Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 24 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-27308 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter. | EXPLOITMEDIUM 4.8EPSS 1.99% | 22 March 2021 |
| CVE-2021-27520 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | EXPLOITMEDIUM 6.1EPSS 6.40% | 19 March 2021 |
| CVE-2021-27519 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | EXPLOITMEDIUM 6.1EPSS 7.60% | 19 March 2021 |
| CVE-2021-27928 | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. | EXPLOITHIGH 7.2EPSS 38.4% | 19 March 2021 |
| CVE-2021-24146 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example. | EXPLOITHIGH 7.5EPSS 31.0% | 18 March 2021 |
| CVE-2021-24145 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request. | EXPLOITHIGH 7.2EPSS 87.2% | 18 March 2021 |
| CVE-2021-28420 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time" parameter. | EXPLOITMEDIUM 4.8EPSS 1.93% | 18 March 2021 |
| CVE-2021-28419 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases. | EXPLOITHIGH 7.2EPSS 10.7% | 18 March 2021 |
| CVE-2021-28418 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter. | EXPLOITMEDIUM 4.8EPSS 1.87% | 18 March 2021 |
| CVE-2021-28417 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter. | EXPLOITMEDIUM 4.8EPSS 1.87% | 18 March 2021 |
| CVE-2021-27946 | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. | EXPLOITHIGH 8.8EPSS 4.20% | 15 March 2021 |
| CVE-2021-27890 | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. | EXPLOITHIGH 8.8EPSS 10.6% | 15 March 2021 |
| CVE-2021-27889 | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. | EXPLOITMEDIUM 6.1EPSS 5.07% | 15 March 2021 |
| CVE-2021-27695 | Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters. | EXPLOITMEDIUM 6.1EPSS 3.01% | 15 March 2021 |
| CVE-2021-28379 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. | EXPLOITHIGH 8.8EPSS 6.03% | 15 March 2021 |
| CVE-2020-29238 | An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request. | EXPLOITHIGH 7.5EPSS 16.5% | 10 March 2021 |
| CVE-2021-21337 | In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. | EXPLOITMEDIUM 6.1EPSS 8.44% | 8 March 2021 |
| CVE-2021-27964 | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. | EXPLOIT ✓CRITICAL 9.8EPSS 47.5% | 5 March 2021 |
| CVE-2021-27065 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVEXPLOITHIGH 7.8EPSS 99.9% | 3 March 2021 |
| CVE-2021-26855 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVEXPLOIT ×4CRITICAL 9.1EPSS 100.0% | 3 March 2021 |
| CVE-2021-27885 | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. | EXPLOITHIGH 8.8EPSS 3.21% | 2 March 2021 |
| CVE-2020-23518 | Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML. | EXPLOITMEDIUM 5.4EPSS 2.00% | 2 March 2021 |
| CVE-2021-21972 | VMware vCenter Server Remote Code Execution Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 99.9% | 24 February 2021 |
| CVE-2021-3355 | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords. | EXPLOITMEDIUM 5.4EPSS 7.25% | 24 February 2021 |
| CVE-2021-27370 | The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. | EXPLOITMEDIUM 5.4EPSS 3.27% | 22 February 2021 |
| CVE-2019-25024 | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. | EXPLOITCRITICAL 9.8EPSS 27.6% | 19 February 2021 |
| CVE-2020-28337 | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. | EXPLOITHIGH 7.2EPSS 16.6% | 15 February 2021 |
| CVE-2020-35775 | CITSmart before 9.1.2.23 allows LDAP Injection. | EXPLOITCRITICAL 9.8EPSS 13.3% | 15 February 2021 |
| CVE-2021-26929 | An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). | EXPLOITMEDIUM 6.1EPSS 4.94% | 14 February 2021 |
| CVE-2021-3394 | Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation. | EXPLOIT ✓HIGH 8.8EPSS 5.79% | 9 February 2021 |
| CVE-2020-22841 | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module. | EXPLOITMEDIUM 4.8EPSS 3.54% | 9 February 2021 |
| CVE-2021-3294 | CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. | EXPLOITMEDIUM 5.4EPSS 2.85% | 9 February 2021 |
| CVE-2020-18724 | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list. | EXPLOITMEDIUM 5.4EPSS 3.19% | 3 February 2021 |
| CVE-2020-18723 | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities. | EXPLOITMEDIUM 5.4EPSS 3.80% | 3 February 2021 |
| CVE-2021-3378 | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp. | EXPLOIT ✓CRITICAL 9.8EPSS 97.5% | 1 February 2021 |
| CVE-2021-21276 | Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. | EXPLOITCRITICAL 9.3EPSS 7.16% | 1 February 2021 |
| CVE-2021-3298 | Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter. | EXPLOITMEDIUM 5.4EPSS 2.14% | 29 January 2021 |
| CVE-2021-3337 | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit. | EXPLOITHIGH 7.5EPSS 11.5% | 28 January 2021 |
| CVE-2020-35754 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. | EXPLOITHIGH 7.2EPSS 10.5% | 28 January 2021 |
| CVE-2021-3318 | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. | EXPLOITMEDIUM 6.1EPSS 2.85% | 27 January 2021 |
| CVE-2021-3317 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | EXPLOITHIGH 8.8EPSS 41.4% | 26 January 2021 |
| CVE-2021-3156 | Sudo Heap-Based Buffer Overflow Vulnerability | KEVEXPLOIT ×2HIGH 7.8EPSS 100.0% | 26 January 2021 |
| CVE-2021-3291 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command. | EXPLOIT ✓HIGH 7.2EPSS 16.8% | 26 January 2021 |
| CVE-2021-3278 | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . | EXPLOITCRITICAL 9.8EPSS 25.3% | 26 January 2021 |
| CVE-2021-3186 | A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter. | EXPLOITMEDIUM 5.4EPSS 2.51% | 26 January 2021 |
| CVE-2020-35576 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577. | EXPLOITHIGH 8.8EPSS 42.3% | 26 January 2021 |
| CVE-2021-2109 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). | EXPLOITHIGH 7.2EPSS 70.4% | 20 January 2021 |
| CVE-2020-23342 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. | EXPLOITHIGH 8.8EPSS 12.4% | 19 January 2021 |
| CVE-2020-23522 | Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. | EXPLOITMEDIUM 6.8EPSS 2.01% | 19 January 2021 |
| CVE-2020-35749 | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php. | EXPLOIT ×2 ✓HIGH 7.7EPSS 30.5% | 15 January 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.