SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 91 of 348

CVESummaryPriorityPublished
CVE-2021-29447A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks.MEDIUM 6.5EPSS 85.7%15 April 2021
CVE-2021-21087Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability.MEDIUM 5.4EPSS 37.1%15 April 2021
CVE-2021-27850A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry.CRITICAL 9.8EPSS 93.5%15 April 2021
CVE-2021-3017The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.HIGH 7.5EPSS 63.0%14 April 2021
CVE-2021-26030Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error pageMEDIUM 6.1EPSS 82.3%14 April 2021
CVE-2021-27250This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points.MEDIUM 6.5EPSS 67.4%14 April 2021
CVE-2021-27114Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.CRITICAL 9.8EPSS 24.6%14 April 2021
CVE-2021-26812Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module.MEDIUM 6.1EPSS 97.2%14 April 2021
CVE-2021-29440Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages.HIGH 7.2EPSS 30.6%13 April 2021
CVE-2021-28482Microsoft Exchange Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 83.2%13 April 2021
CVE-2021-28481Microsoft Exchange Server Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 36.2%13 April 2021
CVE-2021-28480Microsoft Exchange Server Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 71.2%13 April 2021
CVE-2021-28472Visual Studio Code Maven for Java Extension Remote Code Execution VulnerabilityHIGH 7.8EPSS 61.8%13 April 2021
CVE-2021-28325Windows SMB Information Disclosure VulnerabilityMEDIUM 6.5EPSS 62.1%13 April 2021
CVE-2021-23279Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID.CRITICAL 10.0EPSS 27.1%13 April 2021
CVE-2021-22720A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.HIGH 7.2EPSS 30.5%13 April 2021
CVE-2021-22719A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.HIGH 8.8EPSS 40.6%13 April 2021
CVE-2021-22718A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.HIGH 7.8EPSS 27.2%13 April 2021
CVE-2021-22717A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.HIGH 8.8EPSS 38.9%13 April 2021
CVE-2020-13568SQL injection vulnerability exists in phpGACL 3.3.7.HIGH 8.8EPSS 29.7%13 April 2021
CVE-2021-30176The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.CRITICAL 9.8EPSS 29.0%13 April 2021
CVE-2021-29425In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not…MEDIUM 4.8EPSS 10.2%13 April 2021
CVE-2021-27905To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter.CRITICAL 9.8EPSS 93.1%13 April 2021
CVE-2021-29003Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.CRITICAL 9.8EPSS 45.4%13 April 2021
CVE-2021-20080Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a…MEDIUM 6.1EPSS 93.1%9 April 2021
CVE-2021-20022SonicWall Email Security Unrestricted Upload of File VulnerabilityKEVHIGH 7.2EPSS 16.5%9 April 2021
CVE-2021-20021SonicWall Email Security Improper Privilege Management VulnerabilityKEVCRITICAL 9.8EPSS 83.4%9 April 2021
CVE-2021-28924Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.MEDIUM 6.1EPSS 10.5%8 April 2021
CVE-2021-1473Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers.CRITICAL 9.8EPSS 64.2%8 April 2021
CVE-2021-1472Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers.CRITICAL 9.8EPSS 71.8%8 April 2021
CVE-2021-21425In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials.CRITICAL 9.8EPSS 80.6%7 April 2021
CVE-2021-26709D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters.CRITICAL 9.8EPSS 40.1%7 April 2021
CVE-2021-30149Composr 10.0.36 allows upload and execution of PHP files.CRITICAL 9.8EPSS 10.1%6 April 2021
CVE-2020-17453WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.MEDIUM 6.1EPSS 26.2%5 April 2021
CVE-2021-24209The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option.HIGH 7.2EPSS 27.7%5 April 2021
CVE-2021-24175The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related…CRITICAL 9.8EPSS 14.5%5 April 2021
CVE-2021-24169The tab parameter in the Admin Panel is vulnerable to reflected XSS.MEDIUM 6.1EPSS 10.3%5 April 2021
CVE-2021-24155The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones,…HIGH 7.2EPSS 84.1%5 April 2021
CVE-2020-27600HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.CRITICAL 9.8EPSS 13.9%2 April 2021
CVE-2021-3374Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.MEDIUM 5.3EPSS 14.4%2 April 2021
CVE-2021-27973SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.HIGH 7.2EPSS 11.0%2 April 2021
CVE-2021-1789Apple Multiple Products Type Confusion VulnerabilityKEVHIGH 8.8EPSS 14.5%2 April 2021
CVE-2021-28113A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.MEDIUM 6.7EPSS 22.3%2 April 2021
CVE-2021-26072The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.MEDIUM 4.3EPSS 38.8%1 April 2021
CVE-2021-20078Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component.CRITICAL 9.1EPSS 60.4%1 April 2021
CVE-2021-28165In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.HIGH 7.5EPSS 53.9%1 April 2021
CVE-2021-28164In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory.MEDIUM 5.3EPSS 82.4%1 April 2021
CVE-2021-20235A remote, unauthenticated attacker who sends a crafted request to the zeromq server could trigger a buffer overflow WRITE of arbitrary data if CURVE/ZAP authentication is not enabled.HIGH 8.1EPSS 43.9%1 April 2021
CVE-2021-28918Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages.CRITICAL 9.1EPSS 16.7%1 April 2021
CVE-2021-22991F5 BIG-IP Traffic Management Microkernel Buffer OverflowKEVCRITICAL 9.8EPSS 61.1%31 March 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.