Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 25 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-35578 | Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands. | EXPLOITHIGH 7.2EPSS 81.9% | 13 January 2021 |
| CVE-2020-35687 | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. | EXPLOITMEDIUM 4.3EPSS 1.36% | 13 January 2021 |
| CVE-2021-3129 | Laravel Ignition File Upload Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 12 January 2021 |
| CVE-2020-5147 | SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. | EXPLOITMEDIUM 5.3EPSS 1.66% | 9 January 2021 |
| CVE-2020-16040 | Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | EXPLOITMEDIUM 6.5EPSS 99.6% | 8 January 2021 |
| CVE-2021-3111 | The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI. | EXPLOITMEDIUM 4.8EPSS 3.01% | 8 January 2021 |
| CVE-2020-35488 | The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. | EXPLOITHIGH 7.5EPSS 7.60% | 5 January 2021 |
| CVE-2020-17519 | Apache Flink Improper Access Control Vulnerability | KEVEXPLOIT ✓HIGH 7.5EPSS 97.8% | 5 January 2021 |
| CVE-2021-3018 | ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page. | EXPLOITCRITICAL 9.8EPSS 19.5% | 5 January 2021 |
| CVE-2020-35391 | Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. | EXPLOITMEDIUM 6.5EPSS 35.2% | 1 January 2021 |
| CVE-2020-35948 | It gave authenticated attackers the ability to modify arbitrary files, including PHP files. | EXPLOITHIGH 8.8EPSS 24.9% | 1 January 2021 |
| CVE-2020-28413 | In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP. | EXPLOITMEDIUM 6.5EPSS 4.72% | 30 December 2020 |
| CVE-2020-35737 | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference. | EXPLOITHIGH 7.5EPSS 10.3% | 30 December 2020 |
| CVE-2020-5811 | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package. | EXPLOITMEDIUM 6.5EPSS 9.37% | 30 December 2020 |
| CVE-2020-35241 | FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. | EXPLOITMEDIUM 4.8EPSS 2.15% | 30 December 2020 |
| CVE-2020-29477 | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. | EXPLOITMEDIUM 4.8EPSS 1.09% | 30 December 2020 |
| CVE-2020-29469 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. | EXPLOITMEDIUM 5.4EPSS 1.37% | 30 December 2020 |
| CVE-2020-29233 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. | EXPLOIT ✓MEDIUM 5.4EPSS 1.27% | 30 December 2020 |
| CVE-2020-35848 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. | EXPLOITCRITICAL 9.8EPSS 74.6% | 30 December 2020 |
| CVE-2020-35847 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. | EXPLOITCRITICAL 9.8EPSS 98.2% | 30 December 2020 |
| CVE-2020-29471 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. | EXPLOITMEDIUM 4.8EPSS 1.26% | 29 December 2020 |
| CVE-2020-29470 | OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. | EXPLOITMEDIUM 4.8EPSS 1.69% | 29 December 2020 |
| CVE-2020-29475 | nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. | EXPLOITMEDIUM 4.8EPSS 1.08% | 29 December 2020 |
| CVE-2020-35729 | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 88.1% | 27 December 2020 |
| CVE-2020-35437 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI. | EXPLOITMEDIUM 6.1EPSS 3.03% | 26 December 2020 |
| CVE-2020-28169 | The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. | EXPLOITHIGH 7.0EPSS 1.17% | 24 December 2020 |
| CVE-2020-35665 | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation. | EXPLOITCRITICAL 9.8EPSS 78.5% | 23 December 2020 |
| CVE-2020-35598 | ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. | EXPLOITHIGH 7.5EPSS 20.8% | 23 December 2020 |
| CVE-2020-35151 | The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection. | EXPLOITHIGH 8.8EPSS 3.83% | 21 December 2020 |
| CVE-2020-35606 | Arbitrary command execution can occur in Webmin through 1.962. | EXPLOIT ✓HIGH 8.8EPSS 28.0% | 21 December 2020 |
| CVE-2020-20277 | There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read… | EXPLOITCRITICAL 9.8EPSS 26.2% | 18 December 2020 |
| CVE-2020-25901 | Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages. | EXPLOITMEDIUM 6.1EPSS 5.14% | 18 December 2020 |
| CVE-2020-25495 | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'. | EXPLOITMEDIUM 6.1EPSS 8.98% | 18 December 2020 |
| CVE-2020-25494 | Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook. | EXPLOITCRITICAL 9.8EPSS 39.2% | 18 December 2020 |
| CVE-2020-20142 | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17. | EXPLOITMEDIUM 6.1EPSS 2.11% | 17 December 2020 |
| CVE-2020-20141 | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | EXPLOITMEDIUM 6.1EPSS 2.16% | 17 December 2020 |
| CVE-2020-20140 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | EXPLOITMEDIUM 6.1EPSS 2.16% | 17 December 2020 |
| CVE-2020-20139 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | EXPLOITMEDIUM 6.1EPSS 2.16% | 17 December 2020 |
| CVE-2020-29607 | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution. | EXPLOIT ✓HIGH 7.2EPSS 33.2% | 16 December 2020 |
| CVE-2020-35416 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML. | EXPLOITMEDIUM 6.1EPSS 2.71% | 15 December 2020 |
| CVE-2020-10770 | This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack. | EXPLOITMEDIUM 5.3EPSS 69.7% | 15 December 2020 |
| CVE-2020-29597 | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. | EXPLOITCRITICAL 9.8EPSS 71.0% | 7 December 2020 |
| CVE-2020-29240 | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). | EXPLOITMEDIUM 4.8EPSS 1.69% | 2 December 2020 |
| CVE-2020-29395 | The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. | EXPLOITMEDIUM 6.1EPSS 12.9% | 30 November 2020 |
| CVE-2020-28978 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. | EXPLOITMEDIUM 5.3EPSS 15.4% | 30 November 2020 |
| CVE-2020-28977 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. | EXPLOITMEDIUM 5.3EPSS 15.4% | 30 November 2020 |
| CVE-2020-28976 | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. | EXPLOITMEDIUM 5.3EPSS 27.8% | 30 November 2020 |
| CVE-2020-12352 | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | EXPLOITMEDIUM 6.5EPSS 5.71% | 23 November 2020 |
| CVE-2020-12351 | Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | EXPLOITHIGH 8.8EPSS 7.69% | 23 November 2020 |
| CVE-2020-28091 | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php. | EXPLOITHIGH 7.5EPSS 3.80% | 18 November 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.