Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,951 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 85 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-22940 | Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior. | HIGH 7.5EPSS 13.9% | 16 August 2021 |
| CVE-2021-22939 | If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. | MEDIUM 5.3EPSS 14.7% | 16 August 2021 |
| CVE-2021-22931 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames… | CRITICAL 9.8EPSS 22.0% | 16 August 2021 |
| CVE-2021-35395 | Realtek AP-Router SDK Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 16 August 2021 |
| CVE-2021-35394 | Realtek Jungle SDK Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 16 August 2021 |
| CVE-2021-35393 | The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. | CRITICAL 9.8EPSS 70.3% | 16 August 2021 |
| CVE-2021-35392 | The server is vulnerable to a heap buffer overflow that is present due to unsafe crafting of SSDP NOTIFY messages from received M-SEARCH messages ST header. | HIGH 7.5EPSS 83.2% | 16 August 2021 |
| CVE-2021-33193 | A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. | HIGH 7.5EPSS 46.2% | 16 August 2021 |
| CVE-2021-3708 | D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. | HIGH 7.8EPSS 24.6% | 16 August 2021 |
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | KEVMEDIUM 5.3EPSS 100.0% | 16 August 2021 |
| CVE-2021-36380 | Sunhillo SureLine OS Command Injection Vulnerablity | KEVCRITICAL 9.8EPSS 97.6% | 13 August 2021 |
| CVE-2021-37350 | Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation. | CRITICAL 9.8EPSS 79.3% | 13 August 2021 |
| CVE-2021-37346 | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection). | CRITICAL 9.8EPSS 73.6% | 13 August 2021 |
| CVE-2021-37344 | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection). | CRITICAL 9.8EPSS 96.8% | 13 August 2021 |
| CVE-2021-37343 | A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios. | HIGH 8.8EPSS 23.8% | 13 August 2021 |
| CVE-2021-36958 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. | HIGH 7.8EPSS 30.6% | 12 August 2021 |
| CVE-2021-36948 | Microsoft Windows Update Medic Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 23.3% | 12 August 2021 |
| CVE-2021-36942 | Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability | KEVHIGH 7.5EPSS 66.0% | 12 August 2021 |
| CVE-2021-34535 | Remote Desktop Client Remote Code Execution Vulnerability | HIGH 8.8EPSS 21.7% | 12 August 2021 |
| CVE-2021-34484 | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 21.8% | 12 August 2021 |
| CVE-2021-34480 | Scripting Engine Memory Corruption Vulnerability | MEDIUM 6.8EPSS 33.9% | 12 August 2021 |
| CVE-2021-34478 | Microsoft Office Remote Code Execution Vulnerability | HIGH 7.8EPSS 51.2% | 12 August 2021 |
| CVE-2021-26432 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 11.3% | 12 August 2021 |
| CVE-2021-26424 | Windows TCP/IP Remote Code Execution Vulnerability | CRITICAL 9.9EPSS 61.1% | 12 August 2021 |
| CVE-2021-37425 | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key. | CRITICAL 9.1EPSS 66.3% | 10 August 2021 |
| CVE-2021-37152 | Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. | MEDIUM 5.4EPSS 24.4% | 10 August 2021 |
| CVE-2021-33256 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. | HIGH 8.8EPSS 79.0% | 9 August 2021 |
| CVE-2021-24507 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated… | CRITICAL 9.8EPSS 11.0% | 9 August 2021 |
| CVE-2021-24499 | The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. | CRITICAL 9.8EPSS 60.1% | 9 August 2021 |
| CVE-2021-35325 | A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS). | HIGH 7.5EPSS 13.3% | 5 August 2021 |
| CVE-2021-35324 | A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication. | CRITICAL 9.8EPSS 10.4% | 5 August 2021 |
| CVE-2021-21805 | An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). | CRITICAL 9.8EPSS 69.8% | 5 August 2021 |
| CVE-2021-34371 | Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. | CRITICAL 9.8EPSS 13.4% | 5 August 2021 |
| CVE-2021-20028 | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 30.1% | 4 August 2021 |
| CVE-2021-32706 | Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. | HIGH 8.8EPSS 60.2% | 4 August 2021 |
| CVE-2021-34850 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. | HIGH 7.8EPSS 38.3% | 4 August 2021 |
| CVE-2021-34847 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. | HIGH 7.8EPSS 61.6% | 4 August 2021 |
| CVE-2021-34842 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. | HIGH 7.8EPSS 13.3% | 4 August 2021 |
| CVE-2021-34833 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. | HIGH 7.8EPSS 95.7% | 4 August 2021 |
| CVE-2021-32804 | The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by… | HIGH 8.1EPSS 15.1% | 3 August 2021 |
| CVE-2021-30560 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 21.6% | 3 August 2021 |
| CVE-2021-37557 | A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the… | HIGH 8.8EPSS 27.4% | 3 August 2021 |
| CVE-2021-37556 | A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the… | HIGH 8.8EPSS 27.4% | 3 August 2021 |
| CVE-2021-31630 | Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application. | HIGH 8.8EPSS 27.1% | 3 August 2021 |
| CVE-2021-26085 | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | KEVMEDIUM 5.3EPSS 99.9% | 3 August 2021 |
| CVE-2021-24488 | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues | MEDIUM 6.1EPSS 11.2% | 2 August 2021 |
| CVE-2021-24472 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content… | CRITICAL 9.8EPSS 56.6% | 2 August 2021 |
| CVE-2021-36754 | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception. | HIGH 7.5EPSS 64.9% | 30 July 2021 |
| CVE-2021-35479 | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. | MEDIUM 5.4EPSS 13.2% | 30 July 2021 |
| CVE-2021-35478 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. | MEDIUM 5.4EPSS 76.6% | 30 July 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.