Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,941 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 80 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-22053 | Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. | HIGH 8.8EPSS 13.2% | 19 November 2021 |
| CVE-2021-44026 | Roundcube Webmail SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 41.9% | 19 November 2021 |
| CVE-2021-41277 | Metabase GeoJSON API Local File Inclusion Vulnerability | KEVHIGH 7.5EPSS 97.2% | 17 November 2021 |
| CVE-2021-42362 | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload… | HIGH 8.8EPSS 79.8% | 17 November 2021 |
| CVE-2021-3958 | Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Injection.This issue affects Ipack SCADA Software: from unspecified before 1.1.0. | CRITICAL 9.8EPSS 14.5% | 16 November 2021 |
| CVE-2021-37580 | The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. | CRITICAL 9.8EPSS 41.9% | 16 November 2021 |
| CVE-2021-41266 | Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. | CRITICAL 9.8EPSS 48.4% | 15 November 2021 |
| CVE-2021-41951 | ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. | MEDIUM 6.1EPSS 77.9% | 15 November 2021 |
| CVE-2021-41950 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. | CRITICAL 9.1EPSS 74.9% | 15 November 2021 |
| CVE-2021-41765 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. | CRITICAL 9.8EPSS 67.8% | 15 November 2021 |
| CVE-2020-16152 | The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then… | CRITICAL 9.8EPSS 35.5% | 14 November 2021 |
| CVE-2021-43617 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based… | CRITICAL 9.8EPSS 19.8% | 14 November 2021 |
| CVE-2021-41653 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. | CRITICAL 9.8EPSS 76.0% | 13 November 2021 |
| CVE-2021-3577 | An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. | HIGH 8.8EPSS 60.2% | 12 November 2021 |
| CVE-2021-43496 | Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. | HIGH 7.5EPSS 15.9% | 12 November 2021 |
| CVE-2021-21699 | Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure… | MEDIUM 5.4EPSS 88.5% | 12 November 2021 |
| CVE-2002-20001 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater… | HIGH 7.5EPSS 24.6% | 11 November 2021 |
| CVE-2021-42847 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | CRITICAL 9.8EPSS 70.3% | 11 November 2021 |
| CVE-2021-41081 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search. | CRITICAL 9.8EPSS 64.1% | 11 November 2021 |
| CVE-2021-33618 | Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature. | MEDIUM 6.1EPSS 79.3% | 10 November 2021 |
| CVE-2021-22048 | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. | HIGH 8.8EPSS 10.3% | 10 November 2021 |
| CVE-2021-3064 | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. | CRITICAL 9.8EPSS 20.1% | 10 November 2021 |
| CVE-2021-3060 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with… | HIGH 8.1EPSS 33.9% | 10 November 2021 |
| CVE-2021-43136 | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform. | CRITICAL 9.8EPSS 15.7% | 10 November 2021 |
| CVE-2021-42321 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 91.7% | 10 November 2021 |
| CVE-2021-42292 | Microsoft Excel Security Feature Bypass | KEVHIGH 7.8EPSS 43.0% | 10 November 2021 |
| CVE-2021-42287 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 7.5EPSS 77.2% | 10 November 2021 |
| CVE-2021-42278 | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | KEVHIGH 7.5EPSS 73.3% | 10 November 2021 |
| CVE-2021-41379 | Microsoft Windows Installer Privilege Escalation Vulnerability | KEVMEDIUM 5.5EPSS 19.5% | 10 November 2021 |
| CVE-2021-41349 | Microsoft Exchange Server Spoofing Vulnerability | MEDIUM 6.5EPSS 93.5% | 10 November 2021 |
| CVE-2021-38666 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH 8.8EPSS 15.1% | 10 November 2021 |
| CVE-2021-24827 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue | CRITICAL 9.8EPSS 12.6% | 8 November 2021 |
| CVE-2021-31602 | The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials. | HIGH 7.5EPSS 51.7% | 8 November 2021 |
| CVE-2021-43405 | An issue was discovered in FusionPBX before 4.5.30. | HIGH 8.8EPSS 35.6% | 5 November 2021 |
| CVE-2021-42671 | An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. | HIGH 7.5EPSS 19.7% | 5 November 2021 |
| CVE-2021-42669 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. | CRITICAL 9.8EPSS 23.3% | 5 November 2021 |
| CVE-2021-42667 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. | CRITICAL 9.8EPSS 16.0% | 5 November 2021 |
| CVE-2021-42237 | Sitecore XP Remote Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.9% | 5 November 2021 |
| CVE-2021-39906 | Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf. | MEDIUM 6.1EPSS 60.7% | 5 November 2021 |
| CVE-2021-38488 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter comment of the API events, which may allow an attacker to remotely… | MEDIUM 4.8EPSS 12.3% | 3 November 2021 |
| CVE-2021-38428 | Delta Electronics DIALink versions 1.2.4.0 and prior is vulnerable to cross-site scripting because an authenticated attacker can inject arbitrary JavaScript code into the parameter name of the API schedule, which may allow an attacker to remotely… | MEDIUM 4.8EPSS 11.4% | 3 November 2021 |
| CVE-2021-41174 | In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. | MEDIUM 6.1EPSS 85.4% | 3 November 2021 |
| CVE-2021-39238 | Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnerable to potential buffer overflow. | CRITICAL 9.8EPSS 12.1% | 3 November 2021 |
| CVE-2021-43267 | The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. | CRITICAL 9.8EPSS 57.9% | 2 November 2021 |
| CVE-2021-42697 | Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments. | HIGH 7.5EPSS 36.1% | 2 November 2021 |
| CVE-2021-39341 | The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to… | HIGH 8.2EPSS 21.9% | 1 November 2021 |
| CVE-2021-20136 | ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. | CRITICAL 9.8EPSS 10.8% | 1 November 2021 |
| CVE-2021-29212 | A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. | CRITICAL 9.8EPSS 13.9% | 1 November 2021 |
| CVE-2021-42574 | Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. | HIGH 8.3EPSS 12.9% | 1 November 2021 |
| CVE-2021-30833 | Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files. | MEDIUM 5.5EPSS 42.7% | 28 October 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.