SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 22 of 501

CVESummaryPriorityPublished
CVE-2021-26085Atlassian Confluence Server Pre-Authorization Arbitrary File Read VulnerabilityKEVEXPLOITMEDIUM 5.3EPSS 99.9%3 August 2021
CVE-2021-24488The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issuesEXPLOITMEDIUM 6.1EPSS 11.2%2 August 2021
CVE-2021-24444The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is…EXPLOITMEDIUM 4.8EPSS 2.31%2 August 2021
CVE-2021-37593PEEL Shopping version 9.4.0 allows remote SQL injection.EXPLOITCRITICAL 9.1EPSS 5.16%30 July 2021
CVE-2021-25791Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name,…EXPLOITMEDIUM 5.4EPSS 2.54%23 July 2021
CVE-2021-35464ForgeRock Access Management (AM) Core Server Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%22 July 2021
CVE-2015-2099Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the…EXPLOITHIGH 8.8EPSS 14.1%22 July 2021
CVE-2015-2098Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4)…EXPLOIT ×3HIGH 8.8EPSS 14.0%22 July 2021
CVE-2021-22146While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.EXPLOITHIGH 7.5EPSS 35.8%21 July 2021
CVE-2021-22145A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.EXPLOITMEDIUM 6.5EPSS 76.2%21 July 2021
CVE-2021-34429For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints.EXPLOITMEDIUM 5.3EPSS 99.3%15 July 2021
CVE-2021-35064KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo.EXPLOITCRITICAL 9.8EPSS 70.8%12 July 2021
CVE-2021-34110WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.EXPLOITHIGH 7.8EPSS 1.16%8 July 2021
CVE-2021-33216An Undocumented Backdoor exists, allowing shell access via a developer account.EXPLOITCRITICAL 9.8EPSS 13.8%7 July 2021
CVE-2021-34621A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator.EXPLOITCRITICAL 9.8EPSS 68.9%7 July 2021
CVE-2021-22555Linux Kernel Heap Out-of-Bounds Write VulnerabilityKEVEXPLOITHIGH 7.8EPSS 78.7%7 July 2021
CVE-2021-24405The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them.EXPLOITMEDIUM 6.5EPSS 10.7%6 July 2021
CVE-2021-35956Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System…EXPLOITMEDIUM 5.4EPSS 3.23%30 June 2021
CVE-2021-35448Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe.EXPLOITHIGH 7.8EPSS 1.04%24 June 2021
CVE-2020-18662SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.EXPLOITCRITICAL 9.8EPSS 5.38%24 June 2021
CVE-2021-28976Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.EXPLOITHIGH 7.2EPSS 7.55%23 June 2021
CVE-2021-24383The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issueEXPLOITMEDIUM 5.4EPSS 2.47%21 June 2021
CVE-2021-31159Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.EXPLOITMEDIUM 5.3EPSS 17.8%16 June 2021
CVE-2019-25046The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.EXPLOITMEDIUM 6.1EPSS 1.77%10 June 2021
CVE-2021-33393It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root.EXPLOITHIGH 8.8EPSS 58.7%9 June 2021
CVE-2021-29995A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution).EXPLOITHIGH 8.8EPSS 4.21%9 June 2021
CVE-2021-34370Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS.EXPLOITMEDIUM 6.1EPSS 10.00%9 June 2021
CVE-2021-34369portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value.EXPLOITMEDIUM 6.5EPSS 8.24%9 June 2021
CVE-2021-31950Microsoft SharePoint Server Spoofing VulnerabilityEXPLOITHIGH 7.6EPSS 4.56%8 June 2021
CVE-2021-26078The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a…EXPLOITMEDIUM 6.1EPSS 4.03%7 June 2021
CVE-2021-33904In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS.EXPLOITMEDIUM 6.1EPSS 9.97%7 June 2021
CVE-2021-31251An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an…EXPLOITCRITICAL 9.8EPSS 35.7%4 June 2021
CVE-2021-31642A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC.EXPLOITMEDIUM 6.5EPSS 43.7%1 June 2021
CVE-2021-23017A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.EXPLOITHIGH 7.7EPSS 53.5%1 June 2021
CVE-2021-27828SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.EXPLOITCRITICAL 9.1EPSS 20.3%1 June 2021
CVE-2021-22911A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.EXPLOIT ×2CRITICAL 9.8EPSS 95.2%27 May 2021
CVE-2021-33570Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table.EXPLOITMEDIUM 5.4EPSS 3.56%25 May 2021
CVE-2021-33562A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref=…EXPLOITMEDIUM 4.8EPSS 2.92%24 May 2021
CVE-2021-33561A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration.EXPLOITMEDIUM 4.8EPSS 2.85%24 May 2021
CVE-2021-24308The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading…EXPLOITMEDIUM 5.4EPSS 3.25%24 May 2021
CVE-2021-24300The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issueEXPLOITMEDIUM 6.1EPSS 10.6%24 May 2021
CVE-2008-3280It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166).EXPLOITMEDIUM 5.9EPSS 3.95%21 May 2021
CVE-2021-32305WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.EXPLOITCRITICAL 9.8EPSS 87.3%18 May 2021
CVE-2021-24299The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads.EXPLOITMEDIUM 6.1EPSS 5.50%17 May 2021
CVE-2021-32403Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.EXPLOITHIGH 8.8EPSS 2.46%17 May 2021
CVE-2021-24287The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issueEXPLOITMEDIUM 6.1EPSS 10.4%14 May 2021
CVE-2021-24286The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issueEXPLOITMEDIUM 6.1EPSS 13.9%14 May 2021
CVE-2021-24247As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation.EXPLOITMEDIUM 5.4EPSS 4.68%6 May 2021
CVE-2021-24245The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected…EXPLOITMEDIUM 6.1EPSS 5.72%6 May 2021
CVE-2021-24276The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issueEXPLOITMEDIUM 6.1EPSS 16.0%5 May 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.