SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,951 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 83 of 348

CVESummaryPriorityPublished
CVE-2021-41381Payara Micro Community 5.2021.6 and below allows Directory Traversal.HIGH 7.5EPSS 52.9%23 September 2021
CVE-2021-22941Citrix ShareFile Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 53.6%23 September 2021
CVE-2021-22017VMware vCenter Server Improper Access ControlKEVMEDIUM 5.3EPSS 49.2%23 September 2021
CVE-2021-22005VMware vCenter Server File Upload VulnerabilityKEVCRITICAL 9.8EPSS 100.0%23 September 2021
CVE-2021-33035A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack.HIGH 7.8EPSS 50.6%23 September 2021
CVE-2021-40875Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.HIGH 7.5EPSS 48.4%22 September 2021
CVE-2021-37925Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.CRITICAL 9.8EPSS 10.5%22 September 2021
CVE-2021-36260Hikvision Improper Input ValidationKEVCRITICAL 9.8EPSS 99.9%22 September 2021
CVE-2021-40847The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack.HIGH 8.1EPSS 10.0%21 September 2021
CVE-2021-38406Delta Electronics DOPSoft 2 Improper Input Validation VulnerabilityKEVHIGH 7.8EPSS 76.4%17 September 2021
CVE-2021-39327The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of…MEDIUM 5.3EPSS 71.7%17 September 2021
CVE-2021-41303Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass.CRITICAL 9.8EPSS 76.7%17 September 2021
CVE-2021-41314Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2"…HIGH 8.8EPSS 13.6%16 September 2021
CVE-2021-40438Apache HTTP Server-Side Request Forgery (SSRF)KEVCRITICAL 9.0EPSS 100.0%16 September 2021
CVE-2021-39275ap_escape_quotes() may write beyond the end of a buffer when given malicious input.CRITICAL 9.8EPSS 39.4%16 September 2021
CVE-2021-36160A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS).HIGH 7.5EPSS 62.9%16 September 2021
CVE-2021-34798Malformed requests may cause the server to dereference a NULL pointer.HIGH 7.5EPSS 64.5%16 September 2021
CVE-2021-33045Dahua IP Camera Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.6%15 September 2021
CVE-2021-33044Dahua IP Camera Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.9%15 September 2021
CVE-2021-33690Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service…CRITICAL 9.9EPSS 69.1%15 September 2021
CVE-2021-38156In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.MEDIUM 5.4EPSS 88.9%15 September 2021
CVE-2021-21798An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF.HIGH 7.8EPSS 16.0%15 September 2021
CVE-2021-40444Microsoft MSHTML Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 97.5%15 September 2021
CVE-2021-38648Microsoft Open Management Infrastructure (OMI) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 11.4%15 September 2021
CVE-2021-38647Microsoft Open Management Infrastructure (OMI) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%15 September 2021
CVE-2021-36952Visual Studio Remote Code Execution VulnerabilityHIGH 7.8EPSS 51.2%15 September 2021
CVE-2021-38163SAP NetWeaver Unrestricted File Upload VulnerabilityKEVHIGH 8.8EPSS 36.0%14 September 2021
CVE-2021-37200A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1).HIGH 7.7EPSS 37.4%14 September 2021
CVE-2021-33554Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 57.0%13 September 2021
CVE-2021-33553Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 48.8%13 September 2021
CVE-2021-33552Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 48.8%13 September 2021
CVE-2021-33551Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 48.8%13 September 2021
CVE-2021-33550Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 57.0%13 September 2021
CVE-2021-33549Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 66.2%13 September 2021
CVE-2021-33548Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 57.0%13 September 2021
CVE-2021-33544Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.HIGH 7.2EPSS 95.3%13 September 2021
CVE-2021-33543Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings.CRITICAL 9.8EPSS 81.3%13 September 2021
CVE-2021-40870Aviatrix Controller Unrestricted Upload of FileKEVCRITICAL 9.8EPSS 93.0%13 September 2021
CVE-2021-24040Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks.CRITICAL 9.8EPSS 17.4%10 September 2021
CVE-2021-38540This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution.CRITICAL 9.8EPSS 80.9%9 September 2021
CVE-2021-38408A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.CRITICAL 9.8EPSS 11.6%9 September 2021
CVE-2021-40346An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.HIGH 7.5EPSS 57.9%8 September 2021
CVE-2021-30657Apple macOS Unspecified VulnerabilityKEVMEDIUM 5.5EPSS 68.5%8 September 2021
CVE-2021-35217Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI.HIGH 8.8EPSS 72.8%8 September 2021
CVE-2021-30762Apple iOS WebKit Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 11.0%8 September 2021
CVE-2021-30761Apple iOS WebKit Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 10.5%8 September 2021
CVE-2021-30721An attacker in a privileged network position may be able to leak sensitive user information.MEDIUM 6.5EPSS 24.3%8 September 2021
CVE-2020-11301Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer…HIGH 7.5EPSS 11.1%8 September 2021
CVE-2020-11264Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…CRITICAL 9.8EPSS 13.2%8 September 2021
CVE-2021-40539Zoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.0%7 September 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.