Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,136 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 101 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-24432 | Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) and Adobe Acrobat Pro DC 2017.011.30175 (and earlier) are affected by an improper input validation vulnerability that could result in… | HIGH 7.8EPSS 11.1% | 5 November 2020 |
| CVE-2020-24430 | Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability when handling malicious JavaScript. | HIGH 7.8EPSS 18.7% | 5 November 2020 |
| CVE-2020-12146 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API. | HIGH 8.8EPSS 27.6% | 5 November 2020 |
| CVE-2020-27955 | Git LFS 2.12.0 allows Remote Code Execution. | CRITICAL 9.8EPSS 82.7% | 5 November 2020 |
| CVE-2020-27387 | An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename… | HIGH 8.8EPSS 18.5% | 5 November 2020 |
| CVE-2020-16009 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 48.3% | 3 November 2020 |
| CVE-2020-15999 | Google Chrome FreeType Heap Buffer Overflow Vulnerability | KEVCRITICAL 9.6EPSS 44.3% | 3 November 2020 |
| CVE-2020-15994 | Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 13.1% | 3 November 2020 |
| CVE-2020-28032 | WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php. | CRITICAL 9.8EPSS 16.1% | 2 November 2020 |
| CVE-2020-24881 | SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. | CRITICAL 9.8EPSS 73.4% | 2 November 2020 |
| CVE-2020-14750 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 2 November 2020 |
| CVE-2020-14425 | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. | HIGH 7.8EPSS 40.8% | 2 November 2020 |
| CVE-2020-3657 | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer… | CRITICAL 9.8EPSS 28.3% | 2 November 2020 |
| CVE-2020-7373 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. | CRITICAL 9.8EPSS 45.0% | 30 October 2020 |
| CVE-2020-7384 | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. | HIGH 7.8EPSS 30.5% | 29 October 2020 |
| CVE-2020-27986 | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. | HIGH 7.5EPSS 16.0% | 28 October 2020 |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 23.9% | 28 October 2020 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 24.4% | 28 October 2020 |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability | KEVMEDIUM 5.4EPSS 17.7% | 28 October 2020 |
| CVE-2020-8260 | Ivanti Pulse Connect Secure Code Execution Vulnerability | KEVHIGH 7.2EPSS 96.5% | 28 October 2020 |
| CVE-2020-11854 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and… | CRITICAL 9.8EPSS 74.4% | 27 October 2020 |
| CVE-2020-26879 | Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. | CRITICAL 9.8EPSS 45.1% | 26 October 2020 |
| CVE-2020-26878 | Ruckus through 1.5.1.0.21 is affected by remote command injection. | HIGH 8.8EPSS 11.6% | 26 October 2020 |
| CVE-2020-26561 | Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. | HIGH 8.8EPSS 12.2% | 23 October 2020 |
| CVE-2020-11853 | Arbitrary code execution vulnerability affecting multiple Micro Focus products. | HIGH 8.8EPSS 77.0% | 22 October 2020 |
| CVE-2020-15906 | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. | CRITICAL 9.8EPSS 27.2% | 22 October 2020 |
| CVE-2020-27615 | The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip. | CRITICAL 9.8EPSS 52.3% | 21 October 2020 |
| CVE-2020-3580 | Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 85.6% | 21 October 2020 |
| CVE-2020-14883 | Oracle WebLogic Server Unspecified Vulnerability | KEVHIGH 7.2EPSS 97.9% | 21 October 2020 |
| CVE-2020-14882 | Oracle WebLogic Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 21 October 2020 |
| CVE-2020-14871 | Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability | KEVCRITICAL 10.0EPSS 80.3% | 21 October 2020 |
| CVE-2020-14864 | Oracle Business Intelligence Enterprise Edition Path Transversal | KEVHIGH 7.5EPSS 97.2% | 21 October 2020 |
| CVE-2020-14841 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 52.0% | 21 October 2020 |
| CVE-2020-14825 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 30.4% | 21 October 2020 |
| CVE-2020-25820 | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field. | MEDIUM 6.5EPSS 10.5% | 21 October 2020 |
| CVE-2020-5792 | Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user. | HIGH 7.2EPSS 61.0% | 20 October 2020 |
| CVE-2020-5791 | Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user. | HIGH 7.2EPSS 78.6% | 20 October 2020 |
| CVE-2020-3992 | VMware ESXi OpenSLP Use-After-Free Vulnerability | KEVCRITICAL 9.8EPSS 83.0% | 20 October 2020 |
| CVE-2020-6308 | SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible… | MEDIUM 5.3EPSS 61.7% | 20 October 2020 |
| CVE-2020-15261 | On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. | MEDIUM 6.7EPSS 11.3% | 19 October 2020 |
| CVE-2020-13937 | Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed… | MEDIUM 5.3EPSS 78.3% | 19 October 2020 |
| CVE-2020-24648 | A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | CRITICAL 9.8EPSS 10.5% | 19 October 2020 |
| CVE-2020-16952 | <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. | HIGH 8.6EPSS 71.1% | 16 October 2020 |
| CVE-2020-16947 | <p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. | HIGH 7.5EPSS 33.8% | 16 October 2020 |
| CVE-2020-16899 | <p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. | HIGH 7.5EPSS 13.5% | 16 October 2020 |
| CVE-2020-16898 | <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. | HIGH 8.8EPSS 10.9% | 16 October 2020 |
| CVE-2020-16896 | <p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. | HIGH 7.5EPSS 12.6% | 16 October 2020 |
| CVE-2020-16270 | OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. | MEDIUM 6.1EPSS 13.1% | 16 October 2020 |
| CVE-2020-15867 | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. | HIGH 7.2EPSS 87.4% | 16 October 2020 |
| CVE-2020-14144 | The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be… | HIGH 7.2EPSS 95.4% | 16 October 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.