SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,963 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 90 of 348

CVESummaryPriorityPublished
CVE-2021-1499A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device.MEDIUM 5.3EPSS 80.4%6 May 2021
CVE-2021-1498Cisco HyperFlex HX Data Platform Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%6 May 2021
CVE-2021-1497Cisco HyperFlex HX Installer Virtual Machine Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.9%6 May 2021
CVE-2020-28019Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.HIGH 7.5EPSS 61.7%6 May 2021
CVE-2020-28018Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.CRITICAL 9.8EPSS 56.8%6 May 2021
CVE-2020-28017Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients.CRITICAL 9.8EPSS 36.9%6 May 2021
CVE-2021-24276The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 16.0%5 May 2021
CVE-2021-24275The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 18.2%5 May 2021
CVE-2021-24274The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issueMEDIUM 6.1EPSS 17.6%5 May 2021
CVE-2021-31800Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22.CRITICAL 9.8EPSS 19.4%5 May 2021
CVE-2021-21551Dell dbutil Driver Insufficient Access Control VulnerabilityKEVHIGH 7.8EPSS 79.2%4 May 2021
CVE-2021-28359The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.MEDIUM 6.1EPSS 14.4%2 May 2021
CVE-2021-31933A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht).HIGH 7.2EPSS 13.9%30 April 2021
CVE-2021-28959Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive.CRITICAL 9.8EPSS 16.9%30 April 2021
CVE-2021-27651In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.CRITICAL 9.8EPSS 53.8%29 April 2021
CVE-2021-20090Arcadyan Buffalo Firmware Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%29 April 2021
CVE-2021-25216In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are…CRITICAL 9.8EPSS 82.4%29 April 2021
CVE-2021-25215In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable…HIGH 7.5EPSS 11.4%29 April 2021
CVE-2021-25151A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.HIGH 8.8EPSS 11.7%28 April 2021
CVE-2021-27933pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.MEDIUM 6.1EPSS 26.6%28 April 2021
CVE-2021-31856A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).CRITICAL 9.8EPSS 75.4%28 April 2021
CVE-2021-29442Nacos is a platform designed for dynamic service discovery and configuration and service management.HIGH 7.5EPSS 66.6%27 April 2021
CVE-2021-29441This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks.CRITICAL 9.8EPSS 87.7%27 April 2021
CVE-2021-30128Apache OFBiz has unsafe deserialization prior to 17.12.07 versionCRITICAL 9.8EPSS 81.2%27 April 2021
CVE-2021-29200Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attackCRITICAL 9.8EPSS 55.4%27 April 2021
CVE-2021-28125Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious.MEDIUM 6.1EPSS 64.0%27 April 2021
CVE-2021-21224Google Chromium V8 Type Confusion VulnerabilityKEVHIGH 8.8EPSS 84.2%26 April 2021
CVE-2021-21220Google Chromium V8 Improper Input Validation VulnerabilityKEVHIGH 8.8EPSS 70.4%26 April 2021
CVE-2021-21216Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.MEDIUM 6.5EPSS 21.8%26 April 2021
CVE-2021-21215Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.MEDIUM 6.5EPSS 34.5%26 April 2021
CVE-2021-31802NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication.HIGH 8.8EPSS 14.2%26 April 2021
CVE-2021-31761Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.CRITICAL 9.6EPSS 33.6%25 April 2021
CVE-2021-25899An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection.HIGH 7.5EPSS 12.2%23 April 2021
CVE-2021-22205GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityKEVCRITICAL 10.0EPSS 99.7%23 April 2021
CVE-2021-22204ExifTool Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 100.0%23 April 2021
CVE-2021-22893Ivanti Pulse Connect Secure Use-After-Free VulnerabilityKEVCRITICAL 10.0EPSS 47.2%23 April 2021
CVE-2021-2289Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Template, GTIN search).HIGH 8.1EPSS 15.0%22 April 2021
CVE-2021-2198Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin).HIGH 8.2EPSS 79.9%22 April 2021
CVE-2021-2190Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template).HIGH 7.5EPSS 92.9%22 April 2021
CVE-2021-2189Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template).HIGH 7.5EPSS 14.7%22 April 2021
CVE-2021-3287Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.CRITICAL 9.8EPSS 51.3%22 April 2021
CVE-2021-21642Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.HIGH 8.1EPSS 37.8%21 April 2021
CVE-2020-35314A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.CRITICAL 9.8EPSS 26.9%20 April 2021
CVE-2020-35313A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.CRITICAL 9.8EPSS 45.2%20 April 2021
CVE-2021-25681AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS.HIGH 7.5EPSS 10.9%20 April 2021
CVE-2021-20023SonicWall Email Security Path Traversal VulnerabilityKEVMEDIUM 4.9EPSS 51.4%20 April 2021
CVE-2021-27030A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.HIGH 7.8EPSS 59.6%19 April 2021
CVE-2021-3493Linux Kernel Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 49.2%17 April 2021
CVE-2020-2509QNAP Network-Attached Storage (NAS) Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 33.4%17 April 2021
CVE-2021-27691Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS…CRITICAL 9.8EPSS 25.2%16 April 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.