SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 24 of 501

CVESummaryPriorityPublished
CVE-2021-27308A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.EXPLOITMEDIUM 4.8EPSS 1.99%22 March 2021
CVE-2021-27520A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.EXPLOITMEDIUM 6.1EPSS 6.40%19 March 2021
CVE-2021-27519A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.EXPLOITMEDIUM 6.1EPSS 7.60%19 March 2021
CVE-2021-27928A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL.EXPLOITHIGH 7.2EPSS 38.4%19 March 2021
CVE-2021-24146Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.EXPLOITHIGH 7.5EPSS 31.0%18 March 2021
CVE-2021-24145Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.EXPLOITHIGH 7.2EPSS 87.2%18 March 2021
CVE-2021-28420A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter.EXPLOITMEDIUM 4.8EPSS 1.93%18 March 2021
CVE-2021-28419The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.EXPLOITHIGH 7.2EPSS 10.7%18 March 2021
CVE-2021-28418A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.EXPLOITMEDIUM 4.8EPSS 1.87%18 March 2021
CVE-2021-28417A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.EXPLOITMEDIUM 4.8EPSS 1.87%18 March 2021
CVE-2021-27946SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count.EXPLOITHIGH 8.8EPSS 4.20%15 March 2021
CVE-2021-27890SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.EXPLOITHIGH 8.8EPSS 10.6%15 March 2021
CVE-2021-27889Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.EXPLOITMEDIUM 6.1EPSS 5.07%15 March 2021
CVE-2021-27695Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.EXPLOITMEDIUM 6.1EPSS 3.01%15 March 2021
CVE-2021-28379web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.EXPLOITHIGH 8.8EPSS 6.03%15 March 2021
CVE-2020-29238An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.EXPLOITHIGH 7.5EPSS 16.5%10 March 2021
CVE-2021-21337In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability.EXPLOITMEDIUM 6.1EPSS 8.44%8 March 2021
CVE-2021-27964SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload.EXPLOITCRITICAL 9.8EPSS 47.5%5 March 2021
CVE-2021-27065Microsoft Exchange Server Remote Code Execution VulnerabilityKEVEXPLOITHIGH 7.8EPSS 99.9%3 March 2021
CVE-2021-26855Microsoft Exchange Server Remote Code Execution VulnerabilityKEVEXPLOIT ×4CRITICAL 9.1EPSS 100.0%3 March 2021
CVE-2021-27885usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.EXPLOITHIGH 8.8EPSS 3.21%2 March 2021
CVE-2020-23518Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.EXPLOITMEDIUM 5.4EPSS 2.00%2 March 2021
CVE-2021-21972VMware vCenter Server Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.9%24 February 2021
CVE-2021-3355A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.EXPLOITMEDIUM 5.4EPSS 7.25%24 February 2021
CVE-2021-27370The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.EXPLOITMEDIUM 5.4EPSS 3.27%22 February 2021
CVE-2019-25024OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.EXPLOITCRITICAL 9.8EPSS 27.6%19 February 2021
CVE-2020-28337A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature.EXPLOITHIGH 7.2EPSS 16.6%15 February 2021
CVE-2020-35775CITSmart before 9.1.2.23 allows LDAP Injection.EXPLOITCRITICAL 9.8EPSS 13.3%15 February 2021
CVE-2021-26929An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used).EXPLOITMEDIUM 6.1EPSS 4.94%14 February 2021
CVE-2021-3394Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.EXPLOITHIGH 8.8EPSS 5.79%9 February 2021
CVE-2020-22841Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.EXPLOITMEDIUM 4.8EPSS 3.54%9 February 2021
CVE-2021-3294CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php.EXPLOITMEDIUM 5.4EPSS 2.85%9 February 2021
CVE-2020-18724Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.EXPLOITMEDIUM 5.4EPSS 3.19%3 February 2021
CVE-2020-18723Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.EXPLOITMEDIUM 5.4EPSS 3.80%3 February 2021
CVE-2021-3378FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.EXPLOITCRITICAL 9.8EPSS 97.5%1 February 2021
CVE-2021-21276Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account.EXPLOITCRITICAL 9.3EPSS 7.16%1 February 2021
CVE-2021-3298Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.EXPLOITMEDIUM 5.4EPSS 2.14%29 January 2021
CVE-2021-3337The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.EXPLOITHIGH 7.5EPSS 11.5%28 January 2021
CVE-2020-35754OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.EXPLOITHIGH 7.2EPSS 10.5%28 January 2021
CVE-2021-3318attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.EXPLOITMEDIUM 6.1EPSS 2.85%27 January 2021
CVE-2021-3317KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.EXPLOITHIGH 8.8EPSS 41.4%26 January 2021
CVE-2021-3156Sudo Heap-Based Buffer Overflow VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 100.0%26 January 2021
CVE-2021-3291Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.EXPLOITHIGH 7.2EPSS 16.8%26 January 2021
CVE-2021-3278Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection .EXPLOITCRITICAL 9.8EPSS 25.3%26 January 2021
CVE-2021-3186A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.EXPLOITMEDIUM 5.4EPSS 2.51%26 January 2021
CVE-2020-35576A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.EXPLOITHIGH 8.8EPSS 42.3%26 January 2021
CVE-2021-2109Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).EXPLOITHIGH 7.2EPSS 70.4%20 January 2021
CVE-2020-23342A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.EXPLOITHIGH 8.8EPSS 12.4%19 January 2021
CVE-2020-23522Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.EXPLOITMEDIUM 6.8EPSS 2.01%19 January 2021
CVE-2020-35749Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.EXPLOIT ×2HIGH 7.7EPSS 30.5%15 January 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.