SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 21 of 35

CVESummaryPriorityPublished
CVE-2021-21315System Information Library for Node.JS Command InjectionKEVHIGH 7.8EPSS 90.7%16 February 2021
CVE-2021-25298Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 75.1%15 February 2021
CVE-2021-25297Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 56.7%15 February 2021
CVE-2021-25296Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 72.2%15 February 2021
CVE-2021-21311Adminer Server-Side Request Forgery VulnerabilityKEVHIGH 7.2EPSS 90.5%11 February 2021
CVE-2021-21017Adobe Acrobat and Reader Heap-based Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 86.3%11 February 2021
CVE-2021-23874McAfee Total Protection (MTP) Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 1.03%10 February 2021
CVE-2021-21148Google Chromium V8 Heap Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 20.0%9 February 2021
CVE-2021-22502Micro Focus Operation Bridge Report (OBR) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 96.7%8 February 2021
CVE-2021-20016SonicWall SSLVPN SMA100 SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 40.0%4 February 2021
CVE-2020-2506QNAP Helpdesk Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 1.98%3 February 2021
CVE-2020-25506D-Link DNS-320 Device Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%2 February 2021
CVE-2020-29557D-Link DIR-825 R1 Devices Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 54.3%29 January 2021
CVE-2021-3156Sudo Heap-Based Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 100.0%26 January 2021
CVE-2020-36193PEAR Archive_Tar Improper Link Resolution VulnerabilityKEVHIGH 7.5EPSS 70.6%18 January 2021
CVE-2020-6572Google Chrome Media Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 10.6%14 January 2021
CVE-2021-1647Microsoft Defender Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 39.4%12 January 2021
CVE-2021-3129Laravel Ignition File Upload VulnerabilityKEVCRITICAL 9.8EPSS 99.9%12 January 2021
CVE-2020-16017Google Chrome Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 2.75%8 January 2021
CVE-2020-16013Google Chromium V8 Incorrect Implementation VulnerabililtyKEVHIGH 8.8EPSS 2.75%8 January 2021
CVE-2020-17519Apache Flink Improper Access Control VulnerabilityKEVHIGH 7.5EPSS 97.8%5 January 2021
CVE-2020-10148SolarWinds Orion Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 92.0%29 December 2020
CVE-2020-35730Roundcube Webmail Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 32.7%28 December 2020
CVE-2020-29583Zyxel Multiple Products Use of Hard-Coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 90.2%22 December 2020
CVE-2020-29574CyberoamOS (CROS) SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 4.66%11 December 2020
CVE-2020-17530Apache Struts Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 95.9%11 December 2020
CVE-2020-17144Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 8.4EPSS 36.5%10 December 2020
CVE-2020-27950Apple Multiple Products Memory Initialization VulnerabilityKEVMEDIUM 5.5EPSS 16.4%8 December 2020
CVE-2020-27932Apple Multiple Products Type Confusion VulnerabilityKEVHIGH 7.8EPSS 10.3%8 December 2020
CVE-2020-27930Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 22.0%8 December 2020
CVE-2020-4006Multiple VMware Products Command Injection VulnerabilityKEVCRITICAL 9.1EPSS 17.3%23 November 2020
CVE-2020-13671Drupal core Un-restricted Upload of FileKEVHIGH 8.8EPSS 35.4%20 November 2020
CVE-2020-28949PEAR Archive_Tar Deserialization of Untrusted Data VulnerabilityKEVHIGH 7.8EPSS 84.6%19 November 2020
CVE-2020-17087Microsoft Windows Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 5.43%11 November 2020
CVE-2020-13927Apache Airflow's Experimental API Authentication BypassKEVCRITICAL 9.8EPSS 99.8%10 November 2020
CVE-2020-16846SaltStack Salt Shell Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.6%6 November 2020
CVE-2020-16010Google Chrome for Android UI Heap Buffer Overflow VulnerabilityKEVCRITICAL 9.6EPSS 6.36%3 November 2020
CVE-2020-16009Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 48.3%3 November 2020
CVE-2020-15999Google Chrome FreeType Heap Buffer Overflow VulnerabilityKEVCRITICAL 9.6EPSS 44.3%3 November 2020
CVE-2020-14750Oracle WebLogic Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.3%2 November 2020
CVE-2018-19953QNAP NAS File Station Cross-Site Scripting VulnerabilityKEVMEDIUM 6.1EPSS 23.9%28 October 2020
CVE-2018-19949QNAP NAS File Station Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 24.4%28 October 2020
CVE-2018-19943QNAP NAS File Station Cross-Site Scripting VulnerabilityKEVMEDIUM 5.4EPSS 17.7%28 October 2020
CVE-2020-8260Ivanti Pulse Connect Secure Code Execution VulnerabilityKEVHIGH 7.2EPSS 96.5%28 October 2020
CVE-2020-3580Cisco ASA and FTD Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 85.6%21 October 2020
CVE-2020-14883Oracle WebLogic Server Unspecified VulnerabilityKEVHIGH 7.2EPSS 97.9%21 October 2020
CVE-2020-14882Oracle WebLogic Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%21 October 2020
CVE-2020-14871Oracle Solaris and Zettabyte File System (ZFS) Unspecified VulnerabilityKEVCRITICAL 10.0EPSS 79.8%21 October 2020
CVE-2020-14864Oracle Business Intelligence Enterprise Edition Path TransversalKEVHIGH 7.5EPSS 97.2%21 October 2020
CVE-2020-3992VMware ESXi OpenSLP Use-After-Free VulnerabilityKEVCRITICAL 9.8EPSS 83.0%20 October 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.