Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,014 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 19 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-20028 | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 30.1% | 4 August 2021 |
| CVE-2021-30563 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 8.93% | 3 August 2021 |
| CVE-2021-26085 | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | KEVMEDIUM 5.3EPSS 99.9% | 3 August 2021 |
| CVE-2021-36742 | Trend Micro Multiple Products Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 1.48% | 29 July 2021 |
| CVE-2021-36741 | Trend Micro Multiple Products Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 4.95% | 29 July 2021 |
| CVE-2021-35464 | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 22 July 2021 |
| CVE-2021-36934 | Microsoft Windows SAM Local Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 67.3% | 22 July 2021 |
| CVE-2021-34448 | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | KEVMEDIUM 6.8EPSS 40.1% | 16 July 2021 |
| CVE-2021-35211 | SolarWinds Serv-U Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 91.2% | 14 July 2021 |
| CVE-2021-34523 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVCRITICAL 9.0EPSS 100.0% | 14 July 2021 |
| CVE-2021-34473 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 14 July 2021 |
| CVE-2021-33771 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 10.2% | 14 July 2021 |
| CVE-2021-33766 | Microsoft Exchange Server Information Disclosure | KEVHIGH 7.3EPSS 98.1% | 14 July 2021 |
| CVE-2021-31979 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.54% | 14 July 2021 |
| CVE-2021-31196 | Microsoft Exchange Server Information Disclosure Vulnerability | KEVHIGH 7.2EPSS 54.1% | 14 July 2021 |
| CVE-2021-30116 | Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability | KEVCRITICAL 9.8EPSS 85.7% | 9 July 2021 |
| CVE-2021-22555 | Linux Kernel Heap Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 78.7% | 7 July 2021 |
| CVE-2021-34527 | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.8% | 2 July 2021 |
| CVE-2021-30554 | Google Chromium WebGL Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 7.37% | 2 July 2021 |
| CVE-2021-30551 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 64.7% | 15 June 2021 |
| CVE-2021-22175 | GitLab Server-Side Request Forgery (SSRF) Vulnerability | KEVCRITICAL 9.8EPSS 53.4% | 11 June 2021 |
| CVE-2021-25395 | Samsung Mobile Devices Race Condition Vulnerability | KEVMEDIUM 6.4EPSS 0.37% | 11 June 2021 |
| CVE-2021-25394 | Samsung Mobile Devices Race Condition Vulnerability | KEVMEDIUM 6.4EPSS 0.40% | 11 June 2021 |
| CVE-2021-26829 | OpenPLC ScadaBR Cross-site Scripting Vulnerability | KEVMEDIUM 5.4EPSS 48.0% | 11 June 2021 |
| CVE-2021-26828 | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | KEVHIGH 8.8EPSS 39.4% | 11 June 2021 |
| CVE-2020-11261 | Qualcomm Multiple Chipsets Improper Input Validation Vulnerability | KEVHIGH 7.8EPSS 1.77% | 9 June 2021 |
| CVE-2021-33742 | Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 59.4% | 8 June 2021 |
| CVE-2021-33739 | Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | KEVHIGH 8.4EPSS 6.55% | 8 June 2021 |
| CVE-2021-31956 | Microsoft Windows NTFS Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 22.3% | 8 June 2021 |
| CVE-2021-31955 | Microsoft Windows Kernel Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 81.1% | 8 June 2021 |
| CVE-2021-31201 | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | KEVMEDIUM 5.2EPSS 2.62% | 8 June 2021 |
| CVE-2021-31199 | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | KEVMEDIUM 5.2EPSS 2.95% | 8 June 2021 |
| CVE-2021-1675 | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 86.1% | 8 June 2021 |
| CVE-2021-30533 | Google Chromium PopupBlocker Security Bypass Vulnerability | KEVMEDIUM 6.5EPSS 16.6% | 7 June 2021 |
| CVE-2021-27852 | Checkbox Survey Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 31.9% | 27 May 2021 |
| CVE-2021-22900 | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | KEVHIGH 7.2EPSS 14.1% | 27 May 2021 |
| CVE-2021-22899 | Ivanti Pulse Connect Secure Command Injection Vulnerability | KEVHIGH 8.8EPSS 22.9% | 27 May 2021 |
| CVE-2021-22894 | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 41.3% | 27 May 2021 |
| CVE-2021-21985 | VMware vCenter Server Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 26 May 2021 |
| CVE-2021-27562 | Arm Trusted Firmware Out-of-Bounds Write Vulnerability | KEVMEDIUM 5.5EPSS 3.09% | 25 May 2021 |
| CVE-2021-29256 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 2.99% | 24 May 2021 |
| CVE-2021-28799 | QNAP NAS Improper Authorization Vulnerability | KEVCRITICAL 9.8EPSS 78.3% | 13 May 2021 |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | KEVMEDIUM 6.6EPSS 99.8% | 11 May 2021 |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 11 May 2021 |
| CVE-2021-28664 | Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability | KEVHIGH 8.8EPSS 5.41% | 10 May 2021 |
| CVE-2021-28663 | Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 12.1% | 10 May 2021 |
| CVE-2021-31755 | Tenda AC11 Router Stack Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 86.9% | 7 May 2021 |
| CVE-2021-1906 | Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability | KEVMEDIUM 5.5EPSS 0.52% | 7 May 2021 |
| CVE-2021-1905 | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 1.54% | 7 May 2021 |
| CVE-2021-32030 | ASUS Routers Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 6 May 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.