SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 28 of 501

CVESummaryPriorityPublished
CVE-2020-15478The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.EXPLOITHIGH 7.5EPSS 4.69%1 July 2020
CVE-2020-15468Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.EXPLOITCRITICAL 9.8EPSS 2.73%1 July 2020
CVE-2020-14166The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS)…EXPLOITMEDIUM 4.8EPSS 1.94%1 July 2020
CVE-2020-14947OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.EXPLOITHIGH 8.8EPSS 19.5%30 June 2020
CVE-2020-15364The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.EXPLOITMEDIUM 6.1EPSS 3.73%28 June 2020
CVE-2020-15363The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.EXPLOITCRITICAL 9.8EPSS 5.90%28 June 2020
CVE-2020-15046The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users.EXPLOIT ×2HIGH 8.8EPSS 2.30%24 June 2020
CVE-2020-15038The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.EXPLOITMEDIUM 5.4EPSS 3.76%24 June 2020
CVE-2020-14073XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties.EXPLOITMEDIUM 5.4EPSS 2.86%23 June 2020
CVE-2020-14946downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files.EXPLOITMEDIUM 4.3EPSS 7.70%22 June 2020
CVE-2020-14945A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user to escalate their privileges to administrator rights (i.e., the BankAdmin role) via modified SaveUser…EXPLOITHIGH 8.8EPSS 11.4%22 June 2020
CVE-2020-14944This can allow for manipulation and takeover of user accounts if successfully exploited.EXPLOITCRITICAL 9.8EPSS 6.34%22 June 2020
CVE-2020-14943The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Update User Profile.EXPLOITMEDIUM 5.4EPSS 3.68%22 June 2020
CVE-2020-14461Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.EXPLOITHIGH 8.6EPSS 9.54%22 June 2020
CVE-2020-14930Account takeover can occur because the password-reset feature discloses the verification token.EXPLOITHIGH 8.1EPSS 3.36%19 June 2020
CVE-2020-14295A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.EXPLOITHIGH 7.2EPSS 86.3%17 June 2020
CVE-2020-14011This allows command execution via the Add New Package and Scheduled Deployments features.EXPLOITCRITICAL 9.8EPSS 29.5%15 June 2020
CVE-2020-12712A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.EXPLOITHIGH 7.5EPSS 7.84%11 June 2020
CVE-2020-11798A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to…EXPLOITMEDIUM 5.3EPSS 48.8%10 June 2020
CVE-2020-13160AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.EXPLOITCRITICAL 9.8EPSS 80.6%9 June 2020
CVE-2020-13866WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.EXPLOITHIGH 7.8EPSS 1.07%8 June 2020
CVE-2020-7030A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component.EXPLOITMEDIUM 5.5EPSS 1.04%4 June 2020
CVE-2020-5295In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server.EXPLOITMEDIUM 4.9EPSS 7.37%3 June 2020
CVE-2020-13379The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue.EXPLOITHIGH 8.2EPSS 99.9%3 June 2020
CVE-2020-7115The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass.EXPLOITCRITICAL 9.8EPSS 64.6%3 June 2020
CVE-2020-13228There is reflected XSS via the /scgi sid parameter.EXPLOITMEDIUM 6.1EPSS 3.08%2 June 2020
CVE-2020-13448QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.EXPLOITHIGH 8.8EPSS 17.4%1 June 2020
CVE-2020-8816Pi-Hole AdminLTE Remote Code Execution VulnerabilityKEVEXPLOITHIGH 7.2EPSS 78.2%29 May 2020
CVE-2020-13693An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.EXPLOITCRITICAL 9.8EPSS 43.9%29 May 2020
CVE-2020-8605A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations.EXPLOITHIGH 8.8EPSS 87.8%27 May 2020
CVE-2020-5752Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.EXPLOIT ×2HIGH 7.8EPSS 8.61%21 May 2020
CVE-2020-3956VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability.EXPLOITHIGH 8.8EPSS 21.1%20 May 2020
CVE-2020-13152A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time, eventually allows attackers to cause a denial of…EXPLOITMEDIUM 5.5EPSS 3.43%20 May 2020
CVE-2020-7656jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.EXPLOITMEDIUM 6.1EPSS 6.27%19 May 2020
CVE-2020-13166The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.EXPLOITCRITICAL 9.8EPSS 77.6%19 May 2020
CVE-2020-8617Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server.EXPLOITMEDIUM 5.9EPSS 93.4%19 May 2020
CVE-2020-13144Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and…EXPLOITHIGH 8.8EPSS 11.0%18 May 2020
CVE-2020-13118SQL Injection exists in check_community.php via the parameter community.EXPLOITCRITICAL 9.8EPSS 3.96%16 May 2020
CVE-2020-12882Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.EXPLOITMEDIUM 5.4EPSS 1.20%15 May 2020
CVE-2019-15083Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator.EXPLOITMEDIUM 6.1EPSS 6.30%14 May 2020
CVE-2019-16112TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.EXPLOITHIGH 8.8EPSS 11.4%13 May 2020
CVE-2020-11060In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality.EXPLOIT ×2HIGH 8.8EPSS 10.9%12 May 2020
CVE-2020-11108The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files.EXPLOIT ×4HIGH 8.8EPSS 78.3%11 May 2020
CVE-2020-11530A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin.EXPLOITCRITICAL 9.8EPSS 95.7%8 May 2020
CVE-2020-12707An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0.EXPLOITMEDIUM 6.1EPSS 1.23%7 May 2020
CVE-2020-12706Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.phpEXPLOITMEDIUM 5.4EPSS 2.90%7 May 2020
CVE-2020-12704UliCMS before 2020.2 has PageController stored XSS.EXPLOITMEDIUM 6.1EPSS 1.19%7 May 2020
CVE-2020-12608There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\.EXPLOITHIGH 7.8EPSS 22.4%7 May 2020
CVE-2020-3187A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read…EXPLOITCRITICAL 9.1EPSS 96.6%6 May 2020
CVE-2020-11027Access would be needed to the email account of the user by a malicious party for successful execution.EXPLOITHIGH 8.1EPSS 13.6%30 April 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.