SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 110 of 348

CVESummaryPriorityPublished
CVE-2020-5260Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker.HIGH 7.5EPSS 10.0%14 April 2020
CVE-2020-11738WordPress Snap Creek Duplicator Plugin File Download VulnerabilityKEVHIGH 7.5EPSS 97.8%13 April 2020
CVE-2020-11710NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself.CRITICAL 9.8EPSS 33.1%12 April 2020
CVE-2020-5330Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure…HIGH 7.5EPSS 13.3%10 April 2020
CVE-2020-3952VMware vCenter Server Information Disclosure VulnerabilityKEVCRITICAL 9.8EPSS 90.4%10 April 2020
CVE-2020-10619An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.CRITICAL 9.1EPSS 14.3%9 April 2020
CVE-2020-10977GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.MEDIUM 5.5EPSS 42.7%8 April 2020
CVE-2020-5735Amcrest Cameras and NVR Stack-based Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 36.2%8 April 2020
CVE-2020-5734Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange.HIGH 7.5EPSS 25.1%7 April 2020
CVE-2019-19699There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable…HIGH 7.2EPSS 27.7%6 April 2020
CVE-2020-11547PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by…MEDIUM 5.3EPSS 52.1%5 April 2020
CVE-2020-11529Common/Grav.php in Grav before 1.7 has an Open Redirect.MEDIUM 6.1EPSS 10.9%4 April 2020
CVE-2020-11518Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.CRITICAL 9.8EPSS 19.2%4 April 2020
CVE-2020-8143An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.MEDIUM 6.1EPSS 70.4%3 April 2020
CVE-2020-8639An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.HIGH 8.8EPSS 15.9%3 April 2020
CVE-2020-11107An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.HIGH 8.8EPSS 22.5%2 April 2020
CVE-2020-11450Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp.HIGH 7.5EPSS 17.8%2 April 2020
CVE-2020-11100In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.HIGH 8.8EPSS 60.7%2 April 2020
CVE-2020-1927In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.MEDIUM 6.1EPSS 56.7%2 April 2020
CVE-2019-17564Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled.CRITICAL 9.8EPSS 36.5%1 April 2020
CVE-2020-1934In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.MEDIUM 5.3EPSS 52.0%1 April 2020
CVE-2020-1943Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.MEDIUM 6.1EPSS 97.3%1 April 2020
CVE-2020-10204Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.HIGH 7.2EPSS 38.2%1 April 2020
CVE-2020-10199Sonatype Nexus Repository Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.1%1 April 2020
CVE-2020-11456LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).MEDIUM 5.4EPSS 70.8%1 April 2020
CVE-2020-11455LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.CRITICAL 9.8EPSS 97.2%1 April 2020
CVE-2020-4241IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system.HIGH 8.8EPSS 66.3%31 March 2020
CVE-2020-5284Next.js versions before 9.3.2 have a directory traversal vulnerability.MEDIUM 4.3EPSS 44.3%30 March 2020
CVE-2020-5724The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint.HIGH 7.5EPSS 12.2%30 March 2020
CVE-2020-8509Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.HIGH 7.5EPSS 10.6%30 March 2020
CVE-2020-9467Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.MEDIUM 5.4EPSS 23.8%26 March 2020
CVE-2020-10828A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.CRITICAL 9.8EPSS 20.9%26 March 2020
CVE-2020-10827A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.CRITICAL 9.8EPSS 20.9%26 March 2020
CVE-2020-10826/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.CRITICAL 9.8EPSS 39.4%26 March 2020
CVE-2020-10963FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension.HIGH 7.2EPSS 14.7%25 March 2020
CVE-2020-10884This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.HIGH 8.8EPSS 26.5%25 March 2020
CVE-2020-10882This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.HIGH 8.8EPSS 41.4%25 March 2020
CVE-2020-10881This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.CRITICAL 9.8EPSS 10.9%25 March 2020
CVE-2020-1957Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.CRITICAL 9.8EPSS 23.3%25 March 2020
CVE-2020-937562209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.HIGH 7.5EPSS 26.7%25 March 2020
CVE-2020-10931Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.HIGH 7.5EPSS 28.1%24 March 2020
CVE-2020-10879rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.CRITICAL 9.8EPSS 83.9%23 March 2020
CVE-2020-8864This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04.HIGH 8.8EPSS 80.2%23 March 2020
CVE-2020-8863This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04.HIGH 8.8EPSS 76.7%23 March 2020
CVE-2020-5722Grandstream Networks UCM6200 Series SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 84.4%23 March 2020
CVE-2020-10821Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.MEDIUM 4.8EPSS 71.1%22 March 2020
CVE-2020-10820Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.MEDIUM 4.8EPSS 19.1%22 March 2020
CVE-2020-10819Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.MEDIUM 4.8EPSS 71.3%22 March 2020
CVE-2020-10808Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.HIGH 8.8EPSS 77.5%22 March 2020
CVE-2020-8882This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916.HIGH 8.8EPSS 11.1%20 March 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.