SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 105 of 348

CVESummaryPriorityPublished
CVE-2020-15803Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.MEDIUM 6.1EPSS 32.3%17 July 2020
CVE-2020-11981When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.CRITICAL 9.8EPSS 36.5%17 July 2020
CVE-2020-11978Apache Airflow Command InjectionKEVHIGH 8.8EPSS 99.2%17 July 2020
CVE-2020-13405userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.HIGH 7.5EPSS 13.6%16 July 2020
CVE-2020-12011A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution.CRITICAL 9.8EPSS 29.2%16 July 2020
CVE-2020-3387A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system.HIGH 8.8EPSS 13.0%16 July 2020
CVE-2020-3331A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.CRITICAL 9.8EPSS 41.7%16 July 2020
CVE-2020-8958Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.HIGH 7.2EPSS 46.6%15 July 2020
CVE-2020-14645Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 46.9%15 July 2020
CVE-2020-14644Oracle WebLogic Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 94.5%15 July 2020
CVE-2020-9496XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03MEDIUM 6.1EPSS 98.9%15 July 2020
CVE-2020-1481A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.HIGH 8.8EPSS 23.6%14 July 2020
CVE-2020-1458A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.9%14 July 2020
CVE-2020-1447A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.HIGH 8.8EPSS 10.6%14 July 2020
CVE-2020-1446A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.2%14 July 2020
CVE-2020-1439A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.HIGH 8.8EPSS 20.3%14 July 2020
CVE-2020-1436A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows…HIGH 8.8EPSS 21.3%14 July 2020
CVE-2020-1435A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.7%14 July 2020
CVE-2020-1421A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK…HIGH 8.8EPSS 74.5%14 July 2020
CVE-2020-1412A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.HIGH 8.8EPSS 14.0%14 July 2020
CVE-2020-1410A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files.To exploit the vulnerability, an attacker could send a malicious vcard that a victim opens using Windows Address Book (WAB), aka 'Windows…HIGH 7.8EPSS 11.5%14 July 2020
CVE-2020-1409A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.7%14 July 2020
CVE-2020-1407A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.9%14 July 2020
CVE-2020-1403A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.HIGH 7.5EPSS 10.5%14 July 2020
CVE-2020-1401A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.1%14 July 2020
CVE-2020-1400A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 23.7%14 July 2020
CVE-2020-1350Microsoft Windows DNS Server Remote Code Execution VulnerabilityKEVCRITICAL 10.0EPSS 91.4%14 July 2020
CVE-2020-1349A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.HIGH 7.8EPSS 22.4%14 July 2020
CVE-2020-1240A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.8%14 July 2020
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 94.0%14 July 2020
CVE-2020-11546SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php.CRITICAL 9.8EPSS 32.8%14 July 2020
CVE-2020-13935Multiple requests with invalid payload lengths could lead to a denial of service.HIGH 7.5EPSS 86.6%14 July 2020
CVE-2020-13934If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.HIGH 7.5EPSS 64.1%14 July 2020
CVE-2020-1948This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower.CRITICAL 9.8EPSS 16.4%14 July 2020
CVE-2020-6287SAP NetWeaver Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 10.0EPSS 94.7%14 July 2020
CVE-2020-6286The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a…MEDIUM 5.3EPSS 28.3%14 July 2020
CVE-2020-13925Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility…CRITICAL 9.8EPSS 19.9%14 July 2020
CVE-2020-15050Remote attackers can read arbitrary files from the server via Directory Traversal.HIGH 7.5EPSS 50.7%13 July 2020
CVE-2020-10987Tenda AC1900 Router AC15 Model Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 79.8%13 July 2020
CVE-2020-11749Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views.CRITICAL 9.0EPSS 16.2%13 July 2020
CVE-2020-8196Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure VulnerabilityKEVMEDIUM 4.3EPSS 26.3%10 July 2020
CVE-2020-8195Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 33.0%10 July 2020
CVE-2020-8194Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.MEDIUM 6.5EPSS 10.7%10 July 2020
CVE-2020-8193Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass VulnerabilityKEVMEDIUM 6.5EPSS 88.4%10 July 2020
CVE-2020-8191Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).MEDIUM 6.1EPSS 26.1%10 July 2020
CVE-2020-15299A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the…MEDIUM 6.1EPSS 47.0%9 July 2020
CVE-2019-17638If the Jetty version cannot be upgraded, the vulnerability can be significantly reduced by configuring a responseHeaderSize significantly larger than the requestHeaderSize (12KB responseHeaderSize and 8KB requestHeaderSize).CRITICAL 9.4EPSS 11.1%9 July 2020
CVE-2020-7457In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition…HIGH 8.1EPSS 33.1%9 July 2020
CVE-2020-9377D-Link DIR-610 Devices Remote Command ExecutionKEVHIGH 8.8EPSS 21.3%9 July 2020
CVE-2020-9376D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php.HIGH 7.5EPSS 16.6%9 July 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.