SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 89 of 348

CVESummaryPriorityPublished
CVE-2021-21986The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins.CRITICAL 9.8EPSS 12.9%26 May 2021
CVE-2021-21985VMware vCenter Server Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 100.0%26 May 2021
CVE-2021-22160This allows an attacker to connect to Pulsar instances as any user (incl. admins).CRITICAL 9.8EPSS 52.9%26 May 2021
CVE-2021-21659Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.HIGH 8.1EPSS 66.8%25 May 2021
CVE-2020-28905Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.HIGH 8.8EPSS 26.2%24 May 2021
CVE-2020-28903Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.MEDIUM 6.1EPSS 10.1%24 May 2021
CVE-2021-24307The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host.HIGH 8.8EPSS 53.3%24 May 2021
CVE-2021-24300The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 10.6%24 May 2021
CVE-2021-1531A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling Labs server.HIGH 8.8EPSS 30.5%22 May 2021
CVE-2021-31474This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1.CRITICAL 9.8EPSS 94.4%21 May 2021
CVE-2020-35580A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request.HIGH 7.5EPSS 14.0%20 May 2021
CVE-2021-29622Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint.MEDIUM 6.1EPSS 19.6%19 May 2021
CVE-2021-31324The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.CRITICAL 9.8EPSS 34.9%18 May 2021
CVE-2021-31316The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.CRITICAL 9.8EPSS 13.4%18 May 2021
CVE-2021-32305WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.CRITICAL 9.8EPSS 87.3%18 May 2021
CVE-2021-32820More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications.HIGH 8.6EPSS 15.7%14 May 2021
CVE-2021-32819By overwriting internal configuration options remote code execution may be triggered in downstream applications.HIGH 8.8EPSS 58.3%14 May 2021
CVE-2021-24291The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action…MEDIUM 6.1EPSS 14.4%14 May 2021
CVE-2021-24287The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 10.4%14 May 2021
CVE-2021-24286The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 13.9%14 May 2021
CVE-2021-24285The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it…CRITICAL 9.8EPSS 14.7%14 May 2021
CVE-2021-24284The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action.CRITICAL 9.8EPSS 42.1%14 May 2021
CVE-2021-28799QNAP NAS Improper Authorization VulnerabilityKEVCRITICAL 9.8EPSS 78.3%13 May 2021
CVE-2020-36197An improper access control vulnerability has been reported to affect earlier versions of Music Station.HIGH 8.8EPSS 18.5%13 May 2021
CVE-2021-30214Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.MEDIUM 5.4EPSS 23.8%12 May 2021
CVE-2021-32608An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.CRITICAL 9.8EPSS 33.4%12 May 2021
CVE-2021-32607An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.CRITICAL 9.8EPSS 33.4%12 May 2021
CVE-2020-36289Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint.MEDIUM 5.3EPSS 99.2%12 May 2021
CVE-2021-31213Visual Studio Code Remote Containers Extension Remote Code Execution VulnerabilityHIGH 7.8EPSS 52.8%11 May 2021
CVE-2021-31207Microsoft Exchange Server Security Feature Bypass VulnerabilityKEVMEDIUM 6.6EPSS 99.8%11 May 2021
CVE-2021-31195Microsoft Exchange Server Remote Code Execution VulnerabilityMEDIUM 6.5EPSS 73.7%11 May 2021
CVE-2021-31181Microsoft SharePoint Remote Code Execution VulnerabilityHIGH 8.8EPSS 30.0%11 May 2021
CVE-2021-31179Microsoft Office Remote Code Execution VulnerabilityHIGH 7.8EPSS 13.5%11 May 2021
CVE-2021-31178Microsoft Office Information Disclosure VulnerabilityMEDIUM 5.5EPSS 16.0%11 May 2021
CVE-2021-31166Microsoft HTTP Protocol Stack Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.8%11 May 2021
CVE-2021-28476Windows Hyper-V Remote Code Execution VulnerabilityCRITICAL 9.9EPSS 38.6%11 May 2021
CVE-2021-28474Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 50.8%11 May 2021
CVE-2021-27068Visual Studio Remote Code Execution VulnerabilityHIGH 8.8EPSS 53.6%11 May 2021
CVE-2021-26419Scripting Engine Memory Corruption VulnerabilityHIGH 7.5EPSS 22.8%11 May 2021
CVE-2021-21649Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.MEDIUM 5.4EPSS 72.7%11 May 2021
CVE-2021-21648Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.MEDIUM 6.1EPSS 11.3%11 May 2021
CVE-2020-23575A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus.HIGH 7.5EPSS 36.8%10 May 2021
CVE-2021-28663Arm Mali Graphics Processing Unit (GPU) Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 12.1%10 May 2021
CVE-2021-31755Tenda AC11 Router Stack Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 86.9%7 May 2021
CVE-2021-32099A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.CRITICAL 9.8EPSS 12.7%7 May 2021
CVE-2021-29203A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22.CRITICAL 9.8EPSS 68.3%6 May 2021
CVE-2021-28151Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.HIGH 8.8EPSS 27.9%6 May 2021
CVE-2021-28149Hongdian H8922 3.0.5 devices allow Directory Traversal.MEDIUM 6.5EPSS 15.9%6 May 2021
CVE-2021-32030ASUS Routers Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 99.4%6 May 2021
CVE-2021-29490Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter.MEDIUM 5.8EPSS 69.9%6 May 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.