Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 18 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-41773 | Apache HTTP Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 October 2021 |
| CVE-2021-20035 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | KEVMEDIUM 6.5EPSS 4.18% | 27 September 2021 |
| CVE-2021-40655 | D-Link DIR-605 Router Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 86.7% | 24 September 2021 |
| CVE-2021-22941 | Citrix ShareFile Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 53.6% | 23 September 2021 |
| CVE-2021-22017 | VMware vCenter Server Improper Access Control | KEVMEDIUM 5.3EPSS 49.2% | 23 September 2021 |
| CVE-2021-22005 | VMware vCenter Server File Upload Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 23 September 2021 |
| CVE-2021-36260 | Hikvision Improper Input Validation | KEVCRITICAL 9.8EPSS 99.9% | 22 September 2021 |
| CVE-2021-38406 | Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 76.4% | 17 September 2021 |
| CVE-2021-40438 | Apache HTTP Server-Side Request Forgery (SSRF) | KEVCRITICAL 9.0EPSS 100.0% | 16 September 2021 |
| CVE-2021-33045 | Dahua IP Camera Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 15 September 2021 |
| CVE-2021-33044 | Dahua IP Camera Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 15 September 2021 |
| CVE-2021-40444 | Microsoft MSHTML Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 97.5% | 15 September 2021 |
| CVE-2021-38649 | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 2.89% | 15 September 2021 |
| CVE-2021-38648 | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 11.4% | 15 September 2021 |
| CVE-2021-38647 | Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 15 September 2021 |
| CVE-2021-38646 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 7.99% | 15 September 2021 |
| CVE-2021-38645 | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.73% | 15 September 2021 |
| CVE-2021-36955 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.04% | 15 September 2021 |
| CVE-2021-38163 | SAP NetWeaver Unrestricted File Upload Vulnerability | KEVHIGH 8.8EPSS 36.0% | 14 September 2021 |
| CVE-2021-40870 | Aviatrix Controller Unrestricted Upload of File | KEVCRITICAL 9.8EPSS 93.0% | 13 September 2021 |
| CVE-2021-30713 | Apple macOS Unspecified Vulnerability | KEVHIGH 7.8EPSS 7.04% | 8 September 2021 |
| CVE-2021-30666 | Apple iOS WebKit Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 3.00% | 8 September 2021 |
| CVE-2021-30665 | Apple Multiple Products WebKit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 3.67% | 8 September 2021 |
| CVE-2021-30663 | Apple Multiple Products WebKit Integer Overflow Vulnerability | KEVHIGH 8.8EPSS 3.49% | 8 September 2021 |
| CVE-2021-30661 | Apple Multiple Products WebKit Storage Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 4.49% | 8 September 2021 |
| CVE-2021-30657 | Apple macOS Unspecified Vulnerability | KEVMEDIUM 5.5EPSS 68.5% | 8 September 2021 |
| CVE-2021-30762 | Apple iOS WebKit Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 11.0% | 8 September 2021 |
| CVE-2021-30761 | Apple iOS WebKit Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 10.5% | 8 September 2021 |
| CVE-2021-40539 | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 7 September 2021 |
| CVE-2021-28550 | Adobe Acrobat and Reader Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 52.0% | 2 September 2021 |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 1 September 2021 |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 30 August 2021 |
| CVE-2021-32648 | October CMS Improper Authentication | KEVCRITICAL 9.1EPSS 90.4% | 26 August 2021 |
| CVE-2021-31010 | Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability | KEVHIGH 7.5EPSS 3.67% | 24 August 2021 |
| CVE-2021-30983 | Apple iOS and iPadOS Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 2.92% | 24 August 2021 |
| CVE-2021-30952 | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | KEVHIGH 7.8EPSS 6.96% | 24 August 2021 |
| CVE-2021-30900 | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 5.20% | 24 August 2021 |
| CVE-2021-30883 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 14.7% | 24 August 2021 |
| CVE-2021-30869 | Apple iOS, iPadOS, and macOS Type Confusion Vulnerability | KEVHIGH 7.8EPSS 4.13% | 24 August 2021 |
| CVE-2021-30860 | Apple Multiple Products Integer Overflow Vulnerability | KEVHIGH 7.8EPSS 76.0% | 24 August 2021 |
| CVE-2021-30858 | Apple iOS, iPadOS, macOS Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 13.4% | 24 August 2021 |
| CVE-2021-39144 | XStream Remote Code Execution Vulnerability | KEVHIGH 8.5EPSS 98.1% | 23 August 2021 |
| CVE-2021-35395 | Realtek AP-Router SDK Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 16 August 2021 |
| CVE-2021-35394 | Realtek Jungle SDK Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 16 August 2021 |
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | KEVMEDIUM 5.3EPSS 100.0% | 16 August 2021 |
| CVE-2021-36380 | Sunhillo SureLine OS Command Injection Vulnerablity | KEVCRITICAL 9.8EPSS 97.6% | 13 August 2021 |
| CVE-2021-36948 | Microsoft Windows Update Medic Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 23.3% | 12 August 2021 |
| CVE-2021-36942 | Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability | KEVHIGH 7.5EPSS 66.0% | 12 August 2021 |
| CVE-2021-34486 | Microsoft Windows Event Tracing Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 9.25% | 12 August 2021 |
| CVE-2021-34484 | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 21.8% | 12 August 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.