SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,951 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 86 of 348

CVESummaryPriorityPublished
CVE-2021-32610In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.HIGH 7.1EPSS 73.4%30 July 2021
CVE-2021-28966In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.HIGH 7.5EPSS 57.1%30 July 2021
CVE-2020-36239Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before…CRITICAL 9.8EPSS 49.8%29 July 2021
CVE-2021-32789An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16.HIGH 7.5EPSS 17.2%26 July 2021
CVE-2020-7388Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component.CRITICAL 9.8EPSS 69.4%22 July 2021
CVE-2020-7387Sage X3 Installation Pathname Disclosure.MEDIUM 5.3EPSS 36.4%22 July 2021
CVE-2021-36222ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash.HIGH 7.5EPSS 10.3%22 July 2021
CVE-2021-35464ForgeRock Access Management (AM) Core Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%22 July 2021
CVE-2021-33032A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system…CRITICAL 10.0EPSS 52.2%22 July 2021
CVE-2015-2099Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the…HIGH 8.8EPSS 14.1%22 July 2021
CVE-2015-2098Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4)…HIGH 8.8EPSS 14.0%22 July 2021
CVE-2021-36934Microsoft Windows SAM Local Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 67.3%22 July 2021
CVE-2021-32761A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5.HIGH 7.5EPSS 37.6%21 July 2021
CVE-2021-2429Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).MEDIUM 5.9EPSS 41.5%21 July 2021
CVE-2021-2401Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).MEDIUM 5.3EPSS 84.8%21 July 2021
CVE-2021-2400Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).HIGH 7.5EPSS 83.3%21 July 2021
CVE-2021-2396Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).HIGH 8.8EPSS 35.7%21 July 2021
CVE-2021-2394Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 76.6%21 July 2021
CVE-2021-2391Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler).HIGH 8.8EPSS 34.7%21 July 2021
CVE-2021-22784A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.MEDIUM 5.7EPSS 12.1%21 July 2021
CVE-2021-22707A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions…CRITICAL 9.8EPSS 64.6%21 July 2021
CVE-2021-22146While in the default setting the anonymous user has no permissions and is unable to successfully query any Elasticsearch APIs, an attacker could leverage the anonymous user to gain insight into certain details of a deployed cluster.HIGH 7.5EPSS 35.8%21 July 2021
CVE-2021-22145A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.MEDIUM 6.5EPSS 76.2%21 July 2021
CVE-2021-2456Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General).CRITICAL 9.8EPSS 81.4%21 July 2021
CVE-2021-34481A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.HIGH 8.8EPSS 47.7%16 July 2021
CVE-2021-34448Microsoft Windows Scripting Engine Memory Corruption VulnerabilityKEVMEDIUM 6.8EPSS 40.1%16 July 2021
CVE-2021-28114Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.MEDIUM 5.4EPSS 52.0%16 July 2021
CVE-2021-21816An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03.MEDIUM 4.3EPSS 32.4%16 July 2021
CVE-2021-21801This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications.MEDIUM 6.1EPSS 63.4%16 July 2021
CVE-2021-21800Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).MEDIUM 6.1EPSS 14.1%16 July 2021
CVE-2021-21799Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).MEDIUM 6.1EPSS 12.3%16 July 2021
CVE-2021-34429For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints.MEDIUM 5.3EPSS 99.3%15 July 2021
CVE-2021-35211SolarWinds Serv-U Remote Code Execution VulnerabilityKEVCRITICAL 10.0EPSS 91.2%14 July 2021
CVE-2021-34523Microsoft Exchange Server Privilege Escalation VulnerabilityKEVCRITICAL 9.0EPSS 100.0%14 July 2021
CVE-2021-34501Microsoft Excel Remote Code Execution VulnerabilityHIGH 7.8EPSS 51.4%14 July 2021
CVE-2021-34473Microsoft Exchange Server Remote Code Execution VulnerabilityKEVCRITICAL 9.1EPSS 100.0%14 July 2021
CVE-2021-33771Microsoft Windows Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 10.2%14 July 2021
CVE-2021-33766Microsoft Exchange Server Information DisclosureKEVHIGH 7.3EPSS 98.1%14 July 2021
CVE-2021-31206Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 7.6EPSS 13.0%14 July 2021
CVE-2021-31196Microsoft Exchange Server Information Disclosure VulnerabilityKEVHIGH 7.2EPSS 54.1%14 July 2021
CVE-2021-36090This could be used to mount a denial of service attack against services that use Compress' zip package.HIGH 7.5EPSS 12.9%13 July 2021
CVE-2021-35517This could be used to mount a denial of service attack against services that use Compress' tar package.HIGH 7.5EPSS 10.6%13 July 2021
CVE-2021-35516This could be used to mount a denial of service attack against services that use Compress' sevenz package.HIGH 7.5EPSS 12.4%13 July 2021
CVE-2021-35515This could be used to mount a denial of service attack against services that use Compress' sevenz package.HIGH 7.5EPSS 11.6%13 July 2021
CVE-2021-24442The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to…CRITICAL 9.8EPSS 46.0%12 July 2021
CVE-2021-33807Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.HIGH 7.5EPSS 16.1%12 July 2021
CVE-2021-33037Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy.MEDIUM 5.3EPSS 75.4%12 July 2021
CVE-2021-35064KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo.CRITICAL 9.8EPSS 70.8%12 July 2021
CVE-2021-22918Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII.MEDIUM 5.3EPSS 23.1%12 July 2021
CVE-2021-30201When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker.HIGH 7.5EPSS 25.4%9 July 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.