SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,941 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 82 of 348

CVESummaryPriorityPublished
CVE-2021-33731A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1).HIGH 7.2EPSS 46.6%12 October 2021
CVE-2021-33730A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1).HIGH 7.2EPSS 27.7%12 October 2021
CVE-2021-24563The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone…MEDIUM 6.1EPSS 26.4%11 October 2021
CVE-2021-37976Google Chromium Information Disclosure VulnerabilityKEVMEDIUM 6.5EPSS 19.7%8 October 2021
CVE-2021-37975Google Chromium V8 Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 34.9%8 October 2021
CVE-2021-37973Google Chromium Portals Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 11.6%8 October 2021
CVE-2021-30633Google Chromium Indexed DB API Use-After-Free VulnerabilityKEVCRITICAL 9.6EPSS 32.7%8 October 2021
CVE-2021-30632Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 63.2%8 October 2021
CVE-2021-30625Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 10.1%8 October 2021
CVE-2021-42071In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.CRITICAL 9.8EPSS 69.9%7 October 2021
CVE-2021-42013Apache HTTP Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%7 October 2021
CVE-2021-37926Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 73.6%7 October 2021
CVE-2021-37924Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 11.0%7 October 2021
CVE-2021-37923Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 11.0%7 October 2021
CVE-2021-37921Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 11.0%7 October 2021
CVE-2021-37920Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 11.0%7 October 2021
CVE-2021-37919Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 11.0%7 October 2021
CVE-2021-37918Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.CRITICAL 9.8EPSS 73.6%7 October 2021
CVE-2021-40978The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information.HIGH 7.5EPSS 15.1%7 October 2021
CVE-2021-22930Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.CRITICAL 9.8EPSS 36.5%7 October 2021
CVE-2021-32172Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.CRITICAL 9.8EPSS 66.4%7 October 2021
CVE-2021-39226Grafana Authentication Bypass VulnerabilityKEVHIGH 7.3EPSS 99.9%5 October 2021
CVE-2021-41773Apache HTTP Server Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%5 October 2021
CVE-2021-41524While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server.HIGH 7.5EPSS 25.2%5 October 2021
CVE-2021-41578mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files.HIGH 7.8EPSS 10.8%4 October 2021
CVE-2021-32675An attacker delivering specially crafted requests over multiple connections can cause the server to allocate significant amount of memory.HIGH 7.5EPSS 16.9%4 October 2021
CVE-2021-32628An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution.HIGH 7.5EPSS 13.5%4 October 2021
CVE-2021-32626In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition.HIGH 8.8EPSS 16.2%4 October 2021
CVE-2021-40324Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.HIGH 7.5EPSS 68.6%4 October 2021
CVE-2021-40323Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.CRITICAL 9.8EPSS 86.8%4 October 2021
CVE-2021-41649An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter.CRITICAL 9.8EPSS 51.8%1 October 2021
CVE-2021-41648An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter.HIGH 7.5EPSS 10.2%1 October 2021
CVE-2021-41288Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.CRITICAL 9.8EPSS 79.6%30 September 2021
CVE-2021-41293ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure.HIGH 7.5EPSS 19.9%30 September 2021
CVE-2021-41291ECOA BAS controller suffers from a path traversal content disclosure vulnerability.HIGH 7.5EPSS 82.7%30 September 2021
CVE-2021-41826PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.MEDIUM 6.1EPSS 12.1%30 September 2021
CVE-2021-39863Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted PDF file.HIGH 7.8EPSS 13.2%29 September 2021
CVE-2021-39843Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 76.7%29 September 2021
CVE-2021-39842Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user.HIGH 7.8EPSS 17.4%29 September 2021
CVE-2021-39841Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability.HIGH 7.8EPSS 11.7%29 September 2021
CVE-2021-39840Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context…HIGH 7.8EPSS 50.6%29 September 2021
CVE-2021-39839Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code…HIGH 7.8EPSS 65.2%29 September 2021
CVE-2021-39838Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetCaption action that could result in…HIGH 7.8EPSS 65.2%29 September 2021
CVE-2021-39837Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary…HIGH 7.8EPSS 65.2%29 September 2021
CVE-2021-39836Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary…HIGH 7.8EPSS 69.5%29 September 2021
CVE-2021-40651OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file.MEDIUM 6.5EPSS 17.9%29 September 2021
CVE-2021-20034An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.CRITICAL 9.1EPSS 81.0%27 September 2021
CVE-2021-37539Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.CRITICAL 9.8EPSS 92.9%27 September 2021
CVE-2021-40655D-Link DIR-605 Router Information Disclosure VulnerabilityKEVHIGH 7.5EPSS 86.7%24 September 2021
CVE-2021-36749However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process.MEDIUM 6.5EPSS 80.9%24 September 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.