SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 25 of 501

CVESummaryPriorityPublished
CVE-2020-35578Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.EXPLOITHIGH 7.2EPSS 81.9%13 January 2021
CVE-2020-35687PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.EXPLOITMEDIUM 4.3EPSS 1.36%13 January 2021
CVE-2021-3129Laravel Ignition File Upload VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%12 January 2021
CVE-2020-5147SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system.EXPLOITMEDIUM 5.3EPSS 1.66%9 January 2021
CVE-2020-16040Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.EXPLOITMEDIUM 6.5EPSS 99.6%8 January 2021
CVE-2021-3111The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.EXPLOITMEDIUM 4.8EPSS 3.01%8 January 2021
CVE-2020-35488The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service.EXPLOITHIGH 7.5EPSS 7.60%5 January 2021
CVE-2020-17519Apache Flink Improper Access Control VulnerabilityKEVEXPLOITHIGH 7.5EPSS 97.8%5 January 2021
CVE-2021-3018ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.EXPLOITCRITICAL 9.8EPSS 19.5%5 January 2021
CVE-2020-35391Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942.EXPLOITMEDIUM 6.5EPSS 35.2%1 January 2021
CVE-2020-35948It gave authenticated attackers the ability to modify arbitrary files, including PHP files.EXPLOITHIGH 8.8EPSS 24.9%1 January 2021
CVE-2020-28413In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.EXPLOITMEDIUM 6.5EPSS 4.72%30 December 2020
CVE-2020-35737In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.EXPLOITHIGH 7.5EPSS 10.3%30 December 2020
CVE-2020-5811An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.EXPLOITMEDIUM 6.5EPSS 9.37%30 December 2020
CVE-2020-35241FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component.EXPLOITMEDIUM 4.8EPSS 2.15%30 December 2020
CVE-2020-29477Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field.EXPLOITMEDIUM 4.8EPSS 1.09%30 December 2020
CVE-2020-29469WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component.EXPLOITMEDIUM 5.4EPSS 1.37%30 December 2020
CVE-2020-29233WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component.EXPLOITMEDIUM 5.4EPSS 1.27%30 December 2020
CVE-2020-35848Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.EXPLOITCRITICAL 9.8EPSS 74.6%30 December 2020
CVE-2020-35847Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.EXPLOITCRITICAL 9.8EPSS 98.2%30 December 2020
CVE-2020-29471OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image.EXPLOITMEDIUM 4.8EPSS 1.26%29 December 2020
CVE-2020-29470OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail.EXPLOITMEDIUM 4.8EPSS 1.69%29 December 2020
CVE-2020-29475nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field.EXPLOITMEDIUM 4.8EPSS 1.08%29 December 2020
CVE-2020-35729KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.EXPLOIT ×2CRITICAL 9.8EPSS 88.1%27 December 2020
CVE-2020-35437Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.EXPLOITMEDIUM 6.1EPSS 3.03%26 December 2020
CVE-2020-28169The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.EXPLOITHIGH 7.0EPSS 1.17%24 December 2020
CVE-2020-35665An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.EXPLOITCRITICAL 9.8EPSS 78.5%23 December 2020
CVE-2020-35598ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.EXPLOITHIGH 7.5EPSS 20.8%23 December 2020
CVE-2020-35151The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.EXPLOITHIGH 8.8EPSS 3.83%21 December 2020
CVE-2020-35606Arbitrary command execution can occur in Webmin through 1.962.EXPLOITHIGH 8.8EPSS 28.0%21 December 2020
CVE-2020-20277There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read…EXPLOITCRITICAL 9.8EPSS 26.2%18 December 2020
CVE-2020-25901Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.EXPLOITMEDIUM 6.1EPSS 5.14%18 December 2020
CVE-2020-25495A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.EXPLOITMEDIUM 6.1EPSS 8.98%18 December 2020
CVE-2020-25494Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.EXPLOITCRITICAL 9.8EPSS 39.2%18 December 2020
CVE-2020-20142Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.EXPLOITMEDIUM 6.1EPSS 2.11%17 December 2020
CVE-2020-20141Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.EXPLOITMEDIUM 6.1EPSS 2.16%17 December 2020
CVE-2020-20140Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.EXPLOITMEDIUM 6.1EPSS 2.16%17 December 2020
CVE-2020-20139Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.EXPLOITMEDIUM 6.1EPSS 2.16%17 December 2020
CVE-2020-29607A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.EXPLOITHIGH 7.2EPSS 33.2%16 December 2020
CVE-2020-35416Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.EXPLOITMEDIUM 6.1EPSS 2.71%15 December 2020
CVE-2020-10770This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.EXPLOITMEDIUM 5.3EPSS 69.7%15 December 2020
CVE-2020-29597IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability.EXPLOITCRITICAL 9.8EPSS 71.0%7 December 2020
CVE-2020-29240Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS).EXPLOITMEDIUM 4.8EPSS 1.69%2 December 2020
CVE-2020-29395The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.EXPLOITMEDIUM 6.1EPSS 12.9%30 November 2020
CVE-2020-28978The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.EXPLOITMEDIUM 5.3EPSS 15.4%30 November 2020
CVE-2020-28977The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.EXPLOITMEDIUM 5.3EPSS 15.4%30 November 2020
CVE-2020-28976The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.EXPLOITMEDIUM 5.3EPSS 27.8%30 November 2020
CVE-2020-12352Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.EXPLOITMEDIUM 6.5EPSS 5.71%23 November 2020
CVE-2020-12351Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.EXPLOITHIGH 8.8EPSS 7.69%23 November 2020
CVE-2020-28091cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.EXPLOITHIGH 7.5EPSS 3.80%18 November 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.