SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 104 of 348

CVESummaryPriorityPublished
CVE-2020-1380Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 24.2%17 August 2020
CVE-2020-1337An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system.HIGH 7.8EPSS 14.1%17 August 2020
CVE-2020-3433Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking VulnerabilityKEVHIGH 7.8EPSS 10.0%17 August 2020
CVE-2020-8209Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.HIGH 7.5EPSS 48.7%17 August 2020
CVE-2019-5591Fortinet FortiOS Default Configuration VulnerabilityKEVMEDIUM 6.5EPSS 18.4%14 August 2020
CVE-2020-16205Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).HIGH 7.2EPSS 61.1%14 August 2020
CVE-2020-17463Fuel CMS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 89.7%13 August 2020
CVE-2020-16139A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets.HIGH 7.5EPSS 79.8%12 August 2020
CVE-2020-16138A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the device until it is power cycled.HIGH 7.5EPSS 21.4%12 August 2020
CVE-2020-16137A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values.CRITICAL 9.8EPSS 19.4%12 August 2020
CVE-2020-17506Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.CRITICAL 9.8EPSS 94.0%12 August 2020
CVE-2020-17505Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php.HIGH 8.8EPSS 82.2%12 August 2020
CVE-2020-2230Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.MEDIUM 5.4EPSS 82.7%12 August 2020
CVE-2020-17496vBulletin PHP Module Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 87.7%12 August 2020
CVE-2020-5412Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the…MEDIUM 6.5EPSS 10.2%7 August 2020
CVE-2020-9490A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards.HIGH 7.5EPSS 88.8%7 August 2020
CVE-2020-11993Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.HIGH 7.5EPSS 56.4%7 August 2020
CVE-2020-11984Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCECRITICAL 9.8EPSS 90.0%7 August 2020
CVE-2020-7361The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component.HIGH 8.8EPSS 17.2%6 August 2020
CVE-2020-7357Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials.CRITICAL 9.9EPSS 32.1%6 August 2020
CVE-2020-7356CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability.CRITICAL 9.8EPSS 14.0%6 August 2020
CVE-2020-13921**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.CRITICAL 9.8EPSS 33.5%5 August 2020
CVE-2020-13151Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query.CRITICAL 9.8EPSS 86.7%5 August 2020
CVE-2020-15956ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.HIGH 7.5EPSS 16.2%4 August 2020
CVE-2020-16157A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.MEDIUM 5.4EPSS 14.4%30 July 2020
CVE-2020-8218Pulse Connect Secure Code Injection VulnerabilityKEVHIGH 7.2EPSS 32.7%30 July 2020
CVE-2020-15588An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.CRITICAL 9.8EPSS 12.7%29 July 2020
CVE-2020-13699A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL.HIGH 8.8EPSS 25.8%29 July 2020
CVE-2020-4463IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.HIGH 8.2EPSS 31.6%29 July 2020
CVE-2020-5377Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.CRITICAL 9.1EPSS 48.3%28 July 2020
CVE-2020-15419This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415.HIGH 7.5EPSS 59.8%28 July 2020
CVE-2020-10924This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers.HIGH 8.8EPSS 87.3%28 July 2020
CVE-2020-10923This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers.HIGH 8.8EPSS 84.7%28 July 2020
CVE-2020-1457A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.4%27 July 2020
CVE-2020-12812Fortinet FortiOS SSL VPN Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 49.3%24 July 2020
CVE-2020-15778scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument.HIGH 7.4EPSS 13.0%24 July 2020
CVE-2020-15922There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.CRITICAL 9.8EPSS 57.3%24 July 2020
CVE-2020-15921Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.CRITICAL 9.8EPSS 18.3%24 July 2020
CVE-2020-15920There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.CRITICAL 9.8EPSS 98.2%24 July 2020
CVE-2020-15492This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.CRITICAL 9.8EPSS 16.6%23 July 2020
CVE-2020-15902Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.MEDIUM 6.1EPSS 35.1%22 July 2020
CVE-2020-15901In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.HIGH 8.8EPSS 21.9%22 July 2020
CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal VulnerabilityKEVHIGH 7.5EPSS 100.0%22 July 2020
CVE-2020-15893An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.CRITICAL 9.8EPSS 20.9%22 July 2020
CVE-2020-6519Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.MEDIUM 6.5EPSS 11.3%22 July 2020
CVE-2020-6507Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 19.1%22 July 2020
CVE-2020-12028In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions.HIGH 8.1EPSS 53.0%20 July 2020
CVE-2020-12027All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system.MEDIUM 4.3EPSS 53.0%20 July 2020
CVE-2020-12029A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE).HIGH 7.8EPSS 47.0%20 July 2020
CVE-2020-4464IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector.HIGH 8.8EPSS 13.2%17 July 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.