Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 21 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-21315 | System Information Library for Node.JS Command Injection | KEVHIGH 7.8EPSS 90.7% | 16 February 2021 |
| CVE-2021-25298 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 75.1% | 15 February 2021 |
| CVE-2021-25297 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 56.7% | 15 February 2021 |
| CVE-2021-25296 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 72.2% | 15 February 2021 |
| CVE-2021-21311 | Adminer Server-Side Request Forgery Vulnerability | KEVHIGH 7.2EPSS 90.5% | 11 February 2021 |
| CVE-2021-21017 | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 86.3% | 11 February 2021 |
| CVE-2021-23874 | McAfee Total Protection (MTP) Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 1.03% | 10 February 2021 |
| CVE-2021-21148 | Google Chromium V8 Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 20.0% | 9 February 2021 |
| CVE-2021-22502 | Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 8 February 2021 |
| CVE-2021-20016 | SonicWall SSLVPN SMA100 SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 40.0% | 4 February 2021 |
| CVE-2020-2506 | QNAP Helpdesk Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 1.98% | 3 February 2021 |
| CVE-2020-25506 | D-Link DNS-320 Device Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 2 February 2021 |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 54.3% | 29 January 2021 |
| CVE-2021-3156 | Sudo Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 100.0% | 26 January 2021 |
| CVE-2020-36193 | PEAR Archive_Tar Improper Link Resolution Vulnerability | KEVHIGH 7.5EPSS 70.6% | 18 January 2021 |
| CVE-2020-6572 | Google Chrome Media Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 10.6% | 14 January 2021 |
| CVE-2021-1647 | Microsoft Defender Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 39.4% | 12 January 2021 |
| CVE-2021-3129 | Laravel Ignition File Upload Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 12 January 2021 |
| CVE-2020-16017 | Google Chrome Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 2.75% | 8 January 2021 |
| CVE-2020-16013 | Google Chromium V8 Incorrect Implementation Vulnerabililty | KEVHIGH 8.8EPSS 2.75% | 8 January 2021 |
| CVE-2020-17519 | Apache Flink Improper Access Control Vulnerability | KEVHIGH 7.5EPSS 97.8% | 5 January 2021 |
| CVE-2020-10148 | SolarWinds Orion Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 92.0% | 29 December 2020 |
| CVE-2020-35730 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 32.7% | 28 December 2020 |
| CVE-2020-29583 | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 90.2% | 22 December 2020 |
| CVE-2020-29574 | CyberoamOS (CROS) SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 4.66% | 11 December 2020 |
| CVE-2020-17530 | Apache Struts Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 95.9% | 11 December 2020 |
| CVE-2020-17144 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 8.4EPSS 36.5% | 10 December 2020 |
| CVE-2020-27950 | Apple Multiple Products Memory Initialization Vulnerability | KEVMEDIUM 5.5EPSS 16.4% | 8 December 2020 |
| CVE-2020-27932 | Apple Multiple Products Type Confusion Vulnerability | KEVHIGH 7.8EPSS 10.3% | 8 December 2020 |
| CVE-2020-27930 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 22.0% | 8 December 2020 |
| CVE-2020-4006 | Multiple VMware Products Command Injection Vulnerability | KEVCRITICAL 9.1EPSS 17.3% | 23 November 2020 |
| CVE-2020-13671 | Drupal core Un-restricted Upload of File | KEVHIGH 8.8EPSS 35.4% | 20 November 2020 |
| CVE-2020-28949 | PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability | KEVHIGH 7.8EPSS 84.6% | 19 November 2020 |
| CVE-2020-17087 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.43% | 11 November 2020 |
| CVE-2020-13927 | Apache Airflow's Experimental API Authentication Bypass | KEVCRITICAL 9.8EPSS 99.8% | 10 November 2020 |
| CVE-2020-16846 | SaltStack Salt Shell Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 6 November 2020 |
| CVE-2020-16010 | Google Chrome for Android UI Heap Buffer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 6.36% | 3 November 2020 |
| CVE-2020-16009 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 48.3% | 3 November 2020 |
| CVE-2020-15999 | Google Chrome FreeType Heap Buffer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 44.3% | 3 November 2020 |
| CVE-2020-14750 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 2 November 2020 |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 23.9% | 28 October 2020 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 24.4% | 28 October 2020 |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability | KEVMEDIUM 5.4EPSS 17.7% | 28 October 2020 |
| CVE-2020-8260 | Ivanti Pulse Connect Secure Code Execution Vulnerability | KEVHIGH 7.2EPSS 96.5% | 28 October 2020 |
| CVE-2020-3580 | Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 85.6% | 21 October 2020 |
| CVE-2020-14883 | Oracle WebLogic Server Unspecified Vulnerability | KEVHIGH 7.2EPSS 97.9% | 21 October 2020 |
| CVE-2020-14882 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 21 October 2020 |
| CVE-2020-14871 | Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability | KEVCRITICAL 10.0EPSS 79.8% | 21 October 2020 |
| CVE-2020-14864 | Oracle Business Intelligence Enterprise Edition Path Transversal | KEVHIGH 7.5EPSS 97.2% | 21 October 2020 |
| CVE-2020-3992 | VMware ESXi OpenSLP Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 83.0% | 20 October 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.