Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 87 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-30119 | Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request:… | MEDIUM 5.4EPSS 52.7% | 9 July 2021 |
| CVE-2021-30118 | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to… | CRITICAL 9.8EPSS 60.3% | 9 July 2021 |
| CVE-2021-30117 | The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. | HIGH 8.8EPSS 72.1% | 9 July 2021 |
| CVE-2021-30116 | Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability | KEVCRITICAL 9.8EPSS 85.7% | 9 July 2021 |
| CVE-2021-1585 | A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. | HIGH 8.1EPSS 20.0% | 8 July 2021 |
| CVE-2021-28809 | An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. | CRITICAL 9.8EPSS 15.8% | 8 July 2021 |
| CVE-2021-33221 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. | CRITICAL 9.8EPSS 56.1% | 7 July 2021 |
| CVE-2021-33216 | An Undocumented Backdoor exists, allowing shell access via a developer account. | CRITICAL 9.8EPSS 13.8% | 7 July 2021 |
| CVE-2020-24148 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action. | CRITICAL 9.1EPSS 14.7% | 7 July 2021 |
| CVE-2021-34621 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. | CRITICAL 9.8EPSS 68.9% | 7 July 2021 |
| CVE-2021-22555 | Linux Kernel Heap Out-of-Bounds Write Vulnerability | KEVHIGH 7.8EPSS 78.7% | 7 July 2021 |
| CVE-2021-24405 | The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. | MEDIUM 6.5EPSS 10.7% | 6 July 2021 |
| CVE-2021-34527 | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.8% | 2 July 2021 |
| CVE-2021-30557 | Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 11.7% | 2 July 2021 |
| CVE-2021-35042 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | CRITICAL 9.8EPSS 44.4% | 2 July 2021 |
| CVE-2021-35336 | A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account. | CRITICAL 9.8EPSS 10.1% | 1 July 2021 |
| CVE-2021-31813 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | MEDIUM 5.4EPSS 78.3% | 1 July 2021 |
| CVE-2021-21672 | Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | MEDIUM 4.3EPSS 42.5% | 30 June 2021 |
| CVE-2021-35941 | Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than… | HIGH 7.5EPSS 12.7% | 29 June 2021 |
| CVE-2021-34187 | main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | CRITICAL 9.8EPSS 16.2% | 28 June 2021 |
| CVE-2021-34427 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. | CRITICAL 9.8EPSS 58.0% | 25 June 2021 |
| CVE-2021-28958 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | CRITICAL 9.8EPSS 73.1% | 25 June 2021 |
| CVE-2021-21809 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. | CRITICAL 9.1EPSS 24.2% | 23 June 2021 |
| CVE-2021-31586 | Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. | HIGH 8.8EPSS 44.1% | 23 June 2021 |
| CVE-2021-21998 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. | CRITICAL 9.8EPSS 10.6% | 23 June 2021 |
| CVE-2021-24370 | The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution. | CRITICAL 9.8EPSS 47.4% | 21 June 2021 |
| CVE-2021-21669 | Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | CRITICAL 9.8EPSS 25.7% | 18 June 2021 |
| CVE-2020-22208 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. | CRITICAL 9.8EPSS 10.1% | 16 June 2021 |
| CVE-2021-21668 | Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission. | MEDIUM 5.4EPSS 76.0% | 16 June 2021 |
| CVE-2021-21667 | Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission. | MEDIUM 5.4EPSS 75.7% | 16 June 2021 |
| CVE-2021-31159 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. | MEDIUM 5.3EPSS 17.8% | 16 June 2021 |
| CVE-2021-33813 | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | HIGH 7.5EPSS 19.4% | 16 June 2021 |
| CVE-2021-20093 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. | CRITICAL 9.1EPSS 33.3% | 16 June 2021 |
| CVE-2021-30551 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 64.7% | 15 June 2021 |
| CVE-2021-31618 | This led to a NULL pointer dereference on initialised memory, crashing reliably the child process. | HIGH 7.5EPSS 51.5% | 15 June 2021 |
| CVE-2021-32682 | Several vulnerabilities affect elFinder 2.1.58. | CRITICAL 9.8EPSS 69.9% | 14 June 2021 |
| CVE-2021-24347 | The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. | HIGH 8.8EPSS 54.1% | 14 June 2021 |
| CVE-2021-23394 | The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. | CRITICAL 9.8EPSS 18.9% | 13 June 2021 |
| CVE-2021-22901 | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. | HIGH 8.1EPSS 60.1% | 11 June 2021 |
| CVE-2021-22175 | GitLab Server-Side Request Forgery (SSRF) Vulnerability | KEVCRITICAL 9.8EPSS 53.4% | 11 June 2021 |
| CVE-2021-26829 | OpenPLC ScadaBR Cross-site Scripting Vulnerability | KEVMEDIUM 5.4EPSS 48.0% | 11 June 2021 |
| CVE-2021-26828 | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | KEVHIGH 8.8EPSS 39.4% | 11 June 2021 |
| CVE-2021-20081 | Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. | HIGH 7.2EPSS 52.4% | 10 June 2021 |
| CVE-2021-30641 | Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' | MEDIUM 5.3EPSS 52.6% | 10 June 2021 |
| CVE-2021-26691 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | CRITICAL 9.8EPSS 68.3% | 10 June 2021 |
| CVE-2021-26690 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | HIGH 7.5EPSS 65.3% | 10 June 2021 |
| CVE-2020-35452 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. | HIGH 7.3EPSS 53.5% | 10 June 2021 |
| CVE-2020-13950 | Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service | HIGH 7.5EPSS 49.4% | 10 June 2021 |
| CVE-2020-13938 | Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows | MEDIUM 5.5EPSS 11.9% | 10 June 2021 |
| CVE-2019-17567 | Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass… | MEDIUM 5.3EPSS 60.3% | 10 June 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.