Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 90 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-1499 | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. | MEDIUM 5.3EPSS 80.4% | 6 May 2021 |
| CVE-2021-1498 | Cisco HyperFlex HX Data Platform Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 6 May 2021 |
| CVE-2021-1497 | Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 6 May 2021 |
| CVE-2020-28019 | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. | HIGH 7.5EPSS 61.7% | 6 May 2021 |
| CVE-2020-28018 | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. | CRITICAL 9.8EPSS 56.8% | 6 May 2021 |
| CVE-2020-28017 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. | CRITICAL 9.8EPSS 36.9% | 6 May 2021 |
| CVE-2021-24276 | The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 16.0% | 5 May 2021 |
| CVE-2021-24275 | The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 18.2% | 5 May 2021 |
| CVE-2021-24274 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | MEDIUM 6.1EPSS 17.6% | 5 May 2021 |
| CVE-2021-31800 | Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. | CRITICAL 9.8EPSS 19.4% | 5 May 2021 |
| CVE-2021-21551 | Dell dbutil Driver Insufficient Access Control Vulnerability | KEVHIGH 7.8EPSS 79.2% | 4 May 2021 |
| CVE-2021-28359 | The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. | MEDIUM 6.1EPSS 14.4% | 2 May 2021 |
| CVE-2021-31933 | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). | HIGH 7.2EPSS 13.9% | 30 April 2021 |
| CVE-2021-28959 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. | CRITICAL 9.8EPSS 16.9% | 30 April 2021 |
| CVE-2021-27651 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. | CRITICAL 9.8EPSS 53.8% | 29 April 2021 |
| CVE-2021-20090 | Arcadyan Buffalo Firmware Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 29 April 2021 |
| CVE-2021-25216 | In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are… | CRITICAL 9.8EPSS 82.4% | 29 April 2021 |
| CVE-2021-25215 | In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable… | HIGH 7.5EPSS 11.4% | 29 April 2021 |
| CVE-2021-25151 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. | HIGH 8.8EPSS 11.7% | 28 April 2021 |
| CVE-2021-27933 | pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. | MEDIUM 6.1EPSS 26.6% | 28 April 2021 |
| CVE-2021-31856 | A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go). | CRITICAL 9.8EPSS 75.4% | 28 April 2021 |
| CVE-2021-29442 | Nacos is a platform designed for dynamic service discovery and configuration and service management. | HIGH 7.5EPSS 66.6% | 27 April 2021 |
| CVE-2021-29441 | This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. | CRITICAL 9.8EPSS 87.7% | 27 April 2021 |
| CVE-2021-30128 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version | CRITICAL 9.8EPSS 81.2% | 27 April 2021 |
| CVE-2021-29200 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack | CRITICAL 9.8EPSS 55.4% | 27 April 2021 |
| CVE-2021-28125 | Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. | MEDIUM 6.1EPSS 64.0% | 27 April 2021 |
| CVE-2021-21224 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 84.2% | 26 April 2021 |
| CVE-2021-21220 | Google Chromium V8 Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 70.4% | 26 April 2021 |
| CVE-2021-21216 | Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. | MEDIUM 6.5EPSS 21.8% | 26 April 2021 |
| CVE-2021-21215 | Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. | MEDIUM 6.5EPSS 34.5% | 26 April 2021 |
| CVE-2021-31802 | NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. | HIGH 8.8EPSS 14.2% | 26 April 2021 |
| CVE-2021-31761 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature. | CRITICAL 9.6EPSS 33.6% | 25 April 2021 |
| CVE-2021-25899 | An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. | HIGH 7.5EPSS 12.2% | 23 April 2021 |
| CVE-2021-22205 | GitLab Community and Enterprise Editions Remote Code Execution Vulnerability | KEVCRITICAL 10.0EPSS 99.7% | 23 April 2021 |
| CVE-2021-22204 | ExifTool Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 100.0% | 23 April 2021 |
| CVE-2021-22893 | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | KEVCRITICAL 10.0EPSS 47.2% | 23 April 2021 |
| CVE-2021-2289 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Template, GTIN search). | HIGH 8.1EPSS 15.0% | 22 April 2021 |
| CVE-2021-2198 | Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). | HIGH 8.2EPSS 79.9% | 22 April 2021 |
| CVE-2021-2190 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). | HIGH 7.5EPSS 92.9% | 22 April 2021 |
| CVE-2021-2189 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). | HIGH 7.5EPSS 14.7% | 22 April 2021 |
| CVE-2021-3287 | Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. | CRITICAL 9.8EPSS 51.3% | 22 April 2021 |
| CVE-2021-21642 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | HIGH 8.1EPSS 37.8% | 21 April 2021 |
| CVE-2020-35314 | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer. | CRITICAL 9.8EPSS 26.9% | 20 April 2021 |
| CVE-2020-35313 | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer. | CRITICAL 9.8EPSS 45.2% | 20 April 2021 |
| CVE-2021-25681 | AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. | HIGH 7.5EPSS 10.9% | 20 April 2021 |
| CVE-2021-20023 | SonicWall Email Security Path Traversal Vulnerability | KEVMEDIUM 4.9EPSS 51.4% | 20 April 2021 |
| CVE-2021-27030 | A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system. | HIGH 7.8EPSS 59.6% | 19 April 2021 |
| CVE-2021-3493 | Linux Kernel Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 49.2% | 17 April 2021 |
| CVE-2020-2509 | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 33.4% | 17 April 2021 |
| CVE-2021-27691 | Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS… | CRITICAL 9.8EPSS 25.2% | 16 April 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.