Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 26 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-28092 | PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id= | EXPLOITMEDIUM 6.1EPSS 2.69% | 17 November 2020 |
| CVE-2020-25988 | UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent. | EXPLOITMEDIUM 6.5EPSS 3.05% | 17 November 2020 |
| CVE-2020-28688 | The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | EXPLOITHIGH 8.8EPSS 12.0% | 17 November 2020 |
| CVE-2020-28687 | The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | EXPLOITHIGH 8.8EPSS 12.0% | 17 November 2020 |
| CVE-2020-27423 | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox | EXPLOITHIGH 7.5EPSS 6.44% | 16 November 2020 |
| CVE-2020-27422 | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account. | EXPLOITCRITICAL 9.8EPSS 7.86% | 16 November 2020 |
| CVE-2020-25557 | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. | EXPLOITHIGH 8.8EPSS 9.97% | 13 November 2020 |
| CVE-2020-25538 | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. | EXPLOITHIGH 8.8EPSS 9.97% | 13 November 2020 |
| CVE-2020-26218 | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. | EXPLOITMEDIUM 6.1EPSS 1.94% | 11 November 2020 |
| CVE-2020-13927 | Apache Airflow's Experimental API Authentication Bypass | KEVEXPLOITCRITICAL 9.8EPSS 99.8% | 10 November 2020 |
| CVE-2020-28351 | The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object… | EXPLOITMEDIUM 6.1EPSS 16.0% | 9 November 2020 |
| CVE-2020-28328 | SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. | EXPLOITHIGH 8.8EPSS 63.3% | 6 November 2020 |
| CVE-2020-28249 | Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note. | EXPLOITMEDIUM 6.1EPSS 3.06% | 6 November 2020 |
| CVE-2020-24881 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | EXPLOITCRITICAL 9.8EPSS 73.4% | 2 November 2020 |
| CVE-2020-14425 | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. | EXPLOIT ✓HIGH 7.8EPSS 40.8% | 2 November 2020 |
| CVE-2020-7384 | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. | EXPLOITHIGH 7.8EPSS 30.5% | 29 October 2020 |
| CVE-2020-15238 | In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argument injection vulnerability. | EXPLOITHIGH 7.0EPSS 4.59% | 27 October 2020 |
| CVE-2020-26887 | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. | EXPLOITHIGH 7.8EPSS 1.42% | 23 October 2020 |
| CVE-2020-27533 | A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages. | EXPLOITMEDIUM 5.4EPSS 3.56% | 22 October 2020 |
| CVE-2020-7750 | The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function. | EXPLOITCRITICAL 9.6EPSS 6.15% | 21 October 2020 |
| CVE-2020-14882 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 21 October 2020 |
| CVE-2020-14871 | Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability | KEVEXPLOIT ×3CRITICAL 10.0EPSS 80.2% | 21 October 2020 |
| CVE-2020-14864 | Oracle Business Intelligence Enterprise Edition Path Transversal | KEVEXPLOITHIGH 7.5EPSS 97.2% | 21 October 2020 |
| CVE-2020-25820 | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field. | EXPLOITMEDIUM 6.5EPSS 10.5% | 21 October 2020 |
| CVE-2020-5791 | Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user. | EXPLOITHIGH 7.2EPSS 78.6% | 20 October 2020 |
| CVE-2020-15261 | On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. | EXPLOITMEDIUM 6.7EPSS 11.3% | 19 October 2020 |
| CVE-2020-15255 | In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). | EXPLOITHIGH 7.3EPSS 3.50% | 16 October 2020 |
| CVE-2020-26567 | An issue was discovered on D-Link DSR-250N before 3.17B devices. | EXPLOITMEDIUM 5.5EPSS 17.2% | 8 October 2020 |
| CVE-2020-25270 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | EXPLOITMEDIUM 5.4EPSS 3.19% | 8 October 2020 |
| CVE-2020-24219 | Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password. | EXPLOITHIGH 7.5EPSS 23.6% | 6 October 2020 |
| CVE-2020-24217 | Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution. | EXPLOIT ×2CRITICAL 9.8EPSS 40.3% | 6 October 2020 |
| CVE-2020-24215 | Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve… | EXPLOITCRITICAL 9.8EPSS 19.8% | 6 October 2020 |
| CVE-2020-24214 | Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. | EXPLOITCRITICAL 9.8EPSS 35.4% | 6 October 2020 |
| CVE-2020-17382 | The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054). | EXPLOITHIGH 7.8EPSS 2.08% | 2 October 2020 |
| CVE-2020-25762 | An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc. | EXPLOITCRITICAL 9.1EPSS 11.3% | 30 September 2020 |
| CVE-2020-13951 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | EXPLOITHIGH 7.5EPSS 70.4% | 30 September 2020 |
| CVE-2020-15160 | PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. | EXPLOITCRITICAL 9.8EPSS 10.8% | 24 September 2020 |
| CVE-2020-15930 | An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. | EXPLOITMEDIUM 6.1EPSS 4.38% | 24 September 2020 |
| CVE-2020-24365 | The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. | EXPLOITHIGH 8.8EPSS 11.4% | 24 September 2020 |
| CVE-2019-15993 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. | EXPLOITMEDIUM 5.3EPSS 10.3% | 23 September 2020 |
| CVE-2020-16171 | This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572. | EXPLOITMEDIUM 6.5EPSS 5.50% | 21 September 2020 |
| CVE-2020-25790 | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. | EXPLOITHIGH 7.2EPSS 15.6% | 19 September 2020 |
| CVE-2020-25787 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. | EXPLOITCRITICAL 9.8EPSS 18.4% | 19 September 2020 |
| CVE-2020-13260 | A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in… | EXPLOITMEDIUM 6.1EPSS 1.98% | 17 September 2020 |
| CVE-2020-11804 | Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. | EXPLOITHIGH 8.8EPSS 7.11% | 17 September 2020 |
| CVE-2020-11803 | Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. | EXPLOITHIGH 8.8EPSS 7.55% | 17 September 2020 |
| CVE-2020-11700 | Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. | EXPLOITMEDIUM 6.5EPSS 7.09% | 17 September 2020 |
| CVE-2020-11699 | Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. | EXPLOITHIGH 8.8EPSS 9.64% | 17 September 2020 |
| CVE-2020-11698 | Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server. | EXPLOITCRITICAL 9.8EPSS 73.2% | 17 September 2020 |
| CVE-2020-14181 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. | EXPLOITMEDIUM 5.3EPSS 99.6% | 17 September 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.