SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,136 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 102 of 348

CVESummaryPriorityPublished
CVE-2020-12503Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN,…HIGH 7.2EPSS 23.3%15 October 2020
CVE-2020-13957Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without…CRITICAL 9.8EPSS 79.3%13 October 2020
CVE-2019-17444This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory.CRITICAL 9.8EPSS 69.4%12 October 2020
CVE-2020-8821An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.MEDIUM 5.4EPSS 80.2%12 October 2020
CVE-2020-13943If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a…MEDIUM 4.3EPSS 57.3%12 October 2020
CVE-2020-5135SonicWall SonicOS Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 26.9%12 October 2020
CVE-2020-26948Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.CRITICAL 9.8EPSS 87.2%10 October 2020
CVE-2020-26935A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature.CRITICAL 9.8EPSS 67.1%10 October 2020
CVE-2020-26919Netgear JGS516PE Devices Missing Function Level Access Control VulnerabilityKEVCRITICAL 9.8EPSS 57.2%9 October 2020
CVE-2020-4280IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function.HIGH 8.8EPSS 73.5%8 October 2020
CVE-2020-13340An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job LogHIGH 8.7EPSS 68.6%8 October 2020
CVE-2020-26567An issue was discovered on D-Link DSR-250N before 3.17B devices.MEDIUM 5.5EPSS 17.2%8 October 2020
CVE-2020-15175In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin.CRITICAL 9.1EPSS 71.5%7 October 2020
CVE-2020-26876The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020.HIGH 7.5EPSS 10.6%7 October 2020
CVE-2020-16267Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.HIGH 8.8EPSS 43.3%6 October 2020
CVE-2020-15927Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.HIGH 8.8EPSS 43.3%6 October 2020
CVE-2020-24219Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.HIGH 7.5EPSS 23.6%6 October 2020
CVE-2020-24217Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.CRITICAL 9.8EPSS 40.3%6 October 2020
CVE-2020-24215Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve…CRITICAL 9.8EPSS 19.8%6 October 2020
CVE-2020-24214Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash.CRITICAL 9.8EPSS 35.4%6 October 2020
CVE-2020-26525Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter.CRITICAL 9.1EPSS 25.5%2 October 2020
CVE-2020-24397An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.HIGH 7.2EPSS 27.8%2 October 2020
CVE-2020-26124openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc.HIGH 8.8EPSS 67.4%2 October 2020
CVE-2020-12124A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.CRITICAL 9.8EPSS 74.7%2 October 2020
CVE-2020-15227Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE.CRITICAL 9.8EPSS 34.4%1 October 2020
CVE-2020-8243Ivanti Pulse Connect Secure Code Execution VulnerabilityKEVHIGH 7.2EPSS 90.8%30 September 2020
CVE-2020-25762An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.CRITICAL 9.1EPSS 11.3%30 September 2020
CVE-2020-13951Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.HIGH 7.5EPSS 70.4%30 September 2020
CVE-2018-5353The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing.CRITICAL 9.8EPSS 11.1%30 September 2020
CVE-2020-25223Sophos SG UTM Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 96.7%25 September 2020
CVE-2020-15160PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter.CRITICAL 9.8EPSS 10.8%24 September 2020
CVE-2020-24365The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine.HIGH 8.8EPSS 11.4%24 September 2020
CVE-2019-15993A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information.MEDIUM 5.3EPSS 10.3%23 September 2020
CVE-2020-11857An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.CRITICAL 9.8EPSS 15.8%22 September 2020
CVE-2020-6551Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 27.5%21 September 2020
CVE-2020-6550Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 27.5%21 September 2020
CVE-2020-6549Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 27.5%21 September 2020
CVE-2020-6541Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 21.4%21 September 2020
CVE-2020-14179Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.MEDIUM 5.3EPSS 76.0%21 September 2020
CVE-2020-25790Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive.HIGH 7.2EPSS 15.6%19 September 2020
CVE-2020-25787An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.CRITICAL 9.8EPSS 18.4%19 September 2020
CVE-2020-5421In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a…MEDIUM 6.5EPSS 10.7%19 September 2020
CVE-2020-11698Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.CRITICAL 9.8EPSS 73.2%17 September 2020
CVE-2020-13944In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.MEDIUM 6.1EPSS 25.1%17 September 2020
CVE-2020-6116An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.HIGH 7.8EPSS 28.4%17 September 2020
CVE-2020-6113An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table.HIGH 7.8EPSS 65.0%17 September 2020
CVE-2020-6112An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples.HIGH 7.8EPSS 17.1%17 September 2020
CVE-2020-14181Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint.MEDIUM 5.3EPSS 99.6%17 September 2020
CVE-2020-6146An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.HIGH 8.8EPSS 76.1%16 September 2020
CVE-2020-15148Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input.CRITICAL 10.0EPSS 78.8%15 September 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.