Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 91 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-29447 | A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. | MEDIUM 6.5EPSS 85.7% | 15 April 2021 |
| CVE-2021-21087 | Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. | MEDIUM 5.4EPSS 37.1% | 15 April 2021 |
| CVE-2021-27850 | A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. | CRITICAL 9.8EPSS 93.5% | 15 April 2021 |
| CVE-2021-3017 | The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code. | HIGH 7.5EPSS 63.0% | 14 April 2021 |
| CVE-2021-26030 | Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page | MEDIUM 6.1EPSS 82.3% | 14 April 2021 |
| CVE-2021-27250 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. | MEDIUM 6.5EPSS 67.4% | 14 April 2021 |
| CVE-2021-27114 | Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address. | CRITICAL 9.8EPSS 24.6% | 14 April 2021 |
| CVE-2021-26812 | Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. | MEDIUM 6.1EPSS 97.2% | 14 April 2021 |
| CVE-2021-29440 | Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. | HIGH 7.2EPSS 30.6% | 13 April 2021 |
| CVE-2021-28482 | Microsoft Exchange Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 83.2% | 13 April 2021 |
| CVE-2021-28481 | Microsoft Exchange Server Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 36.2% | 13 April 2021 |
| CVE-2021-28480 | Microsoft Exchange Server Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 71.2% | 13 April 2021 |
| CVE-2021-28472 | Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability | HIGH 7.8EPSS 61.8% | 13 April 2021 |
| CVE-2021-28325 | Windows SMB Information Disclosure Vulnerability | MEDIUM 6.5EPSS 62.1% | 13 April 2021 |
| CVE-2021-23279 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. | CRITICAL 10.0EPSS 27.1% | 13 April 2021 |
| CVE-2021-22720 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project. | HIGH 7.2EPSS 30.5% | 13 April 2021 |
| CVE-2021-22719 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded. | HIGH 8.8EPSS 40.6% | 13 April 2021 |
| CVE-2021-22718 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files. | HIGH 7.8EPSS 27.2% | 13 April 2021 |
| CVE-2021-22717 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files. | HIGH 8.8EPSS 38.9% | 13 April 2021 |
| CVE-2020-13568 | SQL injection vulnerability exists in phpGACL 3.3.7. | HIGH 8.8EPSS 29.7% | 13 April 2021 |
| CVE-2021-30176 | The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. | CRITICAL 9.8EPSS 29.0% | 13 April 2021 |
| CVE-2021-29425 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not… | MEDIUM 4.8EPSS 10.2% | 13 April 2021 |
| CVE-2021-27905 | To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. | CRITICAL 9.8EPSS 93.1% | 13 April 2021 |
| CVE-2021-29003 | Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI. | CRITICAL 9.8EPSS 45.4% | 13 April 2021 |
| CVE-2021-20080 | Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a… | MEDIUM 6.1EPSS 93.1% | 9 April 2021 |
| CVE-2021-20022 | SonicWall Email Security Unrestricted Upload of File Vulnerability | KEVHIGH 7.2EPSS 16.5% | 9 April 2021 |
| CVE-2021-20021 | SonicWall Email Security Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 83.4% | 9 April 2021 |
| CVE-2021-28924 | Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page. | MEDIUM 6.1EPSS 10.5% | 8 April 2021 |
| CVE-2021-1473 | Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. | CRITICAL 9.8EPSS 64.2% | 8 April 2021 |
| CVE-2021-1472 | Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. | CRITICAL 9.8EPSS 71.8% | 8 April 2021 |
| CVE-2021-21425 | In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. | CRITICAL 9.8EPSS 80.6% | 7 April 2021 |
| CVE-2021-26709 | D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. | CRITICAL 9.8EPSS 40.1% | 7 April 2021 |
| CVE-2021-30149 | Composr 10.0.36 allows upload and execution of PHP files. | CRITICAL 9.8EPSS 10.1% | 6 April 2021 |
| CVE-2020-17453 | WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | MEDIUM 6.1EPSS 26.2% | 5 April 2021 |
| CVE-2021-24209 | The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. | HIGH 7.2EPSS 27.7% | 5 April 2021 |
| CVE-2021-24175 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related… | CRITICAL 9.8EPSS 14.5% | 5 April 2021 |
| CVE-2021-24169 | The tab parameter in the Admin Panel is vulnerable to reflected XSS. | MEDIUM 6.1EPSS 10.3% | 5 April 2021 |
| CVE-2021-24155 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones,… | HIGH 7.2EPSS 84.1% | 5 April 2021 |
| CVE-2020-27600 | HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter. | CRITICAL 9.8EPSS 13.9% | 2 April 2021 |
| CVE-2021-3374 | Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash. | MEDIUM 5.3EPSS 14.4% | 2 April 2021 |
| CVE-2021-27973 | SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages. | HIGH 7.2EPSS 11.0% | 2 April 2021 |
| CVE-2021-1789 | Apple Multiple Products Type Confusion Vulnerability | KEVHIGH 8.8EPSS 14.5% | 2 April 2021 |
| CVE-2021-28113 | A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account. | MEDIUM 6.7EPSS 22.3% | 2 April 2021 |
| CVE-2021-26072 | The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability. | MEDIUM 4.3EPSS 38.8% | 1 April 2021 |
| CVE-2021-20078 | Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. | CRITICAL 9.1EPSS 60.4% | 1 April 2021 |
| CVE-2021-28165 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | HIGH 7.5EPSS 53.9% | 1 April 2021 |
| CVE-2021-28164 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. | MEDIUM 5.3EPSS 82.4% | 1 April 2021 |
| CVE-2021-20235 | A remote, unauthenticated attacker who sends a crafted request to the zeromq server could trigger a buffer overflow WRITE of arbitrary data if CURVE/ZAP authentication is not enabled. | HIGH 8.1EPSS 43.9% | 1 April 2021 |
| CVE-2021-28918 | Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. | CRITICAL 9.1EPSS 16.7% | 1 April 2021 |
| CVE-2021-22991 | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | KEVCRITICAL 9.8EPSS 61.1% | 31 March 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.