Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 104 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-1380 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 24.2% | 17 August 2020 |
| CVE-2020-1337 | An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. | HIGH 7.8EPSS 14.1% | 17 August 2020 |
| CVE-2020-3433 | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability | KEVHIGH 7.8EPSS 10.0% | 17 August 2020 |
| CVE-2020-8209 | Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files. | HIGH 7.5EPSS 48.7% | 17 August 2020 |
| CVE-2019-5591 | Fortinet FortiOS Default Configuration Vulnerability | KEVMEDIUM 6.5EPSS 18.4% | 14 August 2020 |
| CVE-2020-16205 | Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5). | HIGH 7.2EPSS 61.1% | 14 August 2020 |
| CVE-2020-17463 | Fuel CMS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 89.7% | 13 August 2020 |
| CVE-2020-16139 | A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. | HIGH 7.5EPSS 79.8% | 12 August 2020 |
| CVE-2020-16138 | A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the device until it is power cycled. | HIGH 7.5EPSS 21.4% | 12 August 2020 |
| CVE-2020-16137 | A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. | CRITICAL 9.8EPSS 19.4% | 12 August 2020 |
| CVE-2020-17506 | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. | CRITICAL 9.8EPSS 94.0% | 12 August 2020 |
| CVE-2020-17505 | Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. | HIGH 8.8EPSS 82.2% | 12 August 2020 |
| CVE-2020-2230 | Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission. | MEDIUM 5.4EPSS 82.7% | 12 August 2020 |
| CVE-2020-17496 | vBulletin PHP Module Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 87.7% | 12 August 2020 |
| CVE-2020-5412 | Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the… | MEDIUM 6.5EPSS 10.2% | 7 August 2020 |
| CVE-2020-9490 | A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. | HIGH 7.5EPSS 88.8% | 7 August 2020 |
| CVE-2020-11993 | Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers. | HIGH 7.5EPSS 56.4% | 7 August 2020 |
| CVE-2020-11984 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | CRITICAL 9.8EPSS 90.0% | 7 August 2020 |
| CVE-2020-7361 | The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. | HIGH 8.8EPSS 17.2% | 6 August 2020 |
| CVE-2020-7357 | Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. | CRITICAL 9.9EPSS 32.1% | 6 August 2020 |
| CVE-2020-7356 | CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. | CRITICAL 9.8EPSS 14.0% | 6 August 2020 |
| CVE-2020-13921 | **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases. | CRITICAL 9.8EPSS 33.5% | 5 August 2020 |
| CVE-2020-13151 | Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. | CRITICAL 9.8EPSS 86.7% | 5 August 2020 |
| CVE-2020-15956 | ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload. | HIGH 7.5EPSS 16.2% | 4 August 2020 |
| CVE-2020-16157 | A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu. | MEDIUM 5.4EPSS 14.4% | 30 July 2020 |
| CVE-2020-8218 | Pulse Connect Secure Code Injection Vulnerability | KEVHIGH 7.2EPSS 32.7% | 30 July 2020 |
| CVE-2020-15588 | An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. | CRITICAL 9.8EPSS 12.7% | 29 July 2020 |
| CVE-2020-13699 | A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. | HIGH 8.8EPSS 25.8% | 29 July 2020 |
| CVE-2020-4463 | IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. | HIGH 8.2EPSS 31.6% | 29 July 2020 |
| CVE-2020-5377 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. | CRITICAL 9.1EPSS 48.3% | 28 July 2020 |
| CVE-2020-15419 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. | HIGH 7.5EPSS 59.8% | 28 July 2020 |
| CVE-2020-10924 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. | HIGH 8.8EPSS 87.3% | 28 July 2020 |
| CVE-2020-10923 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. | HIGH 8.8EPSS 84.7% | 28 July 2020 |
| CVE-2020-1457 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.4% | 27 July 2020 |
| CVE-2020-12812 | Fortinet FortiOS SSL VPN Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 49.3% | 24 July 2020 |
| CVE-2020-15778 | scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. | HIGH 7.4EPSS 13.0% | 24 July 2020 |
| CVE-2020-15922 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. | CRITICAL 9.8EPSS 57.3% | 24 July 2020 |
| CVE-2020-15921 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. | CRITICAL 9.8EPSS 18.3% | 24 July 2020 |
| CVE-2020-15920 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. | CRITICAL 9.8EPSS 98.2% | 24 July 2020 |
| CVE-2020-15492 | This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact. | CRITICAL 9.8EPSS 16.6% | 23 July 2020 |
| CVE-2020-15902 | Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option. | MEDIUM 6.1EPSS 35.1% | 22 July 2020 |
| CVE-2020-15901 | In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys. | HIGH 8.8EPSS 21.9% | 22 July 2020 |
| CVE-2020-3452 | Cisco ASA and FTD Read-Only Path Traversal Vulnerability | KEVHIGH 7.5EPSS 100.0% | 22 July 2020 |
| CVE-2020-15893 | An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. | CRITICAL 9.8EPSS 20.9% | 22 July 2020 |
| CVE-2020-6519 | Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | MEDIUM 6.5EPSS 11.3% | 22 July 2020 |
| CVE-2020-6507 | Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 19.1% | 22 July 2020 |
| CVE-2020-12028 | In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. | HIGH 8.1EPSS 53.0% | 20 July 2020 |
| CVE-2020-12027 | All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. | MEDIUM 4.3EPSS 53.0% | 20 July 2020 |
| CVE-2020-12029 | A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). | HIGH 7.8EPSS 47.0% | 20 July 2020 |
| CVE-2020-4464 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. | HIGH 8.8EPSS 13.2% | 17 July 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.