Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,894 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 78 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-31589 | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper… | MEDIUM 6.1EPSS 29.5% | 5 January 2022 |
| CVE-2022-21647 | Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. | CRITICAL 9.8EPSS 37.7% | 4 January 2022 |
| CVE-2021-43711 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. | CRITICAL 9.8EPSS 37.8% | 4 January 2022 |
| CVE-2021-43942 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. | MEDIUM 6.1EPSS 55.4% | 4 January 2022 |
| CVE-2021-45428 | TLR-2005KSH is affected by an incorrect access control vulnerability. | CRITICAL 9.8EPSS 56.9% | 3 January 2022 |
| CVE-2021-24786 | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue | HIGH 7.2EPSS 17.3% | 3 January 2022 |
| CVE-2021-20158 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. | CRITICAL 9.8EPSS 10.9% | 30 December 2021 |
| CVE-2021-20150 | Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. | MEDIUM 5.3EPSS 40.1% | 30 December 2021 |
| CVE-2021-45427 | Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. | CRITICAL 9.8EPSS 19.2% | 30 December 2021 |
| CVE-2021-44832 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has… | MEDIUM 6.6EPSS 97.9% | 28 December 2021 |
| CVE-2021-43858 | Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. | HIGH 8.8EPSS 35.5% | 27 December 2021 |
| CVE-2021-43857 | Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8. | HIGH 8.8EPSS 55.3% | 27 December 2021 |
| CVE-2021-45232 | In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly… | CRITICAL 9.8EPSS 85.9% | 27 December 2021 |
| CVE-2021-45511 | Certain NETGEAR devices are affected by authentication bypass. | CRITICAL 9.8EPSS 17.6% | 26 December 2021 |
| CVE-2021-45461 | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. | CRITICAL 9.8EPSS 21.7% | 22 December 2021 |
| CVE-2021-40418 | Due to the object property being uninitialized, this can result in dereferencing an arbitrary pointer for the object’s virtual method table, which can result in code execution under the context of the application. | CRITICAL 9.8EPSS 17.9% | 22 December 2021 |
| CVE-2021-40417 | Due to an integer overflow with regards to this calculation, this can result in an undersized heap buffer being allocated. | CRITICAL 9.8EPSS 15.7% | 22 December 2021 |
| CVE-2021-31558 | DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. | MEDIUM 6.1EPSS 10.6% | 22 December 2021 |
| CVE-2021-21924 | A specially-crafted HTTP request can lead to SQL injection. | MEDIUM 6.5EPSS 20.2% | 22 December 2021 |
| CVE-2021-21892 | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). | CRITICAL 9.9EPSS 30.4% | 22 December 2021 |
| CVE-2021-21881 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. | CRITICAL 9.9EPSS 36.2% | 22 December 2021 |
| CVE-2021-36750 | ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names). | HIGH 8.1EPSS 13.5% | 22 December 2021 |
| CVE-2021-44207 | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | KEVHIGH 8.1EPSS 17.6% | 21 December 2021 |
| CVE-2021-24750 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to… | HIGH 8.8EPSS 38.3% | 21 December 2021 |
| CVE-2021-44790 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). | CRITICAL 9.8EPSS 96.8% | 20 December 2021 |
| CVE-2021-44224 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix… | HIGH 8.2EPSS 82.3% | 20 December 2021 |
| CVE-2021-45105 | This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. | MEDIUM 5.9EPSS 100.0% | 18 December 2021 |
| CVE-2021-23450 | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | CRITICAL 9.8EPSS 30.4% | 17 December 2021 |
| CVE-2021-22054 | Omnissa Workspace ONE Server-Side Request Forgery | KEVHIGH 7.5EPSS 97.4% | 17 December 2021 |
| CVE-2021-41843 | An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the… | MEDIUM 6.5EPSS 13.7% | 17 December 2021 |
| CVE-2021-42912 | FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. | HIGH 8.8EPSS 10.1% | 16 December 2021 |
| CVE-2021-45092 | Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. | CRITICAL 9.8EPSS 40.0% | 16 December 2021 |
| CVE-2021-4119 | bookstack is vulnerable to Improper Access Control | CRITICAL 9.8EPSS 26.9% | 15 December 2021 |
| CVE-2021-43891 | Visual Studio Code Remote Code Execution Vulnerability | HIGH 7.8EPSS 13.1% | 15 December 2021 |
| CVE-2021-43890 | Microsoft Windows AppX Installer Spoofing Vulnerability | KEVHIGH 7.1EPSS 10.3% | 15 December 2021 |
| CVE-2021-43883 | Windows Installer Elevation of Privilege Vulnerability | HIGH 7.8EPSS 12.0% | 15 December 2021 |
| CVE-2021-45043 | HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. | HIGH 7.5EPSS 33.1% | 15 December 2021 |
| CVE-2021-41560 | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. | CRITICAL 9.8EPSS 11.1% | 15 December 2021 |
| CVE-2021-36450 | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. | MEDIUM 6.1EPSS 64.3% | 15 December 2021 |
| CVE-2021-43829 | This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. | HIGH 8.8EPSS 59.2% | 14 December 2021 |
| CVE-2021-45046 | Apache Log4j2 Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.0EPSS 100.0% | 14 December 2021 |
| CVE-2021-4044 | The exact behaviour will depend on the application but it could result in crashes, infinite loops or other similar incorrect responses. | HIGH 7.5EPSS 50.1% | 14 December 2021 |
| CVE-2021-42063 | A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. | MEDIUM 6.1EPSS 22.2% | 14 December 2021 |
| CVE-2021-39312 | The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file. | HIGH 7.5EPSS 77.9% | 14 December 2021 |
| CVE-2021-4104 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. | HIGH 7.5EPSS 81.1% | 14 December 2021 |
| CVE-2021-39935 | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 7.5EPSS 35.6% | 13 December 2021 |
| CVE-2021-24946 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated… | CRITICAL 9.8EPSS 72.8% | 13 December 2021 |
| CVE-2021-44152 | This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account. | CRITICAL 9.8EPSS 58.6% | 13 December 2021 |
| CVE-2021-40856 | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. | HIGH 7.5EPSS 50.1% | 13 December 2021 |
| CVE-2021-44848 | In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists. | MEDIUM 5.3EPSS 23.0% | 13 December 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.