Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 112 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-9054 | Zyxel Multiple NAS Devices OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 March 2020 |
| CVE-2020-9757 | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | CRITICAL 9.8EPSS 72.8% | 4 March 2020 |
| CVE-2020-8437 | The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service. | HIGH 7.5EPSS 12.0% | 2 March 2020 |
| CVE-2019-17026 | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | KEVHIGH 8.8EPSS 46.3% | 2 March 2020 |
| CVE-2020-9548 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). | CRITICAL 9.8EPSS 18.3% | 2 March 2020 |
| CVE-2020-9547 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). | CRITICAL 9.8EPSS 18.4% | 2 March 2020 |
| CVE-2020-9465 | The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie. | CRITICAL 9.8EPSS 82.2% | 28 February 2020 |
| CVE-2020-6418 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 78.8% | 27 February 2020 |
| CVE-2020-3837 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 16.1% | 27 February 2020 |
| CVE-2015-0565 | NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. | CRITICAL 10.0EPSS 13.6% | 25 February 2020 |
| CVE-2020-8794 | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. | CRITICAL 9.8EPSS 88.9% | 25 February 2020 |
| CVE-2020-1938 | Apache Tomcat Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 99.3% | 24 February 2020 |
| CVE-2020-9374 | On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature. | CRITICAL 9.8EPSS 42.7% | 24 February 2020 |
| CVE-2020-4222 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. | CRITICAL 9.8EPSS 15.5% | 24 February 2020 |
| CVE-2020-4213 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. | CRITICAL 9.8EPSS 15.5% | 24 February 2020 |
| CVE-2020-4212 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. | CRITICAL 9.8EPSS 15.0% | 24 February 2020 |
| CVE-2020-4211 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. | CRITICAL 9.8EPSS 71.1% | 24 February 2020 |
| CVE-2020-4210 | IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. | CRITICAL 9.8EPSS 15.5% | 24 February 2020 |
| CVE-2020-8813 | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. | HIGH 8.8EPSS 73.8% | 22 February 2020 |
| CVE-2020-8862 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. | HIGH 8.8EPSS 13.3% | 22 February 2020 |
| CVE-2020-9015 | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. | CRITICAL 9.8EPSS 16.5% | 20 February 2020 |
| CVE-2020-9283 | golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. | HIGH 7.5EPSS 20.5% | 20 February 2020 |
| CVE-2014-4019 | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0. | HIGH 7.5EPSS 12.7% | 20 February 2020 |
| CVE-2014-4650 | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended… | CRITICAL 9.8EPSS 24.7% | 20 February 2020 |
| CVE-2020-9273 | In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. | HIGH 8.8EPSS 12.0% | 20 February 2020 |
| CVE-2012-5364 | The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries. | HIGH 7.5EPSS 14.5% | 20 February 2020 |
| CVE-2012-5362 | The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2010-4669. | HIGH 7.5EPSS 14.5% | 20 February 2020 |
| CVE-2020-3153 | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | KEVMEDIUM 6.5EPSS 28.3% | 19 February 2020 |
| CVE-2014-9614 | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. | CRITICAL 9.8EPSS 68.7% | 19 February 2020 |
| CVE-2014-9609 | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. | MEDIUM 5.3EPSS 12.6% | 19 February 2020 |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | KEVCRITICAL 9.8EPSS 84.4% | 18 February 2020 |
| CVE-2013-2679 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5)… | MEDIUM 6.1EPSS 19.6% | 18 February 2020 |
| CVE-2020-8012 | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. | CRITICAL 9.8EPSS 77.4% | 18 February 2020 |
| CVE-2020-8010 | CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. | CRITICAL 9.8EPSS 50.7% | 18 February 2020 |
| CVE-2014-7236 | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome. | CRITICAL 9.1EPSS 55.6% | 17 February 2020 |
| CVE-2015-6922 | Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an… | CRITICAL 9.8EPSS 82.1% | 17 February 2020 |
| CVE-2020-8518 | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. | CRITICAL 9.8EPSS 71.7% | 17 February 2020 |
| CVE-2013-4211 | A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code | CRITICAL 9.8EPSS 70.7% | 14 February 2020 |
| CVE-2020-8856 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. | HIGH 7.8EPSS 19.8% | 14 February 2020 |
| CVE-2020-8846 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. | HIGH 7.8EPSS 19.8% | 14 February 2020 |
| CVE-2020-8845 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. | HIGH 7.8EPSS 19.5% | 14 February 2020 |
| CVE-2020-8844 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. | HIGH 7.8EPSS 23.7% | 14 February 2020 |
| CVE-2015-6589 | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary… | HIGH 8.8EPSS 13.6% | 13 February 2020 |
| CVE-2014-4170 | A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information. | CRITICAL 9.8EPSS 14.5% | 13 February 2020 |
| CVE-2020-3757 | Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. | HIGH 8.8EPSS 10.2% | 13 February 2020 |
| CVE-2020-7209 | LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | CRITICAL 9.8EPSS 98.8% | 13 February 2020 |
| CVE-2011-4908 | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | CRITICAL 9.8EPSS 55.8% | 12 February 2020 |
| CVE-2020-8947 | functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than… | HIGH 7.2EPSS 22.5% | 12 February 2020 |
| CVE-2020-7046 | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop. | HIGH 7.5EPSS 51.3% | 12 February 2020 |
| CVE-2013-6236 | IZON IP 2.0.2: hard-coded password vulnerability | CRITICAL 9.8EPSS 10.2% | 12 February 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.