Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 17 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2022-23134 | Zabbix Frontend Improper Access Control Vulnerability | KEVMEDIUM 5.3EPSS 84.7% | 13 January 2022 |
| CVE-2022-23131 | Zabbix Frontend Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 95.7% | 13 January 2022 |
| CVE-2022-21919 | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 2.97% | 11 January 2022 |
| CVE-2022-21882 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 59.2% | 11 January 2022 |
| CVE-2022-22265 | Samsung Mobile Devices Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.39% | 10 January 2022 |
| CVE-2021-35247 | SolarWinds Serv-U Improper Input Validation Vulnerability | KEVMEDIUM 5.3EPSS 3.45% | 10 January 2022 |
| CVE-2021-44168 | Fortinet FortiOS Arbitrary File Download | KEVHIGH 7.8EPSS 0.87% | 4 January 2022 |
| CVE-2021-44207 | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | KEVHIGH 8.1EPSS 17.6% | 21 December 2021 |
| CVE-2021-22054 | Omnissa Workspace ONE Server-Side Request Forgery | KEVHIGH 7.5EPSS 97.4% | 17 December 2021 |
| CVE-2021-1048 | Android Kernel Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.04% | 15 December 2021 |
| CVE-2021-0920 | Android Kernel Race Condition Vulnerability | KEVMEDIUM 6.4EPSS 0.85% | 15 December 2021 |
| CVE-2021-43890 | Microsoft Windows AppX Installer Spoofing Vulnerability | KEVHIGH 7.1EPSS 10.3% | 15 December 2021 |
| CVE-2021-43226 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.07% | 15 December 2021 |
| CVE-2021-45046 | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.0EPSS 100.0% | 14 December 2021 |
| CVE-2021-39935 | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 7.5EPSS 35.6% | 13 December 2021 |
| CVE-2021-44515 | Zoho Desktop Central Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 12 December 2021 |
| CVE-2021-44228 | Apache Log4j2 Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 10 December 2021 |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.1% | 8 December 2021 |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | KEVHIGH 8.8EPSS 39.8% | 8 December 2021 |
| CVE-2021-20038 | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 8 December 2021 |
| CVE-2021-43798 | Grafana Path Traversal Vulnerability | KEVHIGH 7.5EPSS 88.5% | 7 December 2021 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 83.6% | 3 December 2021 |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 93.3% | 29 November 2021 |
| CVE-2021-38003 | Google Chromium V8 Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 38.6% | 23 November 2021 |
| CVE-2021-38000 | Google Chromium Intents Improper Input Validation Vulnerability | KEVMEDIUM 6.1EPSS 4.65% | 23 November 2021 |
| CVE-2021-44026 | Roundcube Webmail SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 41.9% | 19 November 2021 |
| CVE-2021-41277 | Metabase GeoJSON API Local File Inclusion Vulnerability | KEVHIGH 7.5EPSS 97.2% | 17 November 2021 |
| CVE-2021-42321 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 91.7% | 10 November 2021 |
| CVE-2021-42292 | Microsoft Excel Security Feature Bypass | KEVHIGH 7.8EPSS 43.0% | 10 November 2021 |
| CVE-2021-42287 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 7.5EPSS 77.2% | 10 November 2021 |
| CVE-2021-42278 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 7.5EPSS 73.3% | 10 November 2021 |
| CVE-2021-41379 | Microsoft Windows Installer Privilege Escalation Vulnerability | KEVMEDIUM 5.5EPSS 19.5% | 10 November 2021 |
| CVE-2021-42237 | Sitecore XP Remote Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 5 November 2021 |
| CVE-2021-42258 | BQE BillQuick Web Suite SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 74.4% | 22 October 2021 |
| CVE-2021-30807 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 28.8% | 19 October 2021 |
| CVE-2021-27561 | Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability | KEVCRITICAL 9.8EPSS 82.9% | 15 October 2021 |
| CVE-2021-20124 | Draytek VigorConnect Path Traversal Vulnerability | KEVHIGH 7.5EPSS 96.3% | 13 October 2021 |
| CVE-2021-20123 | Draytek VigorConnect Path Traversal Vulnerability | KEVHIGH 7.5EPSS 90.2% | 13 October 2021 |
| CVE-2021-41357 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.08% | 13 October 2021 |
| CVE-2021-40450 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.08% | 13 October 2021 |
| CVE-2021-40449 | Microsoft Windows Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 74.1% | 13 October 2021 |
| CVE-2021-37976 | Google Chromium Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 19.7% | 8 October 2021 |
| CVE-2021-37975 | Google Chromium V8 Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 34.9% | 8 October 2021 |
| CVE-2021-37973 | Google Chromium Portals Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 11.6% | 8 October 2021 |
| CVE-2021-30633 | Google Chromium Indexed DB API Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 32.7% | 8 October 2021 |
| CVE-2021-30632 | Google Chromium V8 Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 63.2% | 8 October 2021 |
| CVE-2021-42013 | Apache HTTP Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 7 October 2021 |
| CVE-2021-25489 | Samsung Mobile Devices Improper Input Validation Vulnerability | KEVMEDIUM 5.5EPSS 0.53% | 6 October 2021 |
| CVE-2021-25487 | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | KEVHIGH 7.8EPSS 0.64% | 6 October 2021 |
| CVE-2021-39226 | Grafana Authentication Bypass Vulnerability | KEVHIGH 7.3EPSS 99.9% | 5 October 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.