Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 22 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-9934 | Apple iOS, iPadOS, and macOS Input Validation Vulnerability | KEVMEDIUM 5.5EPSS 3.21% | 16 October 2020 |
| CVE-2020-9907 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 3.88% | 16 October 2020 |
| CVE-2020-5135 | SonicWall SonicOS Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 26.9% | 12 October 2020 |
| CVE-2020-26919 | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability | KEVCRITICAL 9.8EPSS 57.2% | 9 October 2020 |
| CVE-2020-8243 | Ivanti Pulse Connect Secure Code Execution Vulnerability | KEVHIGH 7.2EPSS 90.8% | 30 September 2020 |
| CVE-2020-25223 | Sophos SG UTM Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 25 September 2020 |
| CVE-2020-3569 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | KEVHIGH 8.6EPSS 3.32% | 23 September 2020 |
| CVE-2020-0878 | Microsoft Edge and Internet Explorer Memory Corruption Vulnerability | KEVMEDIUM 4.2EPSS 2.70% | 11 September 2020 |
| CVE-2020-25213 | WordPress File Manager Plugin Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 9 September 2020 |
| CVE-2020-25079 | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | KEVHIGH 8.8EPSS 56.3% | 2 September 2020 |
| CVE-2020-25078 | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | KEVHIGH 7.5EPSS 97.9% | 2 September 2020 |
| CVE-2020-24557 | Trend Micro Multiple Products Improper Access Control Vulnerability | KEVHIGH 7.8EPSS 2.64% | 1 September 2020 |
| CVE-2020-24363 | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | KEVHIGH 8.8EPSS 20.7% | 31 August 2020 |
| CVE-2020-3566 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | KEVHIGH 8.6EPSS 3.70% | 29 August 2020 |
| CVE-2020-9715 | Adobe Acrobat Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 48.6% | 19 August 2020 |
| CVE-2020-1472 | Microsoft Netlogon Privilege Escalation Vulnerability | KEVMEDIUM 5.5EPSS 99.4% | 17 August 2020 |
| CVE-2020-1464 | Microsoft Windows Spoofing Vulnerability | KEVHIGH 7.8EPSS 38.9% | 17 August 2020 |
| CVE-2020-1380 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 24.2% | 17 August 2020 |
| CVE-2020-3433 | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability | KEVHIGH 7.8EPSS 10.0% | 17 August 2020 |
| CVE-2019-5591 | Fortinet FortiOS Default Configuration Vulnerability | KEVMEDIUM 6.5EPSS 18.4% | 14 August 2020 |
| CVE-2020-17463 | Fuel CMS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 89.7% | 13 August 2020 |
| CVE-2020-17496 | vBulletin PHP Module Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 87.7% | 12 August 2020 |
| CVE-2020-8218 | Pulse Connect Secure Code Injection Vulnerability | KEVHIGH 7.2EPSS 32.7% | 30 July 2020 |
| CVE-2020-12812 | Fortinet FortiOS SSL VPN Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 49.3% | 24 July 2020 |
| CVE-2020-3452 | Cisco ASA and FTD Read-Only Path Traversal Vulnerability | KEVHIGH 7.5EPSS 100.0% | 22 July 2020 |
| CVE-2020-11978 | Apache Airflow Command Injection | KEVHIGH 8.8EPSS 99.2% | 17 July 2020 |
| CVE-2020-14644 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 94.5% | 15 July 2020 |
| CVE-2020-1350 | Microsoft Windows DNS Server Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 91.4% | 14 July 2020 |
| CVE-2020-1147 | Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 94.0% | 14 July 2020 |
| CVE-2020-1040 | Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability | KEVCRITICAL 9.0EPSS 7.32% | 14 July 2020 |
| CVE-2020-6287 | SAP NetWeaver Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 10.0EPSS 94.7% | 14 July 2020 |
| CVE-2020-10987 | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 79.8% | 13 July 2020 |
| CVE-2020-8196 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | KEVMEDIUM 4.3EPSS 26.3% | 10 July 2020 |
| CVE-2020-8195 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 33.0% | 10 July 2020 |
| CVE-2020-8193 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | KEVMEDIUM 6.5EPSS 88.4% | 10 July 2020 |
| CVE-2020-9377 | D-Link DIR-610 Devices Remote Command Execution | KEVHIGH 8.8EPSS 21.3% | 9 July 2020 |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 7 July 2020 |
| CVE-2020-5902 | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 1 July 2020 |
| CVE-2020-15415 | DrayTek Multiple Vigor Routers OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 84.5% | 30 June 2020 |
| CVE-2020-15069 | Sophos XG Firewall Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 10.7% | 29 June 2020 |
| CVE-2020-2021 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 4.36% | 29 June 2020 |
| CVE-2020-11899 | Treck TCP/IP stack Out-of-Bounds Read Vulnerability | KEVMEDIUM 5.4EPSS 18.6% | 17 June 2020 |
| CVE-2020-0986 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 15.9% | 9 June 2020 |
| CVE-2020-9819 | Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability | KEVMEDIUM 4.3EPSS 2.18% | 9 June 2020 |
| CVE-2020-9818 | Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 2.29% | 9 June 2020 |
| CVE-2020-13965 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 76.6% | 9 June 2020 |
| CVE-2020-9859 | Apple Multiple Products Code Execution Vulnerability | KEVHIGH 7.8EPSS 0.83% | 5 June 2020 |
| CVE-2020-5410 | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 95.6% | 2 June 2020 |
| CVE-2020-8816 | Pi-Hole AdminLTE Remote Code Execution Vulnerability | KEVHIGH 7.2EPSS 78.2% | 29 May 2020 |
| CVE-2020-1956 | Apache Kylin OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 97.3% | 22 May 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.