Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,033 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 23 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-1054 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 54.2% | 21 May 2020 |
| CVE-2020-5741 | Plex Media Server Remote Code Execution Vulnerability | KEVHIGH 7.2EPSS 72.9% | 8 May 2020 |
| CVE-2020-4430 | IBM Data Risk Manager Directory Traversal Vulnerability | KEVMEDIUM 4.3EPSS 68.5% | 7 May 2020 |
| CVE-2020-4428 | IBM Data Risk Manager Remote Code Execution Vulnerability | KEVCRITICAL 9.1EPSS 61.7% | 7 May 2020 |
| CVE-2020-4427 | IBM Data Risk Manager Security Bypass Vulnerability | KEVCRITICAL 9.8EPSS 70.0% | 7 May 2020 |
| CVE-2020-3259 | Cisco ASA and FTD Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 71.8% | 6 May 2020 |
| CVE-2020-12641 | Roundcube Webmail Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 84.3% | 4 May 2020 |
| CVE-2020-1631 | Juniper Junos OS Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 4.72% | 4 May 2020 |
| CVE-2020-11652 | SaltStack Salt Path Traversal Vulnerability | KEVMEDIUM 6.5EPSS 86.2% | 30 April 2020 |
| CVE-2020-11651 | SaltStack Salt Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 96.6% | 30 April 2020 |
| CVE-2020-11023 | JQuery Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 84.9% | 29 April 2020 |
| CVE-2020-12271 | Sophos SFOS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 42.4% | 27 April 2020 |
| CVE-2020-6820 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | KEVHIGH 8.1EPSS 7.06% | 24 April 2020 |
| CVE-2020-6819 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | KEVHIGH 8.1EPSS 3.04% | 24 April 2020 |
| CVE-2020-3161 | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | KEVCRITICAL 9.8EPSS 83.9% | 15 April 2020 |
| CVE-2020-1027 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.55% | 15 April 2020 |
| CVE-2020-1020 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 65.0% | 15 April 2020 |
| CVE-2020-0968 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 30.7% | 15 April 2020 |
| CVE-2020-0938 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 69.2% | 15 April 2020 |
| CVE-2020-2883 | Oracle WebLogic Server Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 94.9% | 15 April 2020 |
| CVE-2020-11738 | WordPress Snap Creek Duplicator Plugin File Download Vulnerability | KEVHIGH 7.5EPSS 97.8% | 13 April 2020 |
| CVE-2020-3952 | VMware vCenter Server Information Disclosure Vulnerability | KEVCRITICAL 9.8EPSS 90.4% | 10 April 2020 |
| CVE-2020-5735 | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 36.2% | 8 April 2020 |
| CVE-2020-10199 | Sonatype Nexus Repository Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.1% | 1 April 2020 |
| CVE-2020-5722 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 84.4% | 23 March 2020 |
| CVE-2020-7961 | Liferay Portal Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 20 March 2020 |
| CVE-2020-8599 | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 11.9% | 18 March 2020 |
| CVE-2020-8468 | Trend Micro Multiple Products Content Validation Escape Vulnerability | KEVHIGH 8.8EPSS 6.17% | 18 March 2020 |
| CVE-2020-8467 | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.9% | 18 March 2020 |
| CVE-2020-3950 | VMware Multiple Products Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 7.25% | 17 March 2020 |
| CVE-2020-5849 | Unraid Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 93.2% | 16 March 2020 |
| CVE-2020-5847 | Unraid Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 95.8% | 16 March 2020 |
| CVE-2020-0796 | Microsoft SMBv3 Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 12 March 2020 |
| CVE-2020-0787 | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 42.5% | 12 March 2020 |
| CVE-2020-10181 | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | KEVCRITICAL 9.8EPSS 14.7% | 11 March 2020 |
| CVE-2020-6207 | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 10 March 2020 |
| CVE-2020-0069 | Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability | KEVHIGH 7.8EPSS 1.37% | 10 March 2020 |
| CVE-2020-0041 | Android Kernel Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 3.25% | 10 March 2020 |
| CVE-2016-11021 | D-Link DCS-930L Devices OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 68.9% | 9 March 2020 |
| CVE-2020-10221 | rConfig OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 80.2% | 8 March 2020 |
| CVE-2020-10189 | Zoho ManageEngine Desktop Central File Upload Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 6 March 2020 |
| CVE-2019-20500 | D-Link DWL-2600AP Access Point Command Injection Vulnerability | KEVHIGH 7.8EPSS 97.1% | 5 March 2020 |
| CVE-2020-9054 | Zyxel Multiple NAS Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 March 2020 |
| CVE-2019-17026 | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | KEVHIGH 8.8EPSS 46.3% | 2 March 2020 |
| CVE-2020-6418 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 78.8% | 27 February 2020 |
| CVE-2020-3837 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 16.1% | 27 February 2020 |
| CVE-2020-1938 | Apache Tomcat Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 24 February 2020 |
| CVE-2020-3153 | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | KEVMEDIUM 6.5EPSS 28.3% | 19 February 2020 |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | KEVCRITICAL 9.8EPSS 84.4% | 18 February 2020 |
| CVE-2020-0688 | Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 100.0% | 11 February 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.