SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 88 of 348

CVESummaryPriorityPublished
CVE-2021-33393It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root.HIGH 8.8EPSS 58.7%9 June 2021
CVE-2021-33357A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS…CRITICAL 9.8EPSS 17.4%9 June 2021
CVE-2021-28169For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory.MEDIUM 5.3EPSS 78.5%9 June 2021
CVE-2021-33742Microsoft Windows MSHTML Platform Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 59.4%8 June 2021
CVE-2021-31956Microsoft Windows NTFS Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 22.3%8 June 2021
CVE-2021-31955Microsoft Windows Kernel Information Disclosure VulnerabilityKEVMEDIUM 5.5EPSS 81.1%8 June 2021
CVE-2021-31939Microsoft Excel Remote Code Execution VulnerabilityHIGH 7.8EPSS 13.3%8 June 2021
CVE-2021-26414Windows DCOM Server Security Feature BypassMEDIUM 4.8EPSS 49.8%8 June 2021
CVE-2021-1675Microsoft Windows Print Spooler Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 86.1%8 June 2021
CVE-2021-31807An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests.MEDIUM 6.5EPSS 16.0%8 June 2021
CVE-2021-22214When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where…HIGH 8.6EPSS 27.8%8 June 2021
CVE-2021-30357SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.MEDIUM 5.3EPSS 22.8%8 June 2021
CVE-2021-3277Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.HIGH 7.2EPSS 54.6%7 June 2021
CVE-2021-32671Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered.CRITICAL 10.0EPSS 39.7%7 June 2021
CVE-2021-30538Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.MEDIUM 4.3EPSS 15.7%7 June 2021
CVE-2021-30533Google Chromium PopupBlocker Security Bypass VulnerabilityKEVMEDIUM 6.5EPSS 16.6%7 June 2021
CVE-2021-24340The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query.HIGH 7.5EPSS 29.8%7 June 2021
CVE-2021-31252An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.MEDIUM 6.1EPSS 28.6%4 June 2021
CVE-2021-31251An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an…CRITICAL 9.8EPSS 35.7%4 June 2021
CVE-2021-31250Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi.MEDIUM 5.4EPSS 79.6%4 June 2021
CVE-2021-31249A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.MEDIUM 6.5EPSS 18.0%4 June 2021
CVE-2021-3490The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution.HIGH 7.8EPSS 27.5%4 June 2021
CVE-2020-6950Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.MEDIUM 6.5EPSS 10.1%2 June 2021
CVE-2021-22123An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.HIGH 8.8EPSS 77.3%1 June 2021
CVE-2021-32924Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.HIGH 8.8EPSS 19.9%1 June 2021
CVE-2021-31643An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.MEDIUM 5.4EPSS 88.4%1 June 2021
CVE-2021-31642A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC.MEDIUM 6.5EPSS 43.7%1 June 2021
CVE-2021-30181When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.CRITICAL 9.8EPSS 60.6%1 June 2021
CVE-2021-30180When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.CRITICAL 9.8EPSS 60.4%1 June 2021
CVE-2021-25641But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction.CRITICAL 9.8EPSS 21.2%1 June 2021
CVE-2021-24321The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them…CRITICAL 9.8EPSS 66.6%1 June 2021
CVE-2021-24320The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default,…MEDIUM 6.1EPSS 10.8%1 June 2021
CVE-2021-23017A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.HIGH 7.7EPSS 53.5%1 June 2021
CVE-2021-27828SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.CRITICAL 9.1EPSS 20.3%1 June 2021
CVE-2021-33564An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled.CRITICAL 9.8EPSS 72.1%29 May 2021
CVE-2021-30461A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.CRITICAL 9.8EPSS 36.6%29 May 2021
CVE-2021-29505A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream.HIGH 8.8EPSS 77.2%28 May 2021
CVE-2021-29492A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`.HIGH 8.3EPSS 66.2%28 May 2021
CVE-2021-33620Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response.MEDIUM 6.5EPSS 79.6%28 May 2021
CVE-2021-27852Checkbox Survey Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 31.9%27 May 2021
CVE-2021-20026A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request.HIGH 8.8EPSS 11.6%27 May 2021
CVE-2021-31806Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.MEDIUM 6.5EPSS 95.8%27 May 2021
CVE-2021-31535LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code.CRITICAL 9.8EPSS 10.6%27 May 2021
CVE-2021-28662If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service.MEDIUM 6.5EPSS 71.8%27 May 2021
CVE-2021-22911A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.CRITICAL 9.8EPSS 95.2%27 May 2021
CVE-2021-22908A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user.HIGH 8.8EPSS 69.4%27 May 2021
CVE-2021-22900Ivanti Pulse Connect Secure Unrestricted File Upload VulnerabilityKEVHIGH 7.2EPSS 14.1%27 May 2021
CVE-2021-22899Ivanti Pulse Connect Secure Command Injection VulnerabilityKEVHIGH 8.8EPSS 22.9%27 May 2021
CVE-2021-22894Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 41.3%27 May 2021
CVE-2021-33558Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js.HIGH 7.5EPSS 12.3%27 May 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.