Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 27 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-13259 | A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. | EXPLOITHIGH 8.8EPSS 4.66% | 16 September 2020 |
| CVE-2020-25015 | A specific router allows changing the Wi-Fi password remotely. | EXPLOITMEDIUM 6.5EPSS 3.10% | 16 September 2020 |
| CVE-2020-25453 | There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | EXPLOITHIGH 8.8EPSS 6.28% | 15 September 2020 |
| CVE-2019-0230 | Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | EXPLOITCRITICAL 9.8EPSS 97.4% | 14 September 2020 |
| CVE-2020-25540 | ThinkAdmin v6 is affected by a directory traversal vulnerability. | EXPLOITHIGH 7.5EPSS 75.3% | 14 September 2020 |
| CVE-2020-2038 | An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. | EXPLOITHIGH 7.2EPSS 86.1% | 9 September 2020 |
| CVE-2020-25213 | WordPress File Manager Plugin Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 97.3% | 9 September 2020 |
| CVE-2020-24963 | An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4. | EXPLOITMEDIUM 5.4EPSS 1.85% | 4 September 2020 |
| CVE-2020-14008 | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution. | EXPLOITHIGH 7.2EPSS 40.1% | 4 September 2020 |
| CVE-2020-24949 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE). | EXPLOIT ✓HIGH 8.8EPSS 67.5% | 3 September 2020 |
| CVE-2020-14209 | Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. | EXPLOITHIGH 8.8EPSS 27.5% | 2 September 2020 |
| CVE-2020-16602 | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. | EXPLOIT ✓HIGH 8.1EPSS 5.99% | 2 September 2020 |
| CVE-2020-23839 | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a… | EXPLOITMEDIUM 6.1EPSS 10.5% | 1 September 2020 |
| CVE-2020-23835 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and… | EXPLOITMEDIUM 6.1EPSS 2.29% | 1 September 2020 |
| CVE-2020-24363 | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | KEVEXPLOITHIGH 8.8EPSS 20.7% | 31 August 2020 |
| CVE-2020-24223 | Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters. | EXPLOITMEDIUM 6.1EPSS 14.6% | 30 August 2020 |
| CVE-2020-23972 | In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the… | EXPLOITHIGH 7.5EPSS 31.4% | 27 August 2020 |
| CVE-2020-24609 | Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal… | EXPLOIT ×2MEDIUM 6.1EPSS 9.81% | 25 August 2020 |
| CVE-2020-24186 | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action. | EXPLOIT ×2CRITICAL 10.0EPSS 94.6% | 24 August 2020 |
| CVE-2020-23935 | Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | EXPLOITCRITICAL 9.8EPSS 15.9% | 20 August 2020 |
| CVE-2020-17456 | SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page. | EXPLOITCRITICAL 9.8EPSS 73.6% | 20 August 2020 |
| CVE-2020-23934 | An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section. | EXPLOIT ✓HIGH 8.8EPSS 16.0% | 18 August 2020 |
| CVE-2020-1472 | Microsoft Netlogon Privilege Escalation Vulnerability | KEVEXPLOITMEDIUM 5.5EPSS 99.4% | 17 August 2020 |
| CVE-2020-17506 | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. | EXPLOITCRITICAL 9.8EPSS 94.0% | 12 August 2020 |
| CVE-2020-2231 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure… | EXPLOITMEDIUM 5.4EPSS 5.30% | 12 August 2020 |
| CVE-2020-2230 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission. | EXPLOITMEDIUM 5.4EPSS 82.7% | 12 August 2020 |
| CVE-2020-2229 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability. | EXPLOITMEDIUM 5.4EPSS 6.77% | 12 August 2020 |
| CVE-2020-13151 | Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. | EXPLOITCRITICAL 9.8EPSS 86.7% | 5 August 2020 |
| CVE-2020-15956 | ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload. | EXPLOITHIGH 7.5EPSS 16.2% | 4 August 2020 |
| CVE-2020-5377 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. | EXPLOITCRITICAL 9.1EPSS 48.3% | 28 July 2020 |
| CVE-2020-15922 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. | EXPLOITCRITICAL 9.8EPSS 57.3% | 24 July 2020 |
| CVE-2020-15921 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. | EXPLOITCRITICAL 9.8EPSS 18.3% | 24 July 2020 |
| CVE-2020-15920 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. | EXPLOITCRITICAL 9.8EPSS 98.2% | 24 July 2020 |
| CVE-2020-15492 | This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact. | EXPLOITCRITICAL 9.8EPSS 16.6% | 23 July 2020 |
| CVE-2020-3452 | Cisco ASA and FTD Read-Only Path Traversal Vulnerability | KEVEXPLOIT ×3HIGH 7.5EPSS 100.0% | 22 July 2020 |
| CVE-2020-6519 | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | EXPLOITMEDIUM 6.5EPSS 11.3% | 22 July 2020 |
| CVE-2020-6507 | Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | EXPLOITHIGH 8.8EPSS 19.1% | 22 July 2020 |
| CVE-2020-7680 | docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). | EXPLOITMEDIUM 6.1EPSS 4.50% | 20 July 2020 |
| CVE-2020-11978 | Apache Airflow Command Injection | KEVEXPLOITHIGH 8.8EPSS 99.2% | 17 July 2020 |
| CVE-2020-15718 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. | EXPLOITMEDIUM 6.1EPSS 6.35% | 15 July 2020 |
| CVE-2020-15716 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. | EXPLOITMEDIUM 6.1EPSS 5.56% | 15 July 2020 |
| CVE-2020-9496 | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 | EXPLOITMEDIUM 6.1EPSS 98.9% | 15 July 2020 |
| CVE-2020-1147 | Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability | KEVEXPLOIT ×2HIGH 7.8EPSS 94.0% | 14 July 2020 |
| CVE-2020-15050 | Remote attackers can read arbitrary files from the server via Directory Traversal. | EXPLOITHIGH 7.5EPSS 50.7% | 13 July 2020 |
| CVE-2020-11749 | Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. | EXPLOITCRITICAL 9.0EPSS 16.2% | 13 July 2020 |
| CVE-2020-15600 | An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. | EXPLOITMEDIUM 6.5EPSS 1.90% | 7 July 2020 |
| CVE-2020-15599 | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | EXPLOITMEDIUM 6.1EPSS 2.11% | 7 July 2020 |
| CVE-2020-8163 | The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. | EXPLOITHIGH 8.8EPSS 82.0% | 2 July 2020 |
| CVE-2020-15500 | The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS. | EXPLOITMEDIUM 6.1EPSS 12.2% | 1 July 2020 |
| CVE-2020-5902 | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability | KEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0% | 1 July 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.