Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 107 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-1225 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 17.1% | 9 June 2020 |
| CVE-2020-1219 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | HIGH 7.5EPSS 19.1% | 9 June 2020 |
| CVE-2020-1208 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 14.7% | 9 June 2020 |
| CVE-2020-1206 | An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'. | HIGH 7.5EPSS 10.5% | 9 June 2020 |
| CVE-2020-1181 | A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 69.3% | 9 June 2020 |
| CVE-2020-0986 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 15.9% | 9 June 2020 |
| CVE-2020-12004 | The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information. | HIGH 7.5EPSS 13.6% | 9 June 2020 |
| CVE-2020-10644 | The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to… | HIGH 7.5EPSS 20.2% | 9 June 2020 |
| CVE-2020-9850 | A remote attacker may be able to cause arbitrary code execution. | CRITICAL 9.8EPSS 77.2% | 9 June 2020 |
| CVE-2020-13160 | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | CRITICAL 9.8EPSS 80.6% | 9 June 2020 |
| CVE-2020-13965 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 76.6% | 9 June 2020 |
| CVE-2020-13432 | rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers. | HIGH 7.5EPSS 30.9% | 8 June 2020 |
| CVE-2020-12800 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | CRITICAL 9.8EPSS 78.6% | 8 June 2020 |
| CVE-2020-12695 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | HIGH 7.5EPSS 15.2% | 8 June 2020 |
| CVE-2020-4450 | IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. | CRITICAL 9.8EPSS 34.2% | 5 June 2020 |
| CVE-2020-4448 | IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. | CRITICAL 9.8EPSS 12.2% | 5 June 2020 |
| CVE-2020-11975 | Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process. | CRITICAL 9.8EPSS 29.9% | 5 June 2020 |
| CVE-2020-10543 | Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. | HIGH 8.2EPSS 11.3% | 5 June 2020 |
| CVE-2020-13818 | In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. | HIGH 7.5EPSS 37.0% | 4 June 2020 |
| CVE-2020-13777 | GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). | HIGH 7.4EPSS 17.5% | 4 June 2020 |
| CVE-2020-10549 | rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. | CRITICAL 9.8EPSS 32.1% | 4 June 2020 |
| CVE-2020-10548 | rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. | CRITICAL 9.8EPSS 36.5% | 4 June 2020 |
| CVE-2020-10547 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. | CRITICAL 9.8EPSS 36.6% | 4 June 2020 |
| CVE-2020-10546 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. | CRITICAL 9.8EPSS 87.3% | 4 June 2020 |
| CVE-2020-13379 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. | HIGH 8.2EPSS 99.9% | 3 June 2020 |
| CVE-2020-7012 | An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. | HIGH 8.8EPSS 18.2% | 3 June 2020 |
| CVE-2020-13782 | D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection. | HIGH 8.8EPSS 27.1% | 3 June 2020 |
| CVE-2020-13756 | Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. | CRITICAL 9.8EPSS 49.8% | 3 June 2020 |
| CVE-2020-7115 | The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. | CRITICAL 9.8EPSS 64.6% | 3 June 2020 |
| CVE-2020-5410 | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 95.6% | 2 June 2020 |
| CVE-2020-10136 | IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network… | MEDIUM 5.3EPSS 28.5% | 2 June 2020 |
| CVE-2020-13448 | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter. | HIGH 8.8EPSS 17.4% | 1 June 2020 |
| CVE-2020-8816 | Pi-Hole AdminLTE Remote Code Execution Vulnerability | KEVHIGH 7.2EPSS 78.2% | 29 May 2020 |
| CVE-2020-13693 | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled. | CRITICAL 9.8EPSS 43.9% | 29 May 2020 |
| CVE-2020-8606 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance. | CRITICAL 9.8EPSS 72.7% | 27 May 2020 |
| CVE-2020-8605 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. | HIGH 8.8EPSS 87.8% | 27 May 2020 |
| CVE-2020-8604 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations. | HIGH 7.5EPSS 89.8% | 27 May 2020 |
| CVE-2020-1956 | Apache Kylin OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 97.3% | 22 May 2020 |
| CVE-2020-1118 | A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. | HIGH 8.6EPSS 16.2% | 21 May 2020 |
| CVE-2020-1054 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.0EPSS 54.2% | 21 May 2020 |
| CVE-2020-1048 | An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. | HIGH 7.8EPSS 16.4% | 21 May 2020 |
| CVE-2020-9484 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the… | HIGH 7.0EPSS 56.6% | 20 May 2020 |
| CVE-2020-3956 | VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. | HIGH 8.8EPSS 21.1% | 20 May 2020 |
| CVE-2020-12835 | Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol… | CRITICAL 9.8EPSS 13.0% | 20 May 2020 |
| CVE-2020-13167 | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters. | CRITICAL 9.8EPSS 95.4% | 19 May 2020 |
| CVE-2020-13166 | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code. | CRITICAL 9.8EPSS 77.6% | 19 May 2020 |
| CVE-2020-10030 | It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of uninitialized memory content via a stack-based out-of-bounds read. | HIGH 8.8EPSS 23.9% | 19 May 2020 |
| CVE-2020-8617 | Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. | MEDIUM 5.9EPSS 93.4% | 19 May 2020 |
| CVE-2020-8616 | A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of… | HIGH 8.6EPSS 10.6% | 19 May 2020 |
| CVE-2020-13144 | Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and… | HIGH 8.8EPSS 11.0% | 18 May 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.