SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,951 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 84 of 348

CVESummaryPriorityPublished
CVE-2021-40531Sketch before 75 allows library feeds to be used to bypass file quarantine.CRITICAL 9.8EPSS 32.8%6 September 2021
CVE-2021-38314The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but…MEDIUM 5.3EPSS 29.0%2 September 2021
CVE-2021-28560Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability.HIGH 8.8EPSS 66.9%2 September 2021
CVE-2021-28558Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Heap-based buffer overflow vulnerability in the PDFLibTool component.HIGH 8.8EPSS 10.4%2 September 2021
CVE-2021-28550Adobe Acrobat and Reader Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 52.0%2 September 2021
CVE-2021-34746A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device…CRITICAL 9.8EPSS 17.7%2 September 2021
CVE-2021-40382An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.HIGH 7.5EPSS 22.7%1 September 2021
CVE-2021-40381An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.HIGH 7.5EPSS 22.7%1 September 2021
CVE-2021-40380An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.HIGH 7.5EPSS 22.7%1 September 2021
CVE-2021-40379An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.HIGH 7.5EPSS 21.6%1 September 2021
CVE-2021-40378An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.HIGH 8.1EPSS 15.0%1 September 2021
CVE-2021-35218Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution.HIGH 8.8EPSS 76.4%1 September 2021
CVE-2021-35216Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module.HIGH 8.8EPSS 81.4%1 September 2021
CVE-2021-35215Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5.HIGH 8.8EPSS 69.7%1 September 2021
CVE-2021-39378A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database.CRITICAL 9.8EPSS 22.7%1 September 2021
CVE-2021-37415Zoho ManageEngine ServiceDesk Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 99.8%1 September 2021
CVE-2021-39316The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.HIGH 7.5EPSS 65.8%31 August 2021
CVE-2021-36356KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI).CRITICAL 9.8EPSS 54.4%31 August 2021
CVE-2021-34646Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link…CRITICAL 9.8EPSS 50.9%30 August 2021
CVE-2021-33055Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.CRITICAL 9.8EPSS 18.1%30 August 2021
CVE-2021-38393A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior.CRITICAL 9.8EPSS 18.5%30 August 2021
CVE-2021-38390A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior.CRITICAL 9.8EPSS 19.8%30 August 2021
CVE-2021-32955Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.CRITICAL 9.8EPSS 37.3%30 August 2021
CVE-2021-26084Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%30 August 2021
CVE-2021-39172Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server.HIGH 8.8EPSS 29.2%27 August 2021
CVE-2021-32648October CMS Improper AuthenticationKEVCRITICAL 9.1EPSS 90.4%26 August 2021
CVE-2021-22242Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdownMEDIUM 5.4EPSS 63.6%25 August 2021
CVE-2021-30970A malicious application may be able to bypass Privacy preferences.MEDIUM 5.5EPSS 14.7%24 August 2021
CVE-2021-30937A memory corruption vulnerability was addressed with improved locking.HIGH 7.8EPSS 17.3%24 August 2021
CVE-2021-30892A malicious application may be able to modify protected parts of the file system.MEDIUM 5.5EPSS 10.4%24 August 2021
CVE-2021-30883Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 14.7%24 August 2021
CVE-2021-30860Apple Multiple Products Integer Overflow VulnerabilityKEVHIGH 7.8EPSS 76.0%24 August 2021
CVE-2021-30858Apple iOS, iPadOS, macOS Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 13.4%24 August 2021
CVE-2021-28554Acrobat Reader DC versions versions 2021.001.20155 (and earlier), 2020.001.30025 (and earlier) and 2017.011.30196 (and earlier) are affected by an Out-of-bounds Read vulnerability.HIGH 7.8EPSS 46.0%24 August 2021
CVE-2021-3712If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit.HIGH 7.4EPSS 50.4%24 August 2021
CVE-2021-3711This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small.CRITICAL 9.8EPSS 87.8%24 August 2021
CVE-2021-38556includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.HIGH 8.8EPSS 13.0%24 August 2021
CVE-2021-37538Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive…CRITICAL 9.8EPSS 74.5%24 August 2021
CVE-2021-39608Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.HIGH 7.2EPSS 45.9%23 August 2021
CVE-2021-39152In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8.HIGH 8.5EPSS 11.4%23 August 2021
CVE-2021-39146In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.HIGH 8.5EPSS 14.3%23 August 2021
CVE-2021-39144XStream Remote Code Execution VulnerabilityKEVHIGH 8.5EPSS 98.1%23 August 2021
CVE-2021-39141In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.HIGH 8.5EPSS 16.1%23 August 2021
CVE-2021-28640Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability.HIGH 7.3EPSS 53.4%20 August 2021
CVE-2021-28639Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability.HIGH 7.8EPSS 66.1%20 August 2021
CVE-2021-28635Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a use-after-free vulnerability.HIGH 7.8EPSS 51.2%20 August 2021
CVE-2021-36748A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.HIGH 7.5EPSS 15.4%20 August 2021
CVE-2021-22238GitLab was vulnerable to a stored XSS by using the design feature in issues.MEDIUM 5.4EPSS 71.8%20 August 2021
CVE-2021-34228Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.MEDIUM 6.1EPSS 29.2%20 August 2021
CVE-2021-34730A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart…CRITICAL 9.8EPSS 18.5%18 August 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.