Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 23 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-24275 | The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 18.2% | 5 May 2021 |
| CVE-2021-24274 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | EXPLOITMEDIUM 6.1EPSS 17.6% | 5 May 2021 |
| CVE-2021-24272 | The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the… | EXPLOITMEDIUM 4.3EPSS 1.81% | 5 May 2021 |
| CVE-2021-21551 | Dell dbutil Driver Insufficient Access Control Vulnerability | KEVEXPLOITHIGH 7.8EPSS 79.2% | 4 May 2021 |
| CVE-2021-31933 | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). | EXPLOIT ✓HIGH 7.2EPSS 13.9% | 30 April 2021 |
| CVE-2021-29460 | This vulnerability is critical if you might have potential attackers in your group of authenticated Panel users, as they can escalate their privileges if they get access to the Panel session of an admin user. | EXPLOITMEDIUM 5.4EPSS 3.17% | 27 April 2021 |
| CVE-2021-31762 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. | EXPLOITHIGH 8.8EPSS 8.78% | 25 April 2021 |
| CVE-2021-31761 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | EXPLOITCRITICAL 9.6EPSS 33.6% | 25 April 2021 |
| CVE-2021-22205 | GitLab Community and Enterprise Editions Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 99.7% | 23 April 2021 |
| CVE-2021-22204 | ExifTool Remote Code Execution Vulnerability | KEVEXPLOITHIGH 7.8EPSS 100.0% | 23 April 2021 |
| CVE-2021-31329 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php | EXPLOITMEDIUM 5.4EPSS 1.66% | 21 April 2021 |
| CVE-2021-31327 | Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. | EXPLOITMEDIUM 5.4EPSS 1.66% | 21 April 2021 |
| CVE-2020-35314 | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer. | EXPLOITCRITICAL 9.8EPSS 26.9% | 20 April 2021 |
| CVE-2020-35313 | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer. | EXPLOITCRITICAL 9.8EPSS 45.2% | 20 April 2021 |
| CVE-2021-25681 | AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. | EXPLOITHIGH 7.5EPSS 10.9% | 20 April 2021 |
| CVE-2021-25680 | The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. | EXPLOITMEDIUM 6.1EPSS 2.46% | 20 April 2021 |
| CVE-2021-25679 | The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. | EXPLOITMEDIUM 5.4EPSS 2.70% | 20 April 2021 |
| CVE-2021-26830 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. | EXPLOITCRITICAL 9.1EPSS 4.57% | 16 April 2021 |
| CVE-2021-29447 | A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. | EXPLOITMEDIUM 6.5EPSS 85.7% | 15 April 2021 |
| CVE-2021-28242 | SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab. | EXPLOITHIGH 8.8EPSS 4.96% | 15 April 2021 |
| CVE-2021-31152 | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. | EXPLOITHIGH 8.8EPSS 3.75% | 14 April 2021 |
| CVE-2021-29440 | Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. | EXPLOITHIGH 7.2EPSS 30.6% | 13 April 2021 |
| CVE-2021-29003 | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI. | EXPLOITCRITICAL 9.8EPSS 45.4% | 13 April 2021 |
| CVE-2021-30637 | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. | EXPLOITMEDIUM 5.4EPSS 1.90% | 13 April 2021 |
| CVE-2021-30044 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. | EXPLOITMEDIUM 5.4EPSS 1.77% | 13 April 2021 |
| CVE-2021-30042 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php | EXPLOITMEDIUM 5.4EPSS 1.77% | 13 April 2021 |
| CVE-2021-30039 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php. | EXPLOITMEDIUM 5.4EPSS 1.77% | 13 April 2021 |
| CVE-2021-30034 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. | EXPLOITMEDIUM 5.4EPSS 1.77% | 13 April 2021 |
| CVE-2021-30030 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. | EXPLOITMEDIUM 5.4EPSS 1.77% | 13 April 2021 |
| CVE-2021-21425 | In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. | EXPLOIT ✓CRITICAL 9.8EPSS 80.6% | 7 April 2021 |
| CVE-2021-30147 | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. | EXPLOITHIGH 8.8EPSS 3.52% | 7 April 2021 |
| CVE-2021-28142 | CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete." | EXPLOITHIGH 8.8EPSS 5.77% | 6 April 2021 |
| CVE-2021-30150 | Composr 10.0.36 allows XSS in an XML script. | EXPLOITMEDIUM 6.1EPSS 2.77% | 6 April 2021 |
| CVE-2021-30149 | Composr 10.0.36 allows upload and execution of PHP files. | EXPLOITCRITICAL 9.8EPSS 10.1% | 6 April 2021 |
| CVE-2021-24174 | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups. | EXPLOITHIGH 8.1EPSS 3.22% | 5 April 2021 |
| CVE-2021-24169 | The tab parameter in the Admin Panel is vulnerable to reflected XSS. | EXPLOITMEDIUM 6.1EPSS 10.3% | 5 April 2021 |
| CVE-2021-24155 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones,… | EXPLOITHIGH 7.2EPSS 84.1% | 5 April 2021 |
| CVE-2021-27973 | SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages. | EXPLOITHIGH 7.2EPSS 11.0% | 2 April 2021 |
| CVE-2021-28164 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. | EXPLOITMEDIUM 5.3EPSS 82.4% | 1 April 2021 |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 31 March 2021 |
| CVE-2021-28935 | CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. | EXPLOITMEDIUM 5.4EPSS 1.57% | 30 March 2021 |
| CVE-2021-25162 | A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x:… | EXPLOITHIGH 8.1EPSS 25.8% | 30 March 2021 |
| CVE-2021-25161 | A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and… | EXPLOITMEDIUM 6.1EPSS 16.4% | 30 March 2021 |
| CVE-2021-25160 | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14… | EXPLOITMEDIUM 4.9EPSS 6.61% | 30 March 2021 |
| CVE-2021-25159 | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14… | EXPLOITMEDIUM 6.5EPSS 12.6% | 30 March 2021 |
| CVE-2021-25158 | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba… | EXPLOITMEDIUM 5.9EPSS 30.5% | 30 March 2021 |
| CVE-2021-25157 | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below;… | EXPLOITMEDIUM 4.9EPSS 10.3% | 30 March 2021 |
| CVE-2021-25156 | A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and… | EXPLOITMEDIUM 4.9EPSS 39.6% | 30 March 2021 |
| CVE-2021-25155 | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14… | EXPLOIT ×2MEDIUM 6.5EPSS 12.4% | 30 March 2021 |
| CVE-2021-29156 | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. | EXPLOITHIGH 7.5EPSS 76.4% | 25 March 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.