Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 111 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-8881 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. | HIGH 8.8EPSS 11.1% | 20 March 2020 |
| CVE-2020-8880 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. | HIGH 8.8EPSS 11.1% | 20 March 2020 |
| CVE-2020-8878 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. | HIGH 8.8EPSS 11.1% | 20 March 2020 |
| CVE-2020-7961 | Liferay Portal Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 20 March 2020 |
| CVE-2020-9425 | An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. | HIGH 7.5EPSS 19.0% | 20 March 2020 |
| CVE-2019-16072 | An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within… | CRITICAL 9.8EPSS 25.9% | 20 March 2020 |
| CVE-2019-16012 | A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. | HIGH 8.1EPSS 54.2% | 19 March 2020 |
| CVE-2020-8599 | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 11.9% | 18 March 2020 |
| CVE-2020-8598 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. | CRITICAL 9.8EPSS 13.2% | 18 March 2020 |
| CVE-2020-8467 | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 10.9% | 18 March 2020 |
| CVE-2020-5849 | Unraid Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 93.2% | 16 March 2020 |
| CVE-2020-5847 | Unraid Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 95.8% | 16 March 2020 |
| CVE-2020-5844 | index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. | HIGH 7.2EPSS 30.3% | 16 March 2020 |
| CVE-2020-6586 | Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. | MEDIUM 5.4EPSS 19.0% | 16 March 2020 |
| CVE-2020-10230 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter. | CRITICAL 9.8EPSS 14.7% | 16 March 2020 |
| CVE-2019-19208 | Codiad Web IDE through 2.8.4 allows PHP Code injection. | CRITICAL 9.8EPSS 19.2% | 16 March 2020 |
| CVE-2020-10567 | This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. | CRITICAL 9.8EPSS 19.6% | 14 March 2020 |
| CVE-2020-10541 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. | CRITICAL 9.8EPSS 10.1% | 13 March 2020 |
| CVE-2020-0905 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | HIGH 8.0EPSS 10.8% | 12 March 2020 |
| CVE-2020-0892 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 12 March 2020 |
| CVE-2020-0883 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 22.0% | 12 March 2020 |
| CVE-2020-0881 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.8% | 12 March 2020 |
| CVE-2020-0872 | A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application… | CRITICAL 9.6EPSS 10.1% | 12 March 2020 |
| CVE-2020-0855 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 12 March 2020 |
| CVE-2020-0852 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.0% | 12 March 2020 |
| CVE-2020-0851 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 11.8% | 12 March 2020 |
| CVE-2020-0827 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 13.3% | 12 March 2020 |
| CVE-2020-0825 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 13.3% | 12 March 2020 |
| CVE-2020-0816 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | HIGH 8.8EPSS 10.7% | 12 March 2020 |
| CVE-2020-0796 | Microsoft SMBv3 Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.8% | 12 March 2020 |
| CVE-2020-0787 | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 42.5% | 12 March 2020 |
| CVE-2020-10386 | admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory. | HIGH 7.2EPSS 12.3% | 12 March 2020 |
| CVE-2020-1947 | SnakeYAML allows to unmarshal data to a Java type By using the YAML tag. | CRITICAL 9.8EPSS 33.9% | 11 March 2020 |
| CVE-2020-8540 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML… | CRITICAL 9.8EPSS 12.8% | 11 March 2020 |
| CVE-2020-10181 | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | KEVCRITICAL 9.8EPSS 14.7% | 11 March 2020 |
| CVE-2020-6207 | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 98.3% | 10 March 2020 |
| CVE-2017-10992 | In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461. | CRITICAL 9.8EPSS 10.5% | 10 March 2020 |
| CVE-2020-2140 | Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability. | MEDIUM 6.1EPSS 76.0% | 9 March 2020 |
| CVE-2016-11021 | D-Link DCS-930L Devices OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 68.9% | 9 March 2020 |
| CVE-2020-10221 | rConfig OS Command Injection Vulnerability | KEVHIGH 8.8EPSS 80.2% | 8 March 2020 |
| CVE-2020-10220 | The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. | CRITICAL 9.8EPSS 99.7% | 7 March 2020 |
| CVE-2020-10214 | There is a stack-based buffer overflow in the httpd binary. | HIGH 8.8EPSS 18.3% | 7 March 2020 |
| CVE-2020-10189 | Zoho ManageEngine Desktop Central File Upload Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 6 March 2020 |
| CVE-2020-10188 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. | CRITICAL 9.8EPSS 74.3% | 6 March 2020 |
| CVE-2020-5405 | Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. | MEDIUM 6.5EPSS 68.8% | 5 March 2020 |
| CVE-2020-9402 | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. | HIGH 8.8EPSS 22.5% | 5 March 2020 |
| CVE-2020-10173 | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi. | HIGH 8.8EPSS 77.1% | 5 March 2020 |
| CVE-2019-20501 | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip… | HIGH 7.8EPSS 90.5% | 5 March 2020 |
| CVE-2019-20500 | D-Link DWL-2600AP Access Point Command Injection Vulnerability | KEVHIGH 7.8EPSS 97.1% | 5 March 2020 |
| CVE-2019-20499 | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or… | HIGH 7.8EPSS 95.3% | 5 March 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.