.5EPSS 22.7% | 1 September 2021 |
| CVE-2021-40380 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials. | EXPLOITHIGH 7.5EPSS 22.7% | 1 September 2021 |
| CVE-2021-40379 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization. | EXPLOITHIGH 7.5EPSS 21.6% | 1 September 2021 |
| CVE-2021-40378 | An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device. | EXPLOITHIGH 8.1EPSS 15.0% | 1 September 2021 |
| CVE-2021-40352 | OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. | EXPLOITMEDIUM 6.5EPSS 9.71% | 1 September 2021 |
| CVE-2021-39316 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter. | EXPLOITHIGH 7.5EPSS 65.8% | 31 August 2021 |
| CVE-2021-36356 | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). | EXPLOITCRITICAL 9.8EPSS 54.4% | 31 August 2021 |
| CVE-2021-34646 | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link… | EXPLOITCRITICAL 9.8EPSS 50.9% | 30 August 2021 |
| CVE-2021-24581 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. | EXPLOITHIGH 8.8EPSS 4.09% | 30 August 2021 |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 30 August 2021 |
| CVE-2021-39608 | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code. | EXPLOITHIGH 7.2EPSS 45.9% | 23 August 2021 |
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | KEVEXPLOITMEDIUM 5.3EPSS 100.0% | 16 August 2021 |
| CVE-2021-37425 | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key. | EXPLOITCRITICAL 9.1EPSS 66.3% | 10 August 2021 |
| CVE-2021-37391 | A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side… | EXPLOITMEDIUM 5.4EPSS 2.14% | 10 August 2021 |
| CVE-2021-24499 | The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. | EXPLOITCRITICAL 9.8EPSS 60.1% | 9 August 2021 |
| CVE-2021-35312 | A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. | EXPLOITHIGH 7.8EPSS 1.13% | 6 August 2021 |
| CVE-2021-36654 | CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme. | EXPLOITMEDIUM 5.4EPSS 1.94% | 3 August 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.