Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,941 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 79 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-44515 | Zoho Desktop Central Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 12 December 2021 |
| CVE-2021-41805 | An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace. | HIGH 8.8EPSS 34.8% | 12 December 2021 |
| CVE-2021-43813 | Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. | MEDIUM 4.3EPSS 57.5% | 10 December 2021 |
| CVE-2021-44228 | Apache Log4j2 Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 10 December 2021 |
| CVE-2021-43803 | In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. | HIGH 7.5EPSS 44.8% | 10 December 2021 |
| CVE-2021-3817 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | CRITICAL 9.8EPSS 38.4% | 9 December 2021 |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.1% | 8 December 2021 |
| CVE-2021-43527 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. | CRITICAL 9.8EPSS 17.6% | 8 December 2021 |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | KEVHIGH 8.8EPSS 39.8% | 8 December 2021 |
| CVE-2021-20045 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. | CRITICAL 9.8EPSS 25.2% | 8 December 2021 |
| CVE-2021-20044 | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. | HIGH 8.8EPSS 40.1% | 8 December 2021 |
| CVE-2021-20043 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. | HIGH 8.8EPSS 23.3% | 8 December 2021 |
| CVE-2021-20040 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. | HIGH 7.5EPSS 25.1% | 8 December 2021 |
| CVE-2021-20039 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. | HIGH 8.8EPSS 78.7% | 8 December 2021 |
| CVE-2021-20038 | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 8 December 2021 |
| CVE-2021-38759 | If not changed, attackers can gain administrator privileges. | CRITICAL 9.8EPSS 15.7% | 7 December 2021 |
| CVE-2021-43798 | Grafana Path Traversal Vulnerability | KEVHIGH 7.5EPSS 88.5% | 7 December 2021 |
| CVE-2021-40859 | Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device. | CRITICAL 9.8EPSS 72.0% | 7 December 2021 |
| CVE-2021-42132 | A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | HIGH 8.8EPSS 70.1% | 7 December 2021 |
| CVE-2021-42131 | A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | HIGH 8.8EPSS 66.5% | 7 December 2021 |
| CVE-2021-42130 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution. | HIGH 8.8EPSS 62.2% | 7 December 2021 |
| CVE-2021-42129 | A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | HIGH 8.8EPSS 77.3% | 7 December 2021 |
| CVE-2021-42127 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service. | CRITICAL 9.8EPSS 65.8% | 7 December 2021 |
| CVE-2021-42125 | An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | HIGH 8.8EPSS 81.6% | 7 December 2021 |
| CVE-2021-43936 | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution. | CRITICAL 9.8EPSS 35.8% | 6 December 2021 |
| CVE-2021-24931 | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a… | CRITICAL 9.8EPSS 78.8% | 6 December 2021 |
| CVE-2021-24917 | The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user. | HIGH 7.5EPSS 71.5% | 6 December 2021 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 83.6% | 3 December 2021 |
| CVE-2021-44352 | A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind. | CRITICAL 9.8EPSS 13.4% | 3 December 2021 |
| CVE-2021-33266 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_8004776c in /formVirtualApp. | CRITICAL 9.8EPSS 16.9% | 1 December 2021 |
| CVE-2021-33265 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80046eb4 in /formSetPortTr. | CRITICAL 9.8EPSS 13.7% | 1 December 2021 |
| CVE-2021-43319 | Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. | CRITICAL 9.8EPSS 21.4% | 30 November 2021 |
| CVE-2021-44427 | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear… | CRITICAL 9.8EPSS 50.6% | 29 November 2021 |
| CVE-2021-43788 | Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. | MEDIUM 5.0EPSS 25.8% | 29 November 2021 |
| CVE-2021-24915 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow… | CRITICAL 9.8EPSS 12.7% | 29 November 2021 |
| CVE-2021-38147 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to… | HIGH 7.5EPSS 53.0% | 29 November 2021 |
| CVE-2021-21707 | In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. | MEDIUM 5.3EPSS 26.0% | 29 November 2021 |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 93.3% | 29 November 2021 |
| CVE-2021-44223 | This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet… | CRITICAL 9.8EPSS 29.0% | 25 November 2021 |
| CVE-2021-43778 | GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. | HIGH 7.5EPSS 52.7% | 24 November 2021 |
| CVE-2021-38003 | Google Chromium V8 Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 38.6% | 23 November 2021 |
| CVE-2021-38001 | Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 26.7% | 23 November 2021 |
| CVE-2021-36301 | Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. | HIGH 7.2EPSS 27.7% | 23 November 2021 |
| CVE-2021-36300 | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. | HIGH 8.2EPSS 33.3% | 23 November 2021 |
| CVE-2021-36299 | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. | HIGH 8.1EPSS 29.6% | 23 November 2021 |
| CVE-2021-24891 | The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue. | MEDIUM 6.1EPSS 25.1% | 23 November 2021 |
| CVE-2021-42727 | Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 39.4% | 22 November 2021 |
| CVE-2021-43557 | This makes it possible to construct a URI to bypass the block list on some occasions. | HIGH 7.5EPSS 12.9% | 22 November 2021 |
| CVE-2021-38146 | The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data. | HIGH 7.5EPSS 11.9% | 22 November 2021 |
| CVE-2021-43555 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. | HIGH 7.8EPSS 38.2% | 19 November 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.