Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,136 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 102 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-12503 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN,… | HIGH 7.2EPSS 23.3% | 15 October 2020 |
| CVE-2020-13957 | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without… | CRITICAL 9.8EPSS 79.3% | 13 October 2020 |
| CVE-2019-17444 | This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. | CRITICAL 9.8EPSS 69.4% | 12 October 2020 |
| CVE-2020-8821 | An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. | MEDIUM 5.4EPSS 80.2% | 12 October 2020 |
| CVE-2020-13943 | If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a… | MEDIUM 4.3EPSS 57.3% | 12 October 2020 |
| CVE-2020-5135 | SonicWall SonicOS Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 26.9% | 12 October 2020 |
| CVE-2020-26948 | Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. | CRITICAL 9.8EPSS 87.2% | 10 October 2020 |
| CVE-2020-26935 | A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. | CRITICAL 9.8EPSS 67.1% | 10 October 2020 |
| CVE-2020-26919 | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability | KEVCRITICAL 9.8EPSS 57.2% | 9 October 2020 |
| CVE-2020-4280 | IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. | HIGH 8.8EPSS 73.5% | 8 October 2020 |
| CVE-2020-13340 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log | HIGH 8.7EPSS 68.6% | 8 October 2020 |
| CVE-2020-26567 | An issue was discovered on D-Link DSR-250N before 3.17B devices. | MEDIUM 5.5EPSS 17.2% | 8 October 2020 |
| CVE-2020-15175 | In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. | CRITICAL 9.1EPSS 71.5% | 7 October 2020 |
| CVE-2020-26876 | The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. | HIGH 7.5EPSS 10.6% | 7 October 2020 |
| CVE-2020-16267 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module. | HIGH 8.8EPSS 43.3% | 6 October 2020 |
| CVE-2020-15927 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module. | HIGH 8.8EPSS 43.3% | 6 October 2020 |
| CVE-2020-24219 | Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password. | HIGH 7.5EPSS 23.6% | 6 October 2020 |
| CVE-2020-24217 | Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution. | CRITICAL 9.8EPSS 40.3% | 6 October 2020 |
| CVE-2020-24215 | Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve… | CRITICAL 9.8EPSS 19.8% | 6 October 2020 |
| CVE-2020-24214 | Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. | CRITICAL 9.8EPSS 35.4% | 6 October 2020 |
| CVE-2020-26525 | Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. | CRITICAL 9.1EPSS 25.5% | 2 October 2020 |
| CVE-2020-24397 | An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. | HIGH 7.2EPSS 27.8% | 2 October 2020 |
| CVE-2020-26124 | openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. | HIGH 8.8EPSS 67.4% | 2 October 2020 |
| CVE-2020-12124 | A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication. | CRITICAL 9.8EPSS 74.7% | 2 October 2020 |
| CVE-2020-15227 | Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. | CRITICAL 9.8EPSS 34.4% | 1 October 2020 |
| CVE-2020-8243 | Ivanti Pulse Connect Secure Code Execution Vulnerability | KEVHIGH 7.2EPSS 90.8% | 30 September 2020 |
| CVE-2020-25762 | An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc. | CRITICAL 9.1EPSS 11.3% | 30 September 2020 |
| CVE-2020-13951 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | HIGH 7.5EPSS 70.4% | 30 September 2020 |
| CVE-2018-5353 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. | CRITICAL 9.8EPSS 11.1% | 30 September 2020 |
| CVE-2020-25223 | Sophos SG UTM Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 25 September 2020 |
| CVE-2020-15160 | PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. | CRITICAL 9.8EPSS 10.8% | 24 September 2020 |
| CVE-2020-24365 | The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. | HIGH 8.8EPSS 11.4% | 24 September 2020 |
| CVE-2019-15993 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. | MEDIUM 5.3EPSS 10.3% | 23 September 2020 |
| CVE-2020-11857 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. | CRITICAL 9.8EPSS 15.8% | 22 September 2020 |
| CVE-2020-6551 | Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 27.5% | 21 September 2020 |
| CVE-2020-6550 | Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 27.5% | 21 September 2020 |
| CVE-2020-6549 | Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 27.5% | 21 September 2020 |
| CVE-2020-6541 | Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 21.4% | 21 September 2020 |
| CVE-2020-14179 | Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. | MEDIUM 5.3EPSS 76.0% | 21 September 2020 |
| CVE-2020-25790 | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. | HIGH 7.2EPSS 15.6% | 19 September 2020 |
| CVE-2020-25787 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. | CRITICAL 9.8EPSS 18.4% | 19 September 2020 |
| CVE-2020-5421 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a… | MEDIUM 6.5EPSS 10.7% | 19 September 2020 |
| CVE-2020-11698 | Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server. | CRITICAL 9.8EPSS 73.2% | 17 September 2020 |
| CVE-2020-13944 | In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. | MEDIUM 6.1EPSS 25.1% | 17 September 2020 |
| CVE-2020-6116 | An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. | HIGH 7.8EPSS 28.4% | 17 September 2020 |
| CVE-2020-6113 | An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. | HIGH 7.8EPSS 65.0% | 17 September 2020 |
| CVE-2020-6112 | An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. | HIGH 7.8EPSS 17.1% | 17 September 2020 |
| CVE-2020-14181 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. | MEDIUM 5.3EPSS 99.6% | 17 September 2020 |
| CVE-2020-6146 | An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. | HIGH 8.8EPSS 76.1% | 16 September 2020 |
| CVE-2020-15148 | Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. | CRITICAL 10.0EPSS 78.8% | 15 September 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.