Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 22 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-26085 | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | KEVEXPLOITMEDIUM 5.3EPSS 99.9% | 3 August 2021 |
| CVE-2021-24488 | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues | EXPLOITMEDIUM 6.1EPSS 11.2% | 2 August 2021 |
| CVE-2021-24444 | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is… | EXPLOITMEDIUM 4.8EPSS 2.31% | 2 August 2021 |
| CVE-2021-37593 | PEEL Shopping version 9.4.0 allows remote SQL injection. | EXPLOITCRITICAL 9.1EPSS 5.16% | 30 July 2021 |
| CVE-2021-25791 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name,… | EXPLOITMEDIUM 5.4EPSS 2.54% | 23 July 2021 |
| CVE-2021-35464 | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 22 July 2021 |
| CVE-2015-2099 | Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the… | EXPLOITHIGH 8.8EPSS 14.1% | 22 July 2021 |
| CVE-2015-2098 | Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4)… | EXPLOIT ×3 ✓HIGH 8.8EPSS 14.0% | 22 July 2021 |
| CVE-2021-22146 | While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster. | EXPLOITHIGH 7.5EPSS 35.8% | 21 July 2021 |
| CVE-2021-22145 | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. | EXPLOITMEDIUM 6.5EPSS 76.2% | 21 July 2021 |
| CVE-2021-34429 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. | EXPLOITMEDIUM 5.3EPSS 99.3% | 15 July 2021 |
| CVE-2021-35064 | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. | EXPLOITCRITICAL 9.8EPSS 70.8% | 12 July 2021 |
| CVE-2021-34110 | WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges. | EXPLOITHIGH 7.8EPSS 1.16% | 8 July 2021 |
| CVE-2021-33216 | An Undocumented Backdoor exists, allowing shell access via a developer account. | EXPLOITCRITICAL 9.8EPSS 13.8% | 7 July 2021 |
| CVE-2021-34621 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. | EXPLOITCRITICAL 9.8EPSS 68.9% | 7 July 2021 |
| CVE-2021-22555 | Linux Kernel Heap Out-of-Bounds Write Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 78.7% | 7 July 2021 |
| CVE-2021-24405 | The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. | EXPLOITMEDIUM 6.5EPSS 10.7% | 6 July 2021 |
| CVE-2021-35956 | Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System… | EXPLOITMEDIUM 5.4EPSS 3.23% | 30 June 2021 |
| CVE-2021-35448 | Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. | EXPLOIT ✓HIGH 7.8EPSS 1.04% | 24 June 2021 |
| CVE-2020-18662 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | EXPLOITCRITICAL 9.8EPSS 5.38% | 24 June 2021 |
| CVE-2021-28976 | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. | EXPLOITHIGH 7.2EPSS 7.55% | 23 June 2021 |
| CVE-2021-24383 | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | EXPLOITMEDIUM 5.4EPSS 2.47% | 21 June 2021 |
| CVE-2021-31159 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. | EXPLOITMEDIUM 5.3EPSS 17.8% | 16 June 2021 |
| CVE-2019-25046 | The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. | EXPLOITMEDIUM 6.1EPSS 1.77% | 10 June 2021 |
| CVE-2021-33393 | It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. | EXPLOITHIGH 8.8EPSS 58.7% | 9 June 2021 |
| CVE-2021-29995 | A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). | EXPLOITHIGH 8.8EPSS 4.21% | 9 June 2021 |
| CVE-2021-34370 | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. | EXPLOITMEDIUM 6.1EPSS 10.00% | 9 June 2021 |
| CVE-2021-34369 | portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. | EXPLOITMEDIUM 6.5EPSS 8.24% | 9 June 2021 |
| CVE-2021-31950 | Microsoft SharePoint Server Spoofing Vulnerability | EXPLOITHIGH 7.6EPSS 4.56% | 8 June 2021 |
| CVE-2021-26078 | The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a… | EXPLOITMEDIUM 6.1EPSS 4.03% | 7 June 2021 |
| CVE-2021-33904 | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. | EXPLOITMEDIUM 6.1EPSS 9.97% | 7 June 2021 |
| CVE-2021-31251 | An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an… | EXPLOITCRITICAL 9.8EPSS 35.7% | 4 June 2021 |
| CVE-2021-31642 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. | EXPLOITMEDIUM 6.5EPSS 43.7% | 1 June 2021 |
| CVE-2021-23017 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | EXPLOITHIGH 7.7EPSS 53.5% | 1 June 2021 |
| CVE-2021-27828 | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries. | EXPLOITCRITICAL 9.1EPSS 20.3% | 1 June 2021 |
| CVE-2021-22911 | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 95.2% | 27 May 2021 |
| CVE-2021-33570 | Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. | EXPLOITMEDIUM 5.4EPSS 3.56% | 25 May 2021 |
| CVE-2021-33562 | A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref=… | EXPLOITMEDIUM 4.8EPSS 2.92% | 24 May 2021 |
| CVE-2021-33561 | A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. | EXPLOITMEDIUM 4.8EPSS 2.85% | 24 May 2021 |
| CVE-2021-24308 | The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading… | EXPLOITMEDIUM 5.4EPSS 3.25% | 24 May 2021 |
| CVE-2021-24300 | The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 10.6% | 24 May 2021 |
| CVE-2008-3280 | It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). | EXPLOIT ✓MEDIUM 5.9EPSS 3.95% | 21 May 2021 |
| CVE-2021-32305 | WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 87.3% | 18 May 2021 |
| CVE-2021-24299 | The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. | EXPLOITMEDIUM 6.1EPSS 5.50% | 17 May 2021 |
| CVE-2021-32403 | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules. | EXPLOITHIGH 8.8EPSS 2.46% | 17 May 2021 |
| CVE-2021-24287 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 10.4% | 14 May 2021 |
| CVE-2021-24286 | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 13.9% | 14 May 2021 |
| CVE-2021-24247 | As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. | EXPLOITMEDIUM 5.4EPSS 4.68% | 6 May 2021 |
| CVE-2021-24245 | The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected… | EXPLOITMEDIUM 6.1EPSS 5.72% | 6 May 2021 |
| CVE-2021-24276 | The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 16.0% | 5 May 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.