SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 106 of 348

CVESummaryPriorityPublished
CVE-2020-15505Ivanti MobileIron Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%7 July 2020
CVE-2020-8163The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.HIGH 8.8EPSS 82.0%2 July 2020
CVE-2020-14092The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.CRITICAL 9.8EPSS 94.5%2 July 2020
CVE-2020-15500The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.MEDIUM 6.1EPSS 12.2%1 July 2020
CVE-2020-12497PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow.HIGH 7.8EPSS 14.7%1 July 2020
CVE-2020-5902F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%1 July 2020
CVE-2020-13383openSIS through 7.4 allows Directory Traversal.HIGH 7.5EPSS 67.8%1 July 2020
CVE-2020-13382openSIS through 7.4 has Incorrect Access Control.CRITICAL 9.1EPSS 52.8%1 July 2020
CVE-2020-13381openSIS through 7.4 allows SQL Injection.CRITICAL 9.8EPSS 59.0%1 July 2020
CVE-2020-14947OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.HIGH 8.8EPSS 19.5%30 June 2020
CVE-2020-9483**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data.HIGH 7.5EPSS 34.6%30 June 2020
CVE-2020-15415DrayTek Multiple Vigor Routers OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 84.5%30 June 2020
CVE-2020-15069Sophos XG Firewall Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 10.7%29 June 2020
CVE-2020-13896The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via the form/formDeviceVerGet URI, such as system id, hardware model, hardware version, bootloader version, software version, software…MEDIUM 5.3EPSS 14.8%29 June 2020
CVE-2020-9590Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability.HIGH 7.8EPSS 40.4%26 June 2020
CVE-2020-11996A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds.HIGH 7.5EPSS 26.7%26 June 2020
CVE-2020-9597Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds write vulnerability.HIGH 8.8EPSS 10.1%25 June 2020
CVE-2020-13700It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.HIGH 7.5EPSS 13.5%24 June 2020
CVE-2020-14005Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.HIGH 8.8EPSS 14.3%24 June 2020
CVE-2020-9480This can be leveraged to execute shell commands on the host machine.CRITICAL 9.8EPSS 29.4%23 June 2020
CVE-2020-14945A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user to escalate their privileges to administrator rights (i.e., the BankAdmin role) via modified SaveUser…HIGH 8.8EPSS 11.4%22 June 2020
CVE-2020-11989Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.CRITICAL 9.8EPSS 24.4%22 June 2020
CVE-2020-13158Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.HIGH 7.5EPSS 54.0%22 June 2020
CVE-2020-8165A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.CRITICAL 9.8EPSS 45.7%19 June 2020
CVE-2020-13640A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request.CRITICAL 9.8EPSS 12.6%18 June 2020
CVE-2020-14422Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary…MEDIUM 5.9EPSS 12.7%18 June 2020
CVE-2020-14295A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.HIGH 7.2EPSS 86.3%17 June 2020
CVE-2020-11910The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.MEDIUM 5.3EPSS 10.9%17 June 2020
CVE-2020-11901The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.CRITICAL 9.0EPSS 21.1%17 June 2020
CVE-2020-11900The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.HIGH 8.2EPSS 13.2%17 June 2020
CVE-2020-11899Treck TCP/IP stack Out-of-Bounds Read VulnerabilityKEVMEDIUM 5.4EPSS 18.6%17 June 2020
CVE-2020-11898The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.CRITICAL 9.1EPSS 18.9%17 June 2020
CVE-2020-11896The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.CRITICAL 10.0EPSS 36.9%17 June 2020
CVE-2020-12001FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and…CRITICAL 9.8EPSS 11.5%15 June 2020
CVE-2020-14011This allows command execution via the Add New Package and Scheduled Deployments features.CRITICAL 9.8EPSS 29.5%15 June 2020
CVE-2020-4469IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 13.4%15 June 2020
CVE-2020-13855Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.HIGH 7.2EPSS 27.6%11 June 2020
CVE-2020-13852Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.HIGH 7.2EPSS 27.6%11 June 2020
CVE-2020-13851Artica Pandora FMS 7.44 allows remote command execution via the events feature.HIGH 8.8EPSS 91.0%11 June 2020
CVE-2020-11798A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to…MEDIUM 5.3EPSS 48.8%10 June 2020
CVE-2020-1321A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.6%9 June 2020
CVE-2020-1313An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.HIGH 7.8EPSS 39.0%9 June 2020
CVE-2020-1301A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.HIGH 8.8EPSS 43.8%9 June 2020
CVE-2020-1300A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer…HIGH 8.8EPSS 59.4%9 June 2020
CVE-2020-1299A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK…HIGH 8.8EPSS 14.5%9 June 2020
CVE-2020-1286A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote…HIGH 8.8EPSS 11.8%9 June 2020
CVE-2020-1281A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.HIGH 8.8EPSS 14.5%9 June 2020
CVE-2020-1248A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.7%9 June 2020
CVE-2020-1236A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.5%9 June 2020
CVE-2020-1226A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 17.1%9 June 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.