SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 103 of 348

CVESummaryPriorityPublished
CVE-2019-0233An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.HIGH 7.5EPSS 68.0%14 September 2020
CVE-2019-0230Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.CRITICAL 9.8EPSS 97.4%14 September 2020
CVE-2020-25540ThinkAdmin v6 is affected by a directory traversal vulnerability.HIGH 7.5EPSS 75.3%14 September 2020
CVE-2020-1074<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.HIGH 7.8EPSS 51.0%11 September 2020
CVE-2020-16875<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user.HIGH 8.4EPSS 47.4%11 September 2020
CVE-2020-11991When using the StreamGenerator, the code parse a user-provided XML.HIGH 7.5EPSS 72.5%11 September 2020
CVE-2020-9731A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions).HIGH 7.8EPSS 11.3%10 September 2020
CVE-2020-11998By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A…CRITICAL 9.8EPSS 51.2%10 September 2020
CVE-2020-17408This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.HIGH 7.5EPSS 71.7%10 September 2020
CVE-2020-24916CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.CRITICAL 9.8EPSS 17.4%9 September 2020
CVE-2020-2039An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished.MEDIUM 5.3EPSS 46.4%9 September 2020
CVE-2020-2038An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges.HIGH 7.2EPSS 86.1%9 September 2020
CVE-2020-2036A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface.HIGH 8.8EPSS 23.9%9 September 2020
CVE-2020-25213WordPress File Manager Plugin Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.3%9 September 2020
CVE-2020-11117u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired…CRITICAL 9.8EPSS 19.7%8 September 2020
CVE-2020-14008Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.HIGH 7.2EPSS 40.1%4 September 2020
CVE-2020-3495A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code.HIGH 8.8EPSS 59.9%4 September 2020
CVE-2020-11579An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the…HIGH 7.5EPSS 26.9%3 September 2020
CVE-2020-25042An arbitrary file upload issue exists in Mara CMS 7.5.HIGH 7.2EPSS 18.2%3 September 2020
CVE-2020-24948The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.HIGH 7.2EPSS 13.1%3 September 2020
CVE-2020-24949Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).HIGH 8.8EPSS 67.5%3 September 2020
CVE-2020-14209Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution.HIGH 8.8EPSS 27.5%2 September 2020
CVE-2020-25079D-Link DCS-2530L and DCS-2670L Command Injection VulnerabilityKEVHIGH 8.8EPSS 56.3%2 September 2020
CVE-2020-25078D-Link DCS-2530L and DCS-2670L Devices Unspecified VulnerabilityKEVHIGH 7.5EPSS 97.9%2 September 2020
CVE-2020-5777MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure.CRITICAL 9.8EPSS 23.3%1 September 2020
CVE-2020-5776Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens.HIGH 8.8EPSS 14.7%1 September 2020
CVE-2020-23839A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a…MEDIUM 6.1EPSS 10.5%1 September 2020
CVE-2019-5645By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression.HIGH 7.5EPSS 41.7%1 September 2020
CVE-2020-24363TP-link TL-WA855RE Missing Authentication for Critical Function VulnerabilityKEVHIGH 8.8EPSS 20.7%31 August 2020
CVE-2020-24786The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass.CRITICAL 9.8EPSS 12.8%31 August 2020
CVE-2020-24223Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.MEDIUM 6.1EPSS 14.6%30 August 2020
CVE-2020-23972In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the…HIGH 7.5EPSS 31.4%27 August 2020
CVE-2020-24312mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file.HIGH 7.5EPSS 15.9%26 August 2020
CVE-2020-17389This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.HIGH 8.8EPSS 10.1%25 August 2020
CVE-2020-17387This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.HIGH 8.8EPSS 10.1%25 August 2020
CVE-2020-15645This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.HIGH 8.8EPSS 10.7%25 August 2020
CVE-2020-15643This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.HIGH 8.8EPSS 58.7%25 August 2020
CVE-2020-15639This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64.CRITICAL 9.8EPSS 11.5%25 August 2020
CVE-2020-6637openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.CRITICAL 9.8EPSS 20.1%24 August 2020
CVE-2020-24186A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.CRITICAL 10.0EPSS 94.6%24 August 2020
CVE-2020-8227Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.MEDIUM 6.8EPSS 25.8%21 August 2020
CVE-2020-24589The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.CRITICAL 9.1EPSS 26.3%21 August 2020
CVE-2020-24571NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.HIGH 7.5EPSS 18.0%21 August 2020
CVE-2020-23935Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".CRITICAL 9.8EPSS 15.9%20 August 2020
CVE-2020-17456SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.CRITICAL 9.8EPSS 73.6%20 August 2020
CVE-2020-9715Adobe Acrobat Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 48.6%19 August 2020
CVE-2020-23934An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.HIGH 8.8EPSS 16.0%18 August 2020
CVE-2020-13933Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.HIGH 7.5EPSS 44.4%17 August 2020
CVE-2020-1472Microsoft Netlogon Privilege Escalation VulnerabilityKEVMEDIUM 5.5EPSS 99.4%17 August 2020
CVE-2020-1464Microsoft Windows Spoofing VulnerabilityKEVHIGH 7.8EPSS 38.9%17 August 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.