Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,951 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 86 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-32610 | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193. | HIGH 7.1EPSS 73.4% | 30 July 2021 |
| CVE-2021-28966 | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. | HIGH 7.5EPSS 57.1% | 30 July 2021 |
| CVE-2020-36239 | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before… | CRITICAL 9.8EPSS 49.8% | 29 July 2021 |
| CVE-2021-32789 | An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. | HIGH 7.5EPSS 17.2% | 26 July 2021 |
| CVE-2020-7388 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. | CRITICAL 9.8EPSS 69.4% | 22 July 2021 |
| CVE-2020-7387 | Sage X3 Installation Pathname Disclosure. | MEDIUM 5.3EPSS 36.4% | 22 July 2021 |
| CVE-2021-36222 | ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. | HIGH 7.5EPSS 10.3% | 22 July 2021 |
| CVE-2021-35464 | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 22 July 2021 |
| CVE-2021-33032 | A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system… | CRITICAL 10.0EPSS 52.2% | 22 July 2021 |
| CVE-2015-2099 | Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the… | HIGH 8.8EPSS 14.1% | 22 July 2021 |
| CVE-2015-2098 | Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4)… | HIGH 8.8EPSS 14.0% | 22 July 2021 |
| CVE-2021-36934 | Microsoft Windows SAM Local Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 67.3% | 22 July 2021 |
| CVE-2021-32761 | A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. | HIGH 7.5EPSS 37.6% | 21 July 2021 |
| CVE-2021-2429 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). | MEDIUM 5.9EPSS 41.5% | 21 July 2021 |
| CVE-2021-2401 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). | MEDIUM 5.3EPSS 84.8% | 21 July 2021 |
| CVE-2021-2400 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). | HIGH 7.5EPSS 83.3% | 21 July 2021 |
| CVE-2021-2396 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). | HIGH 8.8EPSS 35.7% | 21 July 2021 |
| CVE-2021-2394 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.8EPSS 76.6% | 21 July 2021 |
| CVE-2021-2391 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). | HIGH 8.8EPSS 34.7% | 21 July 2021 |
| CVE-2021-22784 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system. | MEDIUM 5.7EPSS 12.1% | 21 July 2021 |
| CVE-2021-22707 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions… | CRITICAL 9.8EPSS 64.6% | 21 July 2021 |
| CVE-2021-22146 | While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster. | HIGH 7.5EPSS 35.8% | 21 July 2021 |
| CVE-2021-22145 | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. | MEDIUM 6.5EPSS 76.2% | 21 July 2021 |
| CVE-2021-2456 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). | CRITICAL 9.8EPSS 81.4% | 21 July 2021 |
| CVE-2021-34481 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. | HIGH 8.8EPSS 47.7% | 16 July 2021 |
| CVE-2021-34448 | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | KEVMEDIUM 6.8EPSS 40.1% | 16 July 2021 |
| CVE-2021-28114 | Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing. | MEDIUM 5.4EPSS 52.0% | 16 July 2021 |
| CVE-2021-21816 | An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. | MEDIUM 4.3EPSS 32.4% | 16 July 2021 |
| CVE-2021-21801 | This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. | MEDIUM 6.1EPSS 63.4% | 16 July 2021 |
| CVE-2021-21800 | Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). | MEDIUM 6.1EPSS 14.1% | 16 July 2021 |
| CVE-2021-21799 | Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). | MEDIUM 6.1EPSS 12.3% | 16 July 2021 |
| CVE-2021-34429 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. | MEDIUM 5.3EPSS 99.3% | 15 July 2021 |
| CVE-2021-35211 | SolarWinds Serv-U Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 91.2% | 14 July 2021 |
| CVE-2021-34523 | Microsoft Exchange Server Privilege Escalation Vulnerability | KEVCRITICAL 9.0EPSS 100.0% | 14 July 2021 |
| CVE-2021-34501 | Microsoft Excel Remote Code Execution Vulnerability | HIGH 7.8EPSS 51.4% | 14 July 2021 |
| CVE-2021-34473 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 14 July 2021 |
| CVE-2021-33771 | Microsoft Windows Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 10.2% | 14 July 2021 |
| CVE-2021-33766 | Microsoft Exchange Server Information Disclosure | KEVHIGH 7.3EPSS 98.1% | 14 July 2021 |
| CVE-2021-31206 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 7.6EPSS 13.0% | 14 July 2021 |
| CVE-2021-31196 | Microsoft Exchange Server Information Disclosure Vulnerability | KEVHIGH 7.2EPSS 54.1% | 14 July 2021 |
| CVE-2021-36090 | This could be used to mount a denial of service attack against services that use Compress' zip package. | HIGH 7.5EPSS 12.9% | 13 July 2021 |
| CVE-2021-35517 | This could be used to mount a denial of service attack against services that use Compress' tar package. | HIGH 7.5EPSS 10.6% | 13 July 2021 |
| CVE-2021-35516 | This could be used to mount a denial of service attack against services that use Compress' sevenz package. | HIGH 7.5EPSS 12.4% | 13 July 2021 |
| CVE-2021-35515 | This could be used to mount a denial of service attack against services that use Compress' sevenz package. | HIGH 7.5EPSS 11.6% | 13 July 2021 |
| CVE-2021-24442 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to… | CRITICAL 9.8EPSS 46.0% | 12 July 2021 |
| CVE-2021-33807 | Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData. | HIGH 7.5EPSS 16.1% | 12 July 2021 |
| CVE-2021-33037 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. | MEDIUM 5.3EPSS 75.4% | 12 July 2021 |
| CVE-2021-35064 | KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. | CRITICAL 9.8EPSS 70.8% | 12 July 2021 |
| CVE-2021-22918 | Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. | MEDIUM 5.3EPSS 23.1% | 12 July 2021 |
| CVE-2021-30201 | When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. | HIGH 7.5EPSS 25.4% | 9 July 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.