SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

25,049 results · page 30 of 501

CVESummaryPriorityPublished
CVE-2020-0796Microsoft SMBv3 Remote Code Execution VulnerabilityKEVEXPLOIT ×3CRITICAL 10.0EPSS 99.8%12 March 2020
CVE-2020-10387Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.EXPLOITMEDIUM 4.9EPSS 7.84%12 March 2020
CVE-2020-10386admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.EXPLOITHIGH 7.2EPSS 12.3%12 March 2020
CVE-2012-1096NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.EXPLOITMEDIUM 5.5EPSS 0.71%10 March 2020
CVE-2020-10221rConfig OS Command Injection VulnerabilityKEVEXPLOITHIGH 8.8EPSS 80.2%8 March 2020
CVE-2020-10220The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.EXPLOIT ×2CRITICAL 9.8EPSS 99.7%7 March 2020
CVE-2020-10189Zoho ManageEngine Desktop Central File Upload VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%6 March 2020
CVE-2020-10173Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.EXPLOITHIGH 8.8EPSS 77.1%5 March 2020
CVE-2019-20501D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip…EXPLOITHIGH 7.8EPSS 90.5%5 March 2020
CVE-2019-20500D-Link DWL-2600AP Access Point Command Injection VulnerabilityKEVEXPLOITHIGH 7.8EPSS 97.1%5 March 2020
CVE-2019-20499D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or…EXPLOIT ×2HIGH 7.8EPSS 95.3%5 March 2020
CVE-2020-9372The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in…EXPLOITHIGH 7.8EPSS 8.61%4 March 2020
CVE-2020-9371Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress.EXPLOITMEDIUM 4.8EPSS 3.30%4 March 2020
CVE-2020-8778Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.EXPLOITMEDIUM 5.4EPSS 2.62%2 March 2020
CVE-2020-8777Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.EXPLOITMEDIUM 5.4EPSS 3.17%2 March 2020
CVE-2020-8776Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.EXPLOITMEDIUM 5.4EPSS 2.68%2 March 2020
CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion VulnerabilityKEVEXPLOITHIGH 8.8EPSS 46.3%2 March 2020
CVE-2020-6418Google Chromium V8 Type Confusion VulnerabilityKEVEXPLOITHIGH 8.8EPSS 78.8%27 February 2020
CVE-2020-3837Apple Multiple Products Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.8EPSS 16.1%27 February 2020
CVE-2017-6371Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.EXPLOITHIGH 7.5EPSS 4.68%27 February 2020
CVE-2015-0565NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.EXPLOIT ×2CRITICAL 10.0EPSS 13.6%25 February 2020
CVE-2019-3999Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.EXPLOITHIGH 7.8EPSS 8.57%25 February 2020
CVE-2020-8794OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.EXPLOIT ×2CRITICAL 9.8EPSS 88.9%25 February 2020
CVE-2020-8793OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.EXPLOITMEDIUM 4.7EPSS 0.90%25 February 2020
CVE-2020-8819Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order…EXPLOITHIGH 8.1EPSS 4.88%25 February 2020
CVE-2020-1938Apache Tomcat Improper Privilege Management VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.3%24 February 2020
CVE-2020-9374On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.EXPLOITCRITICAL 9.8EPSS 42.7%24 February 2020
CVE-2020-8813graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.EXPLOIT ×2HIGH 8.8EPSS 74.0%22 February 2020
CVE-2020-9283golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package.EXPLOITHIGH 7.5EPSS 20.5%20 February 2020
CVE-2014-4019ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.EXPLOITHIGH 7.5EPSS 12.7%20 February 2020
CVE-2012-3351Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for…EXPLOITMEDIUM 6.1EPSS 2.58%20 February 2020
CVE-2012-2599Reason: This issue was MERGED into CVE-2012-3835 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions.EXPLOIT ×2UnscoredEPSS —20 February 2020
CVE-2014-4650The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended…EXPLOITCRITICAL 9.8EPSS 24.7%20 February 2020
CVE-2014-7951Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a ..EXPLOITMEDIUM 4.6EPSS 1.08%20 February 2020
CVE-2012-2629Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew…EXPLOITHIGH 8.8EPSS 2.26%20 February 2020
CVE-2014-9613Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.EXPLOITCRITICAL 9.8EPSS 4.06%19 February 2020
CVE-2014-9612SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.EXPLOITCRITICAL 9.8EPSS 4.87%19 February 2020
CVE-2012-0055OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.EXPLOITHIGH 7.8EPSS 1.24%19 February 2020
CVE-2013-5581Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —19 February 2020
CVE-2015-7567SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.EXPLOITCRITICAL 9.8EPSS 3.67%18 February 2020
CVE-2013-2679Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5)…EXPLOIT ×3MEDIUM 6.1EPSS 19.6%18 February 2020
CVE-2015-6970The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.EXPLOITCRITICAL 9.8EPSS 5.35%18 February 2020
CVE-2020-8012CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component.EXPLOITCRITICAL 9.8EPSS 77.4%18 February 2020
CVE-2014-7236Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.EXPLOITCRITICAL 9.1EPSS 55.6%17 February 2020
CVE-2014-1947Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image,…EXPLOITHIGH 7.8EPSS 7.02%17 February 2020
CVE-2015-6922Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an…EXPLOIT ×2CRITICAL 9.8EPSS 82.1%17 February 2020
CVE-2020-9038Joplin through 1.0.184 allows Arbitrary File Read via XSS.EXPLOITMEDIUM 5.4EPSS 3.57%17 February 2020
CVE-2020-8518Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.EXPLOITCRITICAL 9.8EPSS 71.7%17 February 2020
CVE-2013-4211A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP codeEXPLOITCRITICAL 9.8EPSS 70.7%14 February 2020
CVE-2015-6589Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary…EXPLOIT ×2HIGH 8.8EPSS 13.6%13 February 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.