SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 109 of 348

CVESummaryPriorityPublished
CVE-2020-11946Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.HIGH 7.5EPSS 51.8%20 April 2020
CVE-2020-11883In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.MEDIUM 5.3EPSS 15.2%17 April 2020
CVE-2020-11819In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.CRITICAL 9.8EPSS 26.8%16 April 2020
CVE-2020-3251Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.HIGH 8.8EPSS 61.5%15 April 2020
CVE-2020-3250Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.CRITICAL 9.8EPSS 60.9%15 April 2020
CVE-2020-3249Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.HIGH 7.5EPSS 23.6%15 April 2020
CVE-2020-3248Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.CRITICAL 9.8EPSS 74.4%15 April 2020
CVE-2020-3247Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.CRITICAL 9.8EPSS 75.6%15 April 2020
CVE-2020-3243Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.CRITICAL 9.8EPSS 88.4%15 April 2020
CVE-2020-3240Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.HIGH 7.3EPSS 38.7%15 April 2020
CVE-2020-3239Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device.HIGH 8.8EPSS 73.6%15 April 2020
CVE-2020-3161Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service VulnerabilityKEVCRITICAL 9.8EPSS 83.9%15 April 2020
CVE-2020-1020Microsoft Windows Adobe Font Manager Library Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 65.0%15 April 2020
CVE-2020-1008A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0999A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0995A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 17.7%15 April 2020
CVE-2020-0994A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0992A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0991A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.8%15 April 2020
CVE-2020-0988A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0980A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.8%15 April 2020
CVE-2020-0979A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.5%15 April 2020
CVE-2020-0974A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 10.7%15 April 2020
CVE-2020-0971A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.2%15 April 2020
CVE-2020-0970A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 13.3%15 April 2020
CVE-2020-0969A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 13.3%15 April 2020
CVE-2020-0968Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 30.7%15 April 2020
CVE-2020-0967A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.7%15 April 2020
CVE-2020-0966A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.7%15 April 2020
CVE-2020-0964A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 17.1%15 April 2020
CVE-2020-0961A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.8%15 April 2020
CVE-2020-0960A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0959A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0953A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0938Microsoft Windows Adobe Font Manager Library Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 69.2%15 April 2020
CVE-2020-0932A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 31.2%15 April 2020
CVE-2020-0931A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 10.7%15 April 2020
CVE-2020-0929A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 10.7%15 April 2020
CVE-2020-0920A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 10.4%15 April 2020
CVE-2020-0907A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0906A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.5%15 April 2020
CVE-2020-0889A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.0%15 April 2020
CVE-2020-0687A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.HIGH 8.8EPSS 19.3%15 April 2020
CVE-2020-2950Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General).CRITICAL 9.8EPSS 71.0%15 April 2020
CVE-2020-2883Oracle WebLogic Server Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 94.9%15 April 2020
CVE-2020-2882Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers).HIGH 8.1EPSS 46.5%15 April 2020
CVE-2020-2871Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface).HIGH 8.2EPSS 66.2%15 April 2020
CVE-2020-2854Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface).HIGH 8.2EPSS 66.2%15 April 2020
CVE-2020-2852Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Calendar).HIGH 8.2EPSS 66.2%15 April 2020
CVE-2020-2733Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics).CRITICAL 9.8EPSS 18.6%15 April 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.