Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 29 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0235 | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. | EXPLOITHIGH 8.8EPSS 32.7% | 30 April 2020 |
| CVE-2020-11652 | SaltStack Salt Path Traversal Vulnerability | KEVEXPLOITMEDIUM 6.5EPSS 86.2% | 30 April 2020 |
| CVE-2020-11651 | SaltStack Salt Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 96.6% | 30 April 2020 |
| CVE-2020-6010 | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | EXPLOITHIGH 8.8EPSS 49.2% | 30 April 2020 |
| CVE-2020-11022 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. | EXPLOITMEDIUM 6.1EPSS 99.2% | 29 April 2020 |
| CVE-2020-11023 | JQuery Cross-Site Scripting (XSS) Vulnerability | KEVEXPLOITMEDIUM 6.1EPSS 84.9% | 29 April 2020 |
| CVE-2020-12261 | Open-AudIT 3.3.0 allows an XSS attack after login. | EXPLOITMEDIUM 5.4EPSS 2.59% | 28 April 2020 |
| CVE-2020-12242 | Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account. | EXPLOITHIGH 7.8EPSS 1.09% | 27 April 2020 |
| CVE-2019-15794 | Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. | EXPLOIT ✓MEDIUM 6.7EPSS 1.16% | 24 April 2020 |
| CVE-2019-15793 | A local attacker could use this to possibly bypass discretionary access control permissions. | EXPLOIT ✓HIGH 8.8EPSS 0.69% | 24 April 2020 |
| CVE-2019-15792 | As the private_data is not required to be a pointer, an attacker can use this to cause a denial of service or possibly execute arbitrary code. | EXPLOIT ✓HIGH 7.8EPSS 1.10% | 24 April 2020 |
| CVE-2019-15791 | In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. | EXPLOIT ✓HIGH 7.8EPSS 1.32% | 24 April 2020 |
| CVE-2019-17525 | The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. | EXPLOITHIGH 8.8EPSS 5.84% | 21 April 2020 |
| CVE-2020-11819 | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. | EXPLOIT ×2CRITICAL 9.8EPSS 26.8% | 16 April 2020 |
| CVE-2020-3161 | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 83.9% | 15 April 2020 |
| CVE-2020-2944 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). | EXPLOITHIGH 8.8EPSS 1.80% | 15 April 2020 |
| CVE-2020-11738 | WordPress Snap Creek Duplicator Plugin File Download Vulnerability | KEVEXPLOITHIGH 7.5EPSS 97.8% | 13 April 2020 |
| CVE-2020-5330 | Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure… | EXPLOITHIGH 7.5EPSS 13.3% | 10 April 2020 |
| CVE-2020-3952 | VMware vCenter Server Information Disclosure Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 90.4% | 10 April 2020 |
| CVE-2020-5735 | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability | KEVEXPLOITHIGH 8.8EPSS 36.2% | 8 April 2020 |
| CVE-2020-11560 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. | EXPLOITHIGH 7.8EPSS 1.00% | 7 April 2020 |
| CVE-2020-8639 | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | EXPLOITHIGH 8.8EPSS 15.9% | 3 April 2020 |
| CVE-2020-11107 | An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution. | EXPLOITHIGH 8.8EPSS 22.5% | 2 April 2020 |
| CVE-2020-10199 | Sonatype Nexus Repository Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 99.1% | 1 April 2020 |
| CVE-2020-11457 | pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user. | EXPLOITMEDIUM 5.4EPSS 9.28% | 1 April 2020 |
| CVE-2020-11456 | LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups). | EXPLOITMEDIUM 5.4EPSS 70.8% | 1 April 2020 |
| CVE-2020-11455 | LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. | EXPLOIT ✓CRITICAL 9.8EPSS 97.2% | 1 April 2020 |
| CVE-2020-5726 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. | EXPLOITHIGH 7.5EPSS 4.33% | 30 March 2020 |
| CVE-2020-9467 | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. | EXPLOITMEDIUM 5.4EPSS 23.8% | 26 March 2020 |
| CVE-2020-10963 | FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. | EXPLOITHIGH 7.2EPSS 14.7% | 25 March 2020 |
| CVE-2020-10884 | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. | EXPLOIT ✓HIGH 8.8EPSS 26.5% | 25 March 2020 |
| CVE-2020-10883 | This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. | EXPLOIT ✓HIGH 7.8EPSS 5.96% | 25 March 2020 |
| CVE-2020-10882 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. | EXPLOIT ✓HIGH 8.8EPSS 41.4% | 25 March 2020 |
| CVE-2020-9375 | 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field. | EXPLOITHIGH 7.5EPSS 26.7% | 25 March 2020 |
| CVE-2020-10385 | A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. | EXPLOITMEDIUM 5.4EPSS 4.43% | 24 March 2020 |
| CVE-2020-10879 | rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped. | EXPLOITCRITICAL 9.8EPSS 83.9% | 23 March 2020 |
| CVE-2020-8866 | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. | EXPLOIT ×2MEDIUM 6.5EPSS 9.58% | 23 March 2020 |
| CVE-2020-8865 | This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. | EXPLOIT ×2MEDIUM 6.3EPSS 6.81% | 23 March 2020 |
| CVE-2020-5722 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 84.4% | 23 March 2020 |
| CVE-2020-7961 | Liferay Portal Deserialization of Untrusted Data Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 99.9% | 20 March 2020 |
| CVE-2019-16072 | An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within… | EXPLOITCRITICAL 9.8EPSS 25.9% | 20 March 2020 |
| CVE-2019-16068 | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. | EXPLOITHIGH 8.8EPSS 0.95% | 19 March 2020 |
| CVE-2019-16065 | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially… | EXPLOITHIGH 8.8EPSS 2.81% | 19 March 2020 |
| CVE-2020-3950 | VMware Multiple Products Privilege Escalation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 7.25% | 17 March 2020 |
| CVE-2020-10596 | OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section. | EXPLOITMEDIUM 5.4EPSS 2.67% | 17 March 2020 |
| CVE-2020-5849 | Unraid Authentication Bypass Vulnerability | KEVEXPLOIT ✓HIGH 7.5EPSS 93.2% | 16 March 2020 |
| CVE-2020-5847 | Unraid Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 95.8% | 16 March 2020 |
| CVE-2020-5844 | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. | EXPLOITHIGH 7.2EPSS 30.3% | 16 March 2020 |
| CVE-2020-10230 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter. | EXPLOITCRITICAL 9.8EPSS 14.7% | 16 March 2020 |
| CVE-2019-19208 | Codiad Web IDE through 2.8.4 allows PHP Code injection. | EXPLOITCRITICAL 9.8EPSS 19.2% | 16 March 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.