Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 89 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-21986 | The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. | CRITICAL 9.8EPSS 12.9% | 26 May 2021 |
| CVE-2021-21985 | VMware vCenter Server Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 26 May 2021 |
| CVE-2021-22160 | This allows an attacker to connect to Pulsar instances as any user (incl. admins). | CRITICAL 9.8EPSS 52.9% | 26 May 2021 |
| CVE-2021-21659 | Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | HIGH 8.1EPSS 66.8% | 25 May 2021 |
| CVE-2020-28905 | Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination. | HIGH 8.8EPSS 26.2% | 24 May 2021 |
| CVE-2020-28903 | Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS. | MEDIUM 6.1EPSS 10.1% | 24 May 2021 |
| CVE-2021-24307 | The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. | HIGH 8.8EPSS 53.3% | 24 May 2021 |
| CVE-2021-24300 | The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 10.6% | 24 May 2021 |
| CVE-2021-1531 | A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling Labs server. | HIGH 8.8EPSS 30.5% | 22 May 2021 |
| CVE-2021-31474 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. | CRITICAL 9.8EPSS 94.4% | 21 May 2021 |
| CVE-2020-35580 | A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. | HIGH 7.5EPSS 14.0% | 20 May 2021 |
| CVE-2021-29622 | Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. | MEDIUM 6.1EPSS 19.6% | 19 May 2021 |
| CVE-2021-31324 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | CRITICAL 9.8EPSS 34.9% | 18 May 2021 |
| CVE-2021-31316 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | CRITICAL 9.8EPSS 13.4% | 18 May 2021 |
| CVE-2021-32305 | WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. | CRITICAL 9.8EPSS 87.3% | 18 May 2021 |
| CVE-2021-32820 | More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. | HIGH 8.6EPSS 15.7% | 14 May 2021 |
| CVE-2021-32819 | By overwriting internal configuration options remote code execution may be triggered in downstream applications. | HIGH 8.8EPSS 58.3% | 14 May 2021 |
| CVE-2021-24291 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action… | MEDIUM 6.1EPSS 14.4% | 14 May 2021 |
| CVE-2021-24287 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 10.4% | 14 May 2021 |
| CVE-2021-24286 | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 13.9% | 14 May 2021 |
| CVE-2021-24285 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it… | CRITICAL 9.8EPSS 14.7% | 14 May 2021 |
| CVE-2021-24284 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. | CRITICAL 9.8EPSS 42.1% | 14 May 2021 |
| CVE-2021-28799 | QNAP NAS Improper Authorization Vulnerability | KEVCRITICAL 9.8EPSS 78.3% | 13 May 2021 |
| CVE-2020-36197 | An improper access control vulnerability has been reported to affect earlier versions of Music Station. | HIGH 8.8EPSS 18.5% | 13 May 2021 |
| CVE-2021-30214 | Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. | MEDIUM 5.4EPSS 23.8% | 12 May 2021 |
| CVE-2021-32608 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. | CRITICAL 9.8EPSS 33.4% | 12 May 2021 |
| CVE-2021-32607 | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. | CRITICAL 9.8EPSS 33.4% | 12 May 2021 |
| CVE-2020-36289 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. | MEDIUM 5.3EPSS 99.2% | 12 May 2021 |
| CVE-2021-31213 | Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability | HIGH 7.8EPSS 52.8% | 11 May 2021 |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | KEVMEDIUM 6.6EPSS 99.8% | 11 May 2021 |
| CVE-2021-31195 | Microsoft Exchange Server Remote Code Execution Vulnerability | MEDIUM 6.5EPSS 73.7% | 11 May 2021 |
| CVE-2021-31181 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH 8.8EPSS 30.0% | 11 May 2021 |
| CVE-2021-31179 | Microsoft Office Remote Code Execution Vulnerability | HIGH 7.8EPSS 13.5% | 11 May 2021 |
| CVE-2021-31178 | Microsoft Office Information Disclosure Vulnerability | MEDIUM 5.5EPSS 16.0% | 11 May 2021 |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 11 May 2021 |
| CVE-2021-28476 | Windows Hyper-V Remote Code Execution Vulnerability | CRITICAL 9.9EPSS 38.6% | 11 May 2021 |
| CVE-2021-28474 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 50.8% | 11 May 2021 |
| CVE-2021-27068 | Visual Studio Remote Code Execution Vulnerability | HIGH 8.8EPSS 53.6% | 11 May 2021 |
| CVE-2021-26419 | Scripting Engine Memory Corruption Vulnerability | HIGH 7.5EPSS 22.8% | 11 May 2021 |
| CVE-2021-21649 | Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | MEDIUM 5.4EPSS 72.7% | 11 May 2021 |
| CVE-2021-21648 | Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability. | MEDIUM 6.1EPSS 11.3% | 11 May 2021 |
| CVE-2020-23575 | A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. | HIGH 7.5EPSS 36.8% | 10 May 2021 |
| CVE-2021-28663 | Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 12.1% | 10 May 2021 |
| CVE-2021-31755 | Tenda AC11 Router Stack Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 86.9% | 7 May 2021 |
| CVE-2021-32099 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass. | CRITICAL 9.8EPSS 12.7% | 7 May 2021 |
| CVE-2021-29203 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. | CRITICAL 9.8EPSS 68.3% | 6 May 2021 |
| CVE-2021-28151 | Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest. | HIGH 8.8EPSS 27.9% | 6 May 2021 |
| CVE-2021-28149 | Hongdian H8922 3.0.5 devices allow Directory Traversal. | MEDIUM 6.5EPSS 15.9% | 6 May 2021 |
| CVE-2021-32030 | ASUS Routers Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 99.4% | 6 May 2021 |
| CVE-2021-29490 | Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. | MEDIUM 5.8EPSS 69.9% | 6 May 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.