SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,810 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 112 of 348

CVESummaryPriorityPublished
CVE-2020-9054Zyxel Multiple NAS Devices OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%4 March 2020
CVE-2020-9757The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.CRITICAL 9.8EPSS 72.8%4 March 2020
CVE-2020-8437The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.HIGH 7.5EPSS 12.0%2 March 2020
CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion VulnerabilityKEVHIGH 8.8EPSS 46.3%2 March 2020
CVE-2020-9548FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).CRITICAL 9.8EPSS 18.3%2 March 2020
CVE-2020-9547FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).CRITICAL 9.8EPSS 18.4%2 March 2020
CVE-2020-9465The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.CRITICAL 9.8EPSS 82.2%28 February 2020
CVE-2020-6418Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 78.8%27 February 2020
CVE-2020-3837Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 16.1%27 February 2020
CVE-2015-0565NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.CRITICAL 10.0EPSS 13.6%25 February 2020
CVE-2020-8794OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.CRITICAL 9.8EPSS 88.9%25 February 2020
CVE-2020-1938Apache Tomcat Improper Privilege Management VulnerabilityKEVCRITICAL 9.8EPSS 99.3%24 February 2020
CVE-2020-9374On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.CRITICAL 9.8EPSS 42.7%24 February 2020
CVE-2020-4222IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 15.5%24 February 2020
CVE-2020-4213IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 15.5%24 February 2020
CVE-2020-4212IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 15.0%24 February 2020
CVE-2020-4211IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 71.1%24 February 2020
CVE-2020-4210IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system.CRITICAL 9.8EPSS 15.5%24 February 2020
CVE-2020-8813graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.HIGH 8.8EPSS 73.8%22 February 2020
CVE-2020-8862This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers.HIGH 8.8EPSS 13.3%22 February 2020
CVE-2020-9015Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character.CRITICAL 9.8EPSS 16.5%20 February 2020
CVE-2020-9283golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package.HIGH 7.5EPSS 20.5%20 February 2020
CVE-2014-4019ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.HIGH 7.5EPSS 12.7%20 February 2020
CVE-2014-4650The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended…CRITICAL 9.8EPSS 24.7%20 February 2020
CVE-2020-9273In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.HIGH 8.8EPSS 12.0%20 February 2020
CVE-2012-5364The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.HIGH 7.5EPSS 14.5%20 February 2020
CVE-2012-5362The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2010-4669.HIGH 7.5EPSS 14.5%20 February 2020
CVE-2020-3153Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path VulnerabilityKEVMEDIUM 6.5EPSS 28.3%19 February 2020
CVE-2014-9614The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.CRITICAL 9.8EPSS 68.7%19 February 2020
CVE-2014-9609Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a ..MEDIUM 5.3EPSS 12.6%19 February 2020
CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery VulnerabilityKEVCRITICAL 9.8EPSS 84.4%18 February 2020
CVE-2013-2679Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5)…MEDIUM 6.1EPSS 19.6%18 February 2020
CVE-2020-8012CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component.CRITICAL 9.8EPSS 77.4%18 February 2020
CVE-2020-8010CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component.CRITICAL 9.8EPSS 50.7%18 February 2020
CVE-2014-7236Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.CRITICAL 9.1EPSS 55.6%17 February 2020
CVE-2015-6922Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an…CRITICAL 9.8EPSS 82.1%17 February 2020
CVE-2020-8518Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.CRITICAL 9.8EPSS 71.7%17 February 2020
CVE-2013-4211A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP codeCRITICAL 9.8EPSS 70.7%14 February 2020
CVE-2020-8856This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608.HIGH 7.8EPSS 19.8%14 February 2020
CVE-2020-8846This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114.HIGH 7.8EPSS 19.8%14 February 2020
CVE-2020-8845This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114.HIGH 7.8EPSS 19.5%14 February 2020
CVE-2020-8844This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114.HIGH 7.8EPSS 23.7%14 February 2020
CVE-2015-6589Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary…HIGH 8.8EPSS 13.6%13 February 2020
CVE-2014-4170A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.CRITICAL 9.8EPSS 14.5%13 February 2020
CVE-2020-3757Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability.HIGH 8.8EPSS 10.2%13 February 2020
CVE-2020-7209LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.CRITICAL 9.8EPSS 98.8%13 February 2020
CVE-2011-4908TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.CRITICAL 9.8EPSS 55.8%12 February 2020
CVE-2020-8947functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than…HIGH 7.2EPSS 22.5%12 February 2020
CVE-2020-7046lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.HIGH 7.5EPSS 51.3%12 February 2020
CVE-2013-6236IZON IP 2.0.2: hard-coded password vulnerabilityCRITICAL 9.8EPSS 10.2%12 February 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.