Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 88 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-33393 | It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. | HIGH 8.8EPSS 58.7% | 9 June 2021 |
| CVE-2021-33357 | A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS… | CRITICAL 9.8EPSS 17.4% | 9 June 2021 |
| CVE-2021-28169 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. | MEDIUM 5.3EPSS 78.5% | 9 June 2021 |
| CVE-2021-33742 | Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 59.4% | 8 June 2021 |
| CVE-2021-31956 | Microsoft Windows NTFS Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 22.3% | 8 June 2021 |
| CVE-2021-31955 | Microsoft Windows Kernel Information Disclosure Vulnerability | KEVMEDIUM 5.5EPSS 81.1% | 8 June 2021 |
| CVE-2021-31939 | Microsoft Excel Remote Code Execution Vulnerability | HIGH 7.8EPSS 13.3% | 8 June 2021 |
| CVE-2021-26414 | Windows DCOM Server Security Feature Bypass | MEDIUM 4.8EPSS 49.8% | 8 June 2021 |
| CVE-2021-1675 | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 86.1% | 8 June 2021 |
| CVE-2021-31807 | An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. | MEDIUM 6.5EPSS 16.0% | 8 June 2021 |
| CVE-2021-22214 | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where… | HIGH 8.6EPSS 27.8% | 8 June 2021 |
| CVE-2021-30357 | SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access. | MEDIUM 5.3EPSS 22.8% | 8 June 2021 |
| CVE-2021-3277 | Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files. | HIGH 7.2EPSS 54.6% | 7 June 2021 |
| CVE-2021-32671 | Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. | CRITICAL 10.0EPSS 39.7% | 7 June 2021 |
| CVE-2021-30538 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. | MEDIUM 4.3EPSS 15.7% | 7 June 2021 |
| CVE-2021-30533 | Google Chromium PopupBlocker Security Bypass Vulnerability | KEVMEDIUM 6.5EPSS 16.6% | 7 June 2021 |
| CVE-2021-24340 | The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. | HIGH 7.5EPSS 29.8% | 7 June 2021 |
| CVE-2021-31252 | An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it. | MEDIUM 6.1EPSS 28.6% | 4 June 2021 |
| CVE-2021-31251 | An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an… | CRITICAL 9.8EPSS 35.7% | 4 June 2021 |
| CVE-2021-31250 | Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi. | MEDIUM 5.4EPSS 79.6% | 4 June 2021 |
| CVE-2021-31249 | A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components. | MEDIUM 6.5EPSS 18.0% | 4 June 2021 |
| CVE-2021-3490 | The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. | HIGH 7.8EPSS 27.5% | 4 June 2021 |
| CVE-2020-6950 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. | MEDIUM 6.5EPSS 10.1% | 2 June 2021 |
| CVE-2021-22123 | An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page. | HIGH 8.8EPSS 77.3% | 1 June 2021 |
| CVE-2021-32924 | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method. | HIGH 8.8EPSS 19.9% | 1 June 2021 |
| CVE-2021-31643 | An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter. | MEDIUM 5.4EPSS 88.4% | 1 June 2021 |
| CVE-2021-31642 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. | MEDIUM 6.5EPSS 43.7% | 1 June 2021 |
| CVE-2021-30181 | When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code. | CRITICAL 9.8EPSS 60.6% | 1 June 2021 |
| CVE-2021-30180 | When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors. | CRITICAL 9.8EPSS 60.4% | 1 June 2021 |
| CVE-2021-25641 | But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction. | CRITICAL 9.8EPSS 21.2% | 1 June 2021 |
| CVE-2021-24321 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them… | CRITICAL 9.8EPSS 66.6% | 1 June 2021 |
| CVE-2021-24320 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default,… | MEDIUM 6.1EPSS 10.8% | 1 June 2021 |
| CVE-2021-23017 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | HIGH 7.7EPSS 53.5% | 1 June 2021 |
| CVE-2021-27828 | SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries. | CRITICAL 9.1EPSS 20.3% | 1 June 2021 |
| CVE-2021-33564 | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. | CRITICAL 9.8EPSS 72.1% | 29 May 2021 |
| CVE-2021-30461 | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. | CRITICAL 9.8EPSS 36.6% | 29 May 2021 |
| CVE-2021-29505 | A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. | HIGH 8.8EPSS 77.2% | 28 May 2021 |
| CVE-2021-29492 | A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. | HIGH 8.3EPSS 66.2% | 28 May 2021 |
| CVE-2021-33620 | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. | MEDIUM 6.5EPSS 79.6% | 28 May 2021 |
| CVE-2021-27852 | Checkbox Survey Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 31.9% | 27 May 2021 |
| CVE-2021-20026 | A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. | HIGH 8.8EPSS 11.6% | 27 May 2021 |
| CVE-2021-31806 | Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing. | MEDIUM 6.5EPSS 95.8% | 27 May 2021 |
| CVE-2021-31535 | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. | CRITICAL 9.8EPSS 10.6% | 27 May 2021 |
| CVE-2021-28662 | If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. | MEDIUM 6.5EPSS 71.8% | 27 May 2021 |
| CVE-2021-22911 | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | CRITICAL 9.8EPSS 95.2% | 27 May 2021 |
| CVE-2021-22908 | A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. | HIGH 8.8EPSS 69.4% | 27 May 2021 |
| CVE-2021-22900 | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | KEVHIGH 7.2EPSS 14.1% | 27 May 2021 |
| CVE-2021-22899 | Ivanti Pulse Connect Secure Command Injection Vulnerability | KEVHIGH 8.8EPSS 22.9% | 27 May 2021 |
| CVE-2021-22894 | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 41.3% | 27 May 2021 |
| CVE-2021-33558 | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. | HIGH 7.5EPSS 12.3% | 27 May 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.