SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 87 of 348

CVESummaryPriorityPublished
CVE-2021-30119Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request:…MEDIUM 5.4EPSS 52.7%9 July 2021
CVE-2021-30118An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to…CRITICAL 9.8EPSS 60.3%9 July 2021
CVE-2021-30117The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId.HIGH 8.8EPSS 72.1%9 July 2021
CVE-2021-30116Kaseya Virtual System/Server Administrator (VSA) Information Disclosure VulnerabilityKEVCRITICAL 9.8EPSS 85.7%9 July 2021
CVE-2021-1585A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system.HIGH 8.1EPSS 20.0%8 July 2021
CVE-2021-28809An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3.CRITICAL 9.8EPSS 15.8%8 July 2021
CVE-2021-33221An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.CRITICAL 9.8EPSS 56.1%7 July 2021
CVE-2021-33216An Undocumented Backdoor exists, allowing shell access via a developer account.CRITICAL 9.8EPSS 13.8%7 July 2021
CVE-2020-24148Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.CRITICAL 9.1EPSS 14.7%7 July 2021
CVE-2021-34621A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator.CRITICAL 9.8EPSS 68.9%7 July 2021
CVE-2021-22555Linux Kernel Heap Out-of-Bounds Write VulnerabilityKEVHIGH 7.8EPSS 78.7%7 July 2021
CVE-2021-24405The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them.MEDIUM 6.5EPSS 10.7%6 July 2021
CVE-2021-34527Microsoft Windows Print Spooler Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.8%2 July 2021
CVE-2021-30557Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 11.7%2 July 2021
CVE-2021-35042Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.CRITICAL 9.8EPSS 44.4%2 July 2021
CVE-2021-35336A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.CRITICAL 9.8EPSS 10.1%1 July 2021
CVE-2021-31813Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.MEDIUM 5.4EPSS 78.3%1 July 2021
CVE-2021-21672Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.MEDIUM 4.3EPSS 42.5%30 June 2021
CVE-2021-35941Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than…HIGH 7.5EPSS 12.7%29 June 2021
CVE-2021-34187main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.CRITICAL 9.8EPSS 16.2%28 June 2021
CVE-2021-34427In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.CRITICAL 9.8EPSS 58.0%25 June 2021
CVE-2021-28958Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.CRITICAL 9.8EPSS 73.1%25 June 2021
CVE-2021-21809A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.CRITICAL 9.1EPSS 24.2%23 June 2021
CVE-2021-31586Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.HIGH 8.8EPSS 44.1%23 June 2021
CVE-2021-21998VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass.CRITICAL 9.8EPSS 10.6%23 June 2021
CVE-2021-24370The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.CRITICAL 9.8EPSS 47.4%21 June 2021
CVE-2021-21669Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.CRITICAL 9.8EPSS 25.7%18 June 2021
CVE-2020-22208SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.CRITICAL 9.8EPSS 10.1%16 June 2021
CVE-2021-21668Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.MEDIUM 5.4EPSS 76.0%16 June 2021
CVE-2021-21667Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.MEDIUM 5.4EPSS 75.7%16 June 2021
CVE-2021-31159Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.MEDIUM 5.3EPSS 17.8%16 June 2021
CVE-2021-33813An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.HIGH 7.5EPSS 19.4%16 June 2021
CVE-2021-20093A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a.CRITICAL 9.1EPSS 33.3%16 June 2021
CVE-2021-30551Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 64.7%15 June 2021
CVE-2021-31618This led to a NULL pointer dereference on initialised memory, crashing reliably the child process.HIGH 7.5EPSS 51.5%15 June 2021
CVE-2021-32682Several vulnerabilities affect elFinder 2.1.58.CRITICAL 9.8EPSS 69.9%14 June 2021
CVE-2021-24347The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension.HIGH 8.8EPSS 54.1%14 June 2021
CVE-2021-23394The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file.CRITICAL 9.8EPSS 18.9%13 June 2021
CVE-2021-22901curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection.HIGH 8.1EPSS 60.1%11 June 2021
CVE-2021-22175GitLab Server-Side Request Forgery (SSRF) VulnerabilityKEVCRITICAL 9.8EPSS 53.4%11 June 2021
CVE-2021-26829OpenPLC ScadaBR Cross-site Scripting VulnerabilityKEVMEDIUM 5.4EPSS 48.0%11 June 2021
CVE-2021-26828OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type VulnerabilityKEVHIGH 8.8EPSS 39.4%11 June 2021
CVE-2021-20081Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.HIGH 7.2EPSS 52.4%10 June 2021
CVE-2021-30641Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'MEDIUM 5.3EPSS 52.6%10 June 2021
CVE-2021-26691In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflowCRITICAL 9.8EPSS 68.3%10 June 2021
CVE-2021-26690Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of ServiceHIGH 7.5EPSS 65.3%10 June 2021
CVE-2020-35452Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest.HIGH 7.3EPSS 53.5%10 June 2021
CVE-2020-13950Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of ServiceHIGH 7.5EPSS 49.4%10 June 2021
CVE-2020-13938Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on WindowsMEDIUM 5.5EPSS 11.9%10 June 2021
CVE-2019-17567Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass…MEDIUM 5.3EPSS 60.3%10 June 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.