SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,771 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 108 of 348

CVESummaryPriorityPublished
CVE-2020-6092An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects.HIGH 7.8EPSS 42.3%18 May 2020
CVE-2020-6074An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155.HIGH 8.8EPSS 40.9%18 May 2020
CVE-2020-12256rConfig 3.9.4 is vulnerable to reflected XSS.MEDIUM 5.4EPSS 95.8%18 May 2020
CVE-2020-12255rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header.HIGH 8.8EPSS 52.6%18 May 2020
CVE-2020-12259rConfig 3.9.4 is vulnerable to reflected XSS.MEDIUM 5.4EPSS 96.2%18 May 2020
CVE-2020-12834eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature…CRITICAL 9.8EPSS 11.1%15 May 2020
CVE-2020-11971Apache Camel's JMX is vulnerable to Rebind Flaw.HIGH 7.5EPSS 14.0%14 May 2020
CVE-2019-16112TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.HIGH 8.8EPSS 11.4%13 May 2020
CVE-2020-11060In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality.HIGH 8.8EPSS 10.9%12 May 2020
CVE-2018-1285This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.CRITICAL 9.8EPSS 17.4%11 May 2020
CVE-2020-11108The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files.HIGH 8.8EPSS 78.3%11 May 2020
CVE-2020-9315** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys.HIGH 7.5EPSS 81.8%10 May 2020
CVE-2020-11532This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.CRITICAL 9.8EPSS 77.5%8 May 2020
CVE-2020-11531This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.HIGH 8.8EPSS 13.7%8 May 2020
CVE-2020-11530A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin.CRITICAL 9.8EPSS 95.7%8 May 2020
CVE-2020-5741Plex Media Server Remote Code Execution VulnerabilityKEVHIGH 7.2EPSS 72.9%8 May 2020
CVE-2020-12720vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.CRITICAL 9.8EPSS 88.9%8 May 2020
CVE-2020-4430IBM Data Risk Manager Directory Traversal VulnerabilityKEVMEDIUM 4.3EPSS 68.5%7 May 2020
CVE-2020-4429A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges.CRITICAL 9.8EPSS 71.4%7 May 2020
CVE-2020-4428IBM Data Risk Manager Remote Code Execution VulnerabilityKEVCRITICAL 9.1EPSS 61.7%7 May 2020
CVE-2020-4427IBM Data Risk Manager Security Bypass VulnerabilityKEVCRITICAL 9.8EPSS 70.0%7 May 2020
CVE-2020-12116Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.HIGH 7.5EPSS 97.4%7 May 2020
CVE-2020-12608There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\.HIGH 7.8EPSS 22.4%7 May 2020
CVE-2020-8982An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020.HIGH 7.5EPSS 27.1%7 May 2020
CVE-2020-7473In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users.HIGH 7.5EPSS 14.3%7 May 2020
CVE-2020-3259Cisco ASA and FTD Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 71.8%6 May 2020
CVE-2020-3187A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read…CRITICAL 9.1EPSS 96.6%6 May 2020
CVE-2020-2184A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.MEDIUM 4.3EPSS 44.5%6 May 2020
CVE-2020-12109Certain TP-Link devices allow Command Injection.HIGH 8.8EPSS 74.3%4 May 2020
CVE-2020-12641Roundcube Webmail Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 84.3%4 May 2020
CVE-2020-12110Certain TP-Link devices have a Hardcoded Encryption Key.CRITICAL 9.8EPSS 13.6%4 May 2020
CVE-2020-7351An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user.HIGH 8.8EPSS 65.2%1 May 2020
CVE-2020-11027Access would be needed to the email account of the user by a malicious party for successful execution.HIGH 8.1EPSS 13.6%30 April 2020
CVE-2020-7136A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.CRITICAL 9.8EPSS 79.5%30 April 2020
CVE-2019-0235Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.HIGH 8.8EPSS 32.7%30 April 2020
CVE-2020-11652SaltStack Salt Path Traversal VulnerabilityKEVMEDIUM 6.5EPSS 86.2%30 April 2020
CVE-2020-11651SaltStack Salt Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 96.6%30 April 2020
CVE-2020-6010LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL InjectionHIGH 8.8EPSS 49.2%30 April 2020
CVE-2019-5620ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.CRITICAL 9.8EPSS 70.1%29 April 2020
CVE-2020-11943There is Arbitrary file upload.HIGH 8.8EPSS 23.9%29 April 2020
CVE-2020-11022In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.MEDIUM 6.1EPSS 99.2%29 April 2020
CVE-2020-11023JQuery Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 84.9%29 April 2020
CVE-2020-12447A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.HIGH 7.5EPSS 13.7%29 April 2020
CVE-2020-9294An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the…CRITICAL 9.8EPSS 77.8%27 April 2020
CVE-2020-12133The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.CRITICAL 9.8EPSS 10.1%27 April 2020
CVE-2020-12271Sophos SFOS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 42.4%27 April 2020
CVE-2020-11945A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden.CRITICAL 9.8EPSS 27.2%23 April 2020
CVE-2020-10915This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.CRITICAL 9.8EPSS 86.6%22 April 2020
CVE-2020-10914This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.CRITICAL 9.8EPSS 47.9%22 April 2020
CVE-2020-1967Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension.HIGH 7.5EPSS 53.3%21 April 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.