Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 109 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-11946 | Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. | HIGH 7.5EPSS 51.8% | 20 April 2020 |
| CVE-2020-11883 | In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names. | MEDIUM 5.3EPSS 15.2% | 17 April 2020 |
| CVE-2020-11819 | In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. | CRITICAL 9.8EPSS 26.8% | 16 April 2020 |
| CVE-2020-3251 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | HIGH 8.8EPSS 61.5% | 15 April 2020 |
| CVE-2020-3250 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | CRITICAL 9.8EPSS 60.9% | 15 April 2020 |
| CVE-2020-3249 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | HIGH 7.5EPSS 23.6% | 15 April 2020 |
| CVE-2020-3248 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | CRITICAL 9.8EPSS 74.4% | 15 April 2020 |
| CVE-2020-3247 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | CRITICAL 9.8EPSS 75.6% | 15 April 2020 |
| CVE-2020-3243 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | CRITICAL 9.8EPSS 88.4% | 15 April 2020 |
| CVE-2020-3240 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | HIGH 7.3EPSS 38.7% | 15 April 2020 |
| CVE-2020-3239 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. | HIGH 8.8EPSS 73.6% | 15 April 2020 |
| CVE-2020-3161 | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability | KEVCRITICAL 9.8EPSS 83.9% | 15 April 2020 |
| CVE-2020-1020 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 65.0% | 15 April 2020 |
| CVE-2020-1008 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0999 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0995 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 17.7% | 15 April 2020 |
| CVE-2020-0994 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0992 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0991 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 15 April 2020 |
| CVE-2020-0988 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0980 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 15 April 2020 |
| CVE-2020-0979 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.5% | 15 April 2020 |
| CVE-2020-0974 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 10.7% | 15 April 2020 |
| CVE-2020-0971 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.2% | 15 April 2020 |
| CVE-2020-0970 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 13.3% | 15 April 2020 |
| CVE-2020-0969 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 13.3% | 15 April 2020 |
| CVE-2020-0968 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 30.7% | 15 April 2020 |
| CVE-2020-0967 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.7% | 15 April 2020 |
| CVE-2020-0966 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.7% | 15 April 2020 |
| CVE-2020-0964 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 17.1% | 15 April 2020 |
| CVE-2020-0961 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 15 April 2020 |
| CVE-2020-0960 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0959 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0953 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0938 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 69.2% | 15 April 2020 |
| CVE-2020-0932 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 31.2% | 15 April 2020 |
| CVE-2020-0931 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 10.7% | 15 April 2020 |
| CVE-2020-0929 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 10.7% | 15 April 2020 |
| CVE-2020-0920 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 10.4% | 15 April 2020 |
| CVE-2020-0907 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0906 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.5% | 15 April 2020 |
| CVE-2020-0889 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 15 April 2020 |
| CVE-2020-0687 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 19.3% | 15 April 2020 |
| CVE-2020-2950 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). | CRITICAL 9.8EPSS 71.0% | 15 April 2020 |
| CVE-2020-2883 | Oracle WebLogic Server Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 94.9% | 15 April 2020 |
| CVE-2020-2882 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). | HIGH 8.1EPSS 46.5% | 15 April 2020 |
| CVE-2020-2871 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). | HIGH 8.2EPSS 66.2% | 15 April 2020 |
| CVE-2020-2854 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). | HIGH 8.2EPSS 66.2% | 15 April 2020 |
| CVE-2020-2852 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Calendar). | HIGH 8.2EPSS 66.2% | 15 April 2020 |
| CVE-2020-2733 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). | CRITICAL 9.8EPSS 18.6% | 15 April 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.