SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 17 of 35

CVESummaryPriorityPublished
CVE-2022-23134Zabbix Frontend Improper Access Control VulnerabilityKEVMEDIUM 5.3EPSS 84.7%13 January 2022
CVE-2022-23131Zabbix Frontend Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 95.7%13 January 2022
CVE-2022-21919Microsoft Windows User Profile Service Privilege Escalation VulnerabilityKEVHIGH 7.0EPSS 2.97%11 January 2022
CVE-2022-21882Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 59.2%11 January 2022
CVE-2022-22265Samsung Mobile Devices Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.39%10 January 2022
CVE-2021-35247SolarWinds Serv-U Improper Input Validation VulnerabilityKEVMEDIUM 5.3EPSS 3.45%10 January 2022
CVE-2021-44168Fortinet FortiOS Arbitrary File DownloadKEVHIGH 7.8EPSS 0.87%4 January 2022
CVE-2021-44207Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability KEVHIGH 8.1EPSS 17.6%21 December 2021
CVE-2021-22054Omnissa Workspace ONE Server-Side Request ForgeryKEVHIGH 7.5EPSS 97.4%17 December 2021
CVE-2021-1048Android Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 1.04%15 December 2021
CVE-2021-0920Android Kernel Race Condition VulnerabilityKEVMEDIUM 6.4EPSS 0.85%15 December 2021
CVE-2021-43890Microsoft Windows AppX Installer Spoofing VulnerabilityKEVHIGH 7.1EPSS 10.3%15 December 2021
CVE-2021-43226Microsoft Windows Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 3.07%15 December 2021
CVE-2021-45046Apache Log4j2 Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.0EPSS 100.0%14 December 2021
CVE-2021-39935GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 7.5EPSS 35.6%13 December 2021
CVE-2021-44515Zoho Desktop Central Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.9%12 December 2021
CVE-2021-44228Apache Log4j2 Remote Code Execution VulnerabilityKEVCRITICAL 10.0EPSS 100.0%10 December 2021
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability KEVCRITICAL 9.8EPSS 99.1%8 December 2021
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploitKEVHIGH 8.8EPSS 39.8%8 December 2021
CVE-2021-20038SonicWall SMA 100 Appliances Stack-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 99.9%8 December 2021
CVE-2021-43798Grafana Path Traversal VulnerabilityKEVHIGH 7.5EPSS 88.5%7 December 2021
CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 83.6%3 December 2021
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 93.3%29 November 2021
CVE-2021-38003Google Chromium V8 Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 38.6%23 November 2021
CVE-2021-38000Google Chromium Intents Improper Input Validation VulnerabilityKEVMEDIUM 6.1EPSS 4.65%23 November 2021
CVE-2021-44026Roundcube Webmail SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 41.9%19 November 2021
CVE-2021-41277Metabase GeoJSON API Local File Inclusion VulnerabilityKEVHIGH 7.5EPSS 97.2%17 November 2021
CVE-2021-42321Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 91.7%10 November 2021
CVE-2021-42292Microsoft Excel Security Feature BypassKEVHIGH 7.8EPSS 43.0%10 November 2021
CVE-2021-42287Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityKEVHIGH 7.5EPSS 77.2%10 November 2021
CVE-2021-42278Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityKEVHIGH 7.5EPSS 73.3%10 November 2021
CVE-2021-41379Microsoft Windows Installer Privilege Escalation VulnerabilityKEVMEDIUM 5.5EPSS 19.5%10 November 2021
CVE-2021-42237Sitecore XP Remote Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.9%5 November 2021
CVE-2021-42258BQE BillQuick Web Suite SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 74.4%22 October 2021
CVE-2021-30807Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 28.8%19 October 2021
CVE-2021-27561Yealink Device Management Server-Side Request Forgery (SSRF) VulnerabilityKEVCRITICAL 9.8EPSS 82.9%15 October 2021
CVE-2021-20124Draytek VigorConnect Path Traversal Vulnerability KEVHIGH 7.5EPSS 96.3%13 October 2021
CVE-2021-20123Draytek VigorConnect Path Traversal Vulnerability KEVHIGH 7.5EPSS 90.2%13 October 2021
CVE-2021-41357Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 2.08%13 October 2021
CVE-2021-40450Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 2.08%13 October 2021
CVE-2021-40449Microsoft Windows Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 74.1%13 October 2021
CVE-2021-37976Google Chromium Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 19.7%8 October 2021
CVE-2021-37975Google Chromium V8 Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 34.9%8 October 2021
CVE-2021-37973Google Chromium Portals Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 11.6%8 October 2021
CVE-2021-30633Google Chromium Indexed DB API Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 32.7%8 October 2021
CVE-2021-30632Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 63.2%8 October 2021
CVE-2021-42013Apache HTTP Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%7 October 2021
CVE-2021-25489Samsung Mobile Devices Improper Input Validation VulnerabilityKEVMEDIUM 5.5EPSS 0.53%6 October 2021
CVE-2021-25487Samsung Mobile Devices Out-of-Bounds Read VulnerabilityKEVHIGH 7.8EPSS 0.64%6 October 2021
CVE-2021-39226Grafana Authentication Bypass VulnerabilityKEVHIGH 7.3EPSS 99.9%5 October 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.