SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 27 of 501

CVESummaryPriorityPublished
CVE-2020-13259A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.EXPLOITHIGH 8.8EPSS 4.66%16 September 2020
CVE-2020-25015A specific router allows changing the Wi-Fi password remotely.EXPLOITMEDIUM 6.5EPSS 3.10%16 September 2020
CVE-2020-25453There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.EXPLOITHIGH 8.8EPSS 6.28%15 September 2020
CVE-2019-0230Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.EXPLOITCRITICAL 9.8EPSS 97.4%14 September 2020
CVE-2020-25540ThinkAdmin v6 is affected by a directory traversal vulnerability.EXPLOITHIGH 7.5EPSS 75.3%14 September 2020
CVE-2020-2038An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges.EXPLOITHIGH 7.2EPSS 86.1%9 September 2020
CVE-2020-25213WordPress File Manager Plugin Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 97.3%9 September 2020
CVE-2020-24963An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.EXPLOITMEDIUM 5.4EPSS 1.85%4 September 2020
CVE-2020-14008Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.EXPLOITHIGH 7.2EPSS 40.1%4 September 2020
CVE-2020-24949Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).EXPLOITHIGH 8.8EPSS 67.5%3 September 2020
CVE-2020-14209Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution.EXPLOITHIGH 8.8EPSS 27.5%2 September 2020
CVE-2020-16602Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server.EXPLOITHIGH 8.1EPSS 5.99%2 September 2020
CVE-2020-23839A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a…EXPLOITMEDIUM 6.1EPSS 10.5%1 September 2020
CVE-2020-23835A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and…EXPLOITMEDIUM 6.1EPSS 2.29%1 September 2020
CVE-2020-24363TP-link TL-WA855RE Missing Authentication for Critical Function VulnerabilityKEVEXPLOITHIGH 8.8EPSS 20.7%31 August 2020
CVE-2020-24223Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.EXPLOITMEDIUM 6.1EPSS 14.6%30 August 2020
CVE-2020-23972In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the…EXPLOITHIGH 7.5EPSS 31.4%27 August 2020
CVE-2020-24609Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal…EXPLOIT ×2MEDIUM 6.1EPSS 9.81%25 August 2020
CVE-2020-24186A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.EXPLOIT ×2CRITICAL 10.0EPSS 94.6%24 August 2020
CVE-2020-23935Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".EXPLOITCRITICAL 9.8EPSS 15.9%20 August 2020
CVE-2020-17456SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.EXPLOITCRITICAL 9.8EPSS 73.6%20 August 2020
CVE-2020-23934An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.EXPLOITHIGH 8.8EPSS 16.0%18 August 2020
CVE-2020-1472Microsoft Netlogon Privilege Escalation VulnerabilityKEVEXPLOITMEDIUM 5.5EPSS 99.4%17 August 2020
CVE-2020-17506Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.EXPLOITCRITICAL 9.8EPSS 94.0%12 August 2020
CVE-2020-2231Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure…EXPLOITMEDIUM 5.4EPSS 5.30%12 August 2020
CVE-2020-2230Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.EXPLOITMEDIUM 5.4EPSS 82.7%12 August 2020
CVE-2020-2229Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.EXPLOITMEDIUM 5.4EPSS 6.77%12 August 2020
CVE-2020-13151Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query.EXPLOITCRITICAL 9.8EPSS 86.7%5 August 2020
CVE-2020-15956ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.EXPLOITHIGH 7.5EPSS 16.2%4 August 2020
CVE-2020-5377Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.EXPLOITCRITICAL 9.1EPSS 48.3%28 July 2020
CVE-2020-15922There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.EXPLOITCRITICAL 9.8EPSS 57.3%24 July 2020
CVE-2020-15921Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.EXPLOITCRITICAL 9.8EPSS 18.3%24 July 2020
CVE-2020-15920There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.EXPLOITCRITICAL 9.8EPSS 98.2%24 July 2020
CVE-2020-15492This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.EXPLOITCRITICAL 9.8EPSS 16.6%23 July 2020
CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal VulnerabilityKEVEXPLOIT ×3HIGH 7.5EPSS 100.0%22 July 2020
CVE-2020-6519Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.EXPLOITMEDIUM 6.5EPSS 11.3%22 July 2020
CVE-2020-6507Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.EXPLOITHIGH 8.8EPSS 19.1%22 July 2020
CVE-2020-7680docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS).EXPLOITMEDIUM 6.1EPSS 4.50%20 July 2020
CVE-2020-11978Apache Airflow Command InjectionKEVEXPLOITHIGH 8.8EPSS 99.2%17 July 2020
CVE-2020-15718RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script.EXPLOITMEDIUM 6.1EPSS 6.35%15 July 2020
CVE-2020-15716RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script.EXPLOITMEDIUM 6.1EPSS 5.56%15 July 2020
CVE-2020-9496XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03EXPLOITMEDIUM 6.1EPSS 98.9%15 July 2020
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 94.0%14 July 2020
CVE-2020-15050Remote attackers can read arbitrary files from the server via Directory Traversal.EXPLOITHIGH 7.5EPSS 50.7%13 July 2020
CVE-2020-11749Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views.EXPLOITCRITICAL 9.0EPSS 16.2%13 July 2020
CVE-2020-15600An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.EXPLOITMEDIUM 6.5EPSS 1.90%7 July 2020
CVE-2020-15599Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.EXPLOITMEDIUM 6.1EPSS 2.11%7 July 2020
CVE-2020-8163The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.EXPLOITHIGH 8.8EPSS 82.0%2 July 2020
CVE-2020-15500The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.EXPLOITMEDIUM 6.1EPSS 12.2%1 July 2020
CVE-2020-5902F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution VulnerabilityKEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0%1 July 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.