Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 20 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-1498 | Cisco HyperFlex HX Data Platform Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 6 May 2021 |
| CVE-2021-1497 | Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 6 May 2021 |
| CVE-2021-21551 | Dell dbutil Driver Insufficient Access Control Vulnerability | KEVHIGH 7.8EPSS 79.2% | 4 May 2021 |
| CVE-2021-20090 | Arcadyan Buffalo Firmware Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 29 April 2021 |
| CVE-2021-21224 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 84.2% | 26 April 2021 |
| CVE-2021-21220 | Google Chromium V8 Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 70.4% | 26 April 2021 |
| CVE-2021-21206 | Google Chromium Blink Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 9.31% | 26 April 2021 |
| CVE-2021-22205 | GitLab Community and Enterprise Editions Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.7% | 23 April 2021 |
| CVE-2021-22204 | ExifTool Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 100.0% | 23 April 2021 |
| CVE-2021-22893 | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | KEVCRITICAL 10.0EPSS 47.2% | 23 April 2021 |
| CVE-2021-20023 | SonicWall Email Security Path Traversal Vulnerability | KEVMEDIUM 4.9EPSS 51.4% | 20 April 2021 |
| CVE-2021-3493 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 49.2% | 17 April 2021 |
| CVE-2020-2509 | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 33.4% | 17 April 2021 |
| CVE-2021-28310 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 8.33% | 13 April 2021 |
| CVE-2021-20022 | SonicWall Email Security Unrestricted Upload of File Vulnerability | KEVHIGH 7.2EPSS 16.5% | 9 April 2021 |
| CVE-2021-20021 | SonicWall Email Security Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 83.4% | 9 April 2021 |
| CVE-2021-1879 | Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 7.08% | 2 April 2021 |
| CVE-2021-1871 | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 7.00% | 2 April 2021 |
| CVE-2021-1870 | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 7.71% | 2 April 2021 |
| CVE-2021-1789 | Apple Multiple Products Type Confusion Vulnerability | KEVHIGH 8.8EPSS 14.5% | 2 April 2021 |
| CVE-2021-1782 | Apple Multiple Products Race Condition Vulnerability | KEVHIGH 7.0EPSS 2.22% | 2 April 2021 |
| CVE-2021-22991 | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | KEVCRITICAL 9.8EPSS 61.1% | 31 March 2021 |
| CVE-2021-21975 | VMware Server Side Request Forgery in vRealize Operations Manager API | KEVHIGH 7.5EPSS 78.3% | 31 March 2021 |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 31 March 2021 |
| CVE-2021-25372 | Samsung Mobile Devices Improper Boundary Check Vulnerability | KEVMEDIUM 6.7EPSS 0.80% | 26 March 2021 |
| CVE-2021-25371 | Samsung Mobile Devices Unspecified Vulnerability | KEVMEDIUM 6.7EPSS 0.80% | 26 March 2021 |
| CVE-2021-25370 | Samsung Mobile Devices Memory Corruption Vulnerability | KEVMEDIUM 4.4EPSS 0.89% | 26 March 2021 |
| CVE-2021-25369 | Samsung Mobile Devices Improper Access Control Vulnerability | KEVMEDIUM 5.5EPSS 1.12% | 26 March 2021 |
| CVE-2021-22506 | Micro Focus Access Manager Information Leakage Vulnerability | KEVHIGH 7.5EPSS 25.7% | 26 March 2021 |
| CVE-2021-21193 | Google Chromium Blink Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 9.87% | 16 March 2021 |
| CVE-2021-27085 | Microsoft Internet Explorer Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 5.45% | 11 March 2021 |
| CVE-2021-27059 | Microsoft Office Remote Code Execution Vulnerability | KEVHIGH 7.6EPSS 6.08% | 11 March 2021 |
| CVE-2021-26411 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 80.8% | 11 March 2021 |
| CVE-2021-21166 | Google Chromium Race Condition Vulnerability | KEVHIGH 8.8EPSS 26.7% | 9 March 2021 |
| CVE-2021-25337 | Samsung Mobile Devices Improper Access Control Vulnerability | KEVHIGH 7.1EPSS 2.81% | 4 March 2021 |
| CVE-2021-22681 | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | KEVCRITICAL 9.8EPSS 63.6% | 3 March 2021 |
| CVE-2021-27065 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.9% | 3 March 2021 |
| CVE-2021-26858 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 93.7% | 3 March 2021 |
| CVE-2021-26857 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 95.8% | 3 March 2021 |
| CVE-2021-26855 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 3 March 2021 |
| CVE-2021-27878 | Veritas Backup Exec Agent Command Execution Vulnerability | KEVHIGH 8.8EPSS 24.0% | 1 March 2021 |
| CVE-2021-27877 | Veritas Backup Exec Agent Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 64.9% | 1 March 2021 |
| CVE-2021-27876 | Veritas Backup Exec Agent File Access Vulnerability | KEVHIGH 8.1EPSS 13.5% | 1 March 2021 |
| CVE-2021-1732 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 78.4% | 25 February 2021 |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability | KEVMEDIUM 5.3EPSS 87.6% | 24 February 2021 |
| CVE-2021-21972 | VMware vCenter Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 24 February 2021 |
| CVE-2021-27104 | Accellion FTA OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 56.7% | 16 February 2021 |
| CVE-2021-27103 | Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability | KEVCRITICAL 9.8EPSS 11.4% | 16 February 2021 |
| CVE-2021-27102 | Accellion FTA OS Command Injection Vulnerability | KEVHIGH 7.8EPSS 3.65% | 16 February 2021 |
| CVE-2021-27101 | Accellion FTA SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 6.00% | 16 February 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.