SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 18 of 35

CVESummaryPriorityPublished
CVE-2021-41773Apache HTTP Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%5 October 2021
CVE-2021-20035SonicWall SMA100 Appliances OS Command Injection VulnerabilityKEVMEDIUM 6.5EPSS 4.18%27 September 2021
CVE-2021-40655D-Link DIR-605 Router Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 86.7%24 September 2021
CVE-2021-22941Citrix ShareFile Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 53.6%23 September 2021
CVE-2021-22017VMware vCenter Server Improper Access ControlKEVMEDIUM 5.3EPSS 49.2%23 September 2021
CVE-2021-22005VMware vCenter Server File Upload VulnerabilityKEVCRITICAL 9.8EPSS 100.0%23 September 2021
CVE-2021-36260Hikvision Improper Input ValidationKEVCRITICAL 9.8EPSS 99.9%22 September 2021
CVE-2021-38406Delta Electronics DOPSoft 2 Improper Input Validation VulnerabilityKEVHIGH 7.8EPSS 76.4%17 September 2021
CVE-2021-40438Apache HTTP Server-Side Request Forgery (SSRF)KEVCRITICAL 9.0EPSS 100.0%16 September 2021
CVE-2021-33045Dahua IP Camera Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.6%15 September 2021
CVE-2021-33044Dahua IP Camera Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.9%15 September 2021
CVE-2021-40444Microsoft MSHTML Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 97.5%15 September 2021
CVE-2021-38649Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityKEVHIGH 7.0EPSS 2.89%15 September 2021
CVE-2021-38648Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 11.4%15 September 2021
CVE-2021-38647Microsoft Open Management Infrastructure (OMI) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%15 September 2021
CVE-2021-38646Microsoft Office Access Connectivity Engine Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 7.99%15 September 2021
CVE-2021-38645Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 2.73%15 September 2021
CVE-2021-36955Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 4.04%15 September 2021
CVE-2021-38163SAP NetWeaver Unrestricted File Upload VulnerabilityKEVHIGH 8.8EPSS 36.0%14 September 2021
CVE-2021-40870Aviatrix Controller Unrestricted Upload of FileKEVCRITICAL 9.8EPSS 93.0%13 September 2021
CVE-2021-30713Apple macOS Unspecified VulnerabilityKEVHIGH 7.8EPSS 7.04%8 September 2021
CVE-2021-30666Apple iOS WebKit Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 3.00%8 September 2021
CVE-2021-30665Apple Multiple Products WebKit Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 3.67%8 September 2021
CVE-2021-30663Apple Multiple Products WebKit Integer Overflow VulnerabilityKEVHIGH 8.8EPSS 3.49%8 September 2021
CVE-2021-30661Apple Multiple Products WebKit Storage Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 4.49%8 September 2021
CVE-2021-30657Apple macOS Unspecified VulnerabilityKEVMEDIUM 5.5EPSS 68.5%8 September 2021
CVE-2021-30762Apple iOS WebKit Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 11.0%8 September 2021
CVE-2021-30761Apple iOS WebKit Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 10.5%8 September 2021
CVE-2021-40539Zoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.0%7 September 2021
CVE-2021-28550Adobe Acrobat and Reader Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 52.0%2 September 2021
CVE-2021-37415Zoho ManageEngine ServiceDesk Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.8%1 September 2021
CVE-2021-26084Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%30 August 2021
CVE-2021-32648October CMS Improper AuthenticationKEVCRITICAL 9.1EPSS 90.4%26 August 2021
CVE-2021-31010Apple iOS, macOS, watchOS Sandbox Bypass VulnerabilityKEVHIGH 7.5EPSS 3.67%24 August 2021
CVE-2021-30983Apple iOS and iPadOS Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 2.92%24 August 2021
CVE-2021-30952Apple Multiple Products Integer Overflow or Wraparound VulnerabilityKEVHIGH 7.8EPSS 6.96%24 August 2021
CVE-2021-30900Apple iOS, iPadOS, and macOS Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 5.20%24 August 2021
CVE-2021-30883Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 14.7%24 August 2021
CVE-2021-30869Apple iOS, iPadOS, and macOS Type Confusion VulnerabilityKEVHIGH 7.8EPSS 4.13%24 August 2021
CVE-2021-30860Apple Multiple Products Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 76.0%24 August 2021
CVE-2021-30858Apple iOS, iPadOS, macOS Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 13.4%24 August 2021
CVE-2021-39144XStream Remote Code Execution VulnerabilityKEVHIGH 8.5EPSS 98.1%23 August 2021
CVE-2021-35395Realtek AP-Router SDK Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 98.0%16 August 2021
CVE-2021-35394Realtek Jungle SDK Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%16 August 2021
CVE-2021-26086Atlassian Jira Server and Data Center Path Traversal VulnerabilityKEVMEDIUM 5.3EPSS 100.0%16 August 2021
CVE-2021-36380Sunhillo SureLine OS Command Injection VulnerablityKEVCRITICAL 9.8EPSS 97.6%13 August 2021
CVE-2021-36948Microsoft Windows Update Medic Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 23.3%12 August 2021
CVE-2021-36942Microsoft Windows Local Security Authority (LSA) Spoofing VulnerabilityKEVHIGH 7.5EPSS 66.0%12 August 2021
CVE-2021-34486Microsoft Windows Event Tracing Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 9.25%12 August 2021
CVE-2021-34484Microsoft Windows User Profile Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 21.8%12 August 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.