Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,941 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 82 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-33731 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). | HIGH 7.2EPSS 46.6% | 12 October 2021 |
| CVE-2021-33730 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). | HIGH 7.2EPSS 27.7% | 12 October 2021 |
| CVE-2021-24563 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone… | MEDIUM 6.1EPSS 26.4% | 11 October 2021 |
| CVE-2021-37976 | Google Chromium Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 19.7% | 8 October 2021 |
| CVE-2021-37975 | Google Chromium V8 Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 34.9% | 8 October 2021 |
| CVE-2021-37973 | Google Chromium Portals Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 11.6% | 8 October 2021 |
| CVE-2021-30633 | Google Chromium Indexed DB API Use-After-Free Vulnerability | KEVCRITICAL 9.6EPSS 32.7% | 8 October 2021 |
| CVE-2021-30632 | Google Chromium V8 Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 63.2% | 8 October 2021 |
| CVE-2021-30625 | Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 10.1% | 8 October 2021 |
| CVE-2021-42071 | In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header. | CRITICAL 9.8EPSS 69.9% | 7 October 2021 |
| CVE-2021-42013 | Apache HTTP Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 7 October 2021 |
| CVE-2021-37926 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 73.6% | 7 October 2021 |
| CVE-2021-37924 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 11.0% | 7 October 2021 |
| CVE-2021-37923 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 11.0% | 7 October 2021 |
| CVE-2021-37921 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 11.0% | 7 October 2021 |
| CVE-2021-37920 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 11.0% | 7 October 2021 |
| CVE-2021-37919 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 11.0% | 7 October 2021 |
| CVE-2021-37918 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | CRITICAL 9.8EPSS 73.6% | 7 October 2021 |
| CVE-2021-40978 | The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. | HIGH 7.5EPSS 15.1% | 7 October 2021 |
| CVE-2021-22930 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. | CRITICAL 9.8EPSS 36.5% | 7 October 2021 |
| CVE-2021-32172 | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | CRITICAL 9.8EPSS 66.4% | 7 October 2021 |
| CVE-2021-39226 | Grafana Authentication Bypass Vulnerability | KEVHIGH 7.3EPSS 99.9% | 5 October 2021 |
| CVE-2021-41773 | Apache HTTP Server Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 5 October 2021 |
| CVE-2021-41524 | While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. | HIGH 7.5EPSS 25.2% | 5 October 2021 |
| CVE-2021-41578 | mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. | HIGH 7.8EPSS 10.8% | 4 October 2021 |
| CVE-2021-32675 | An attacker delivering specially crafted requests over multiple connections can cause the server to allocate significant amount of memory. | HIGH 7.5EPSS 16.9% | 4 October 2021 |
| CVE-2021-32628 | An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. | HIGH 7.5EPSS 13.5% | 4 October 2021 |
| CVE-2021-32626 | In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. | HIGH 8.8EPSS 16.2% | 4 October 2021 |
| CVE-2021-40324 | Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. | HIGH 7.5EPSS 68.6% | 4 October 2021 |
| CVE-2021-40323 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. | CRITICAL 9.8EPSS 86.8% | 4 October 2021 |
| CVE-2021-41649 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. | CRITICAL 9.8EPSS 51.8% | 1 October 2021 |
| CVE-2021-41648 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. | HIGH 7.5EPSS 10.2% | 1 October 2021 |
| CVE-2021-41288 | Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. | CRITICAL 9.8EPSS 79.6% | 30 September 2021 |
| CVE-2021-41293 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. | HIGH 7.5EPSS 19.9% | 30 September 2021 |
| CVE-2021-41291 | ECOA BAS controller suffers from a path traversal content disclosure vulnerability. | HIGH 7.5EPSS 82.7% | 30 September 2021 |
| CVE-2021-41826 | PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect. | MEDIUM 6.1EPSS 12.1% | 30 September 2021 |
| CVE-2021-39863 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted PDF file. | HIGH 7.8EPSS 13.2% | 29 September 2021 |
| CVE-2021-39843 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 76.7% | 29 September 2021 |
| CVE-2021-39842 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. | HIGH 7.8EPSS 17.4% | 29 September 2021 |
| CVE-2021-39841 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability. | HIGH 7.8EPSS 11.7% | 29 September 2021 |
| CVE-2021-39840 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context… | HIGH 7.8EPSS 50.6% | 29 September 2021 |
| CVE-2021-39839 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code… | HIGH 7.8EPSS 65.2% | 29 September 2021 |
| CVE-2021-39838 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetCaption action that could result in… | HIGH 7.8EPSS 65.2% | 29 September 2021 |
| CVE-2021-39837 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary… | HIGH 7.8EPSS 65.2% | 29 September 2021 |
| CVE-2021-39836 | Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary… | HIGH 7.8EPSS 69.5% | 29 September 2021 |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary file from the server's filesystem as long as the application has access to the file. | MEDIUM 6.5EPSS 17.9% | 29 September 2021 |
| CVE-2021-20034 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. | CRITICAL 9.1EPSS 81.0% | 27 September 2021 |
| CVE-2021-37539 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | CRITICAL 9.8EPSS 92.9% | 27 September 2021 |
| CVE-2021-40655 | D-Link DIR-605 Router Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 86.7% | 24 September 2021 |
| CVE-2021-36749 | However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. | MEDIUM 6.5EPSS 80.9% | 24 September 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.