Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 92 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-21983 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the… | MEDIUM 6.5EPSS 68.6% | 31 March 2021 |
| CVE-2021-21975 | VMware Server Side Request Forgery in vRealize Operations Manager API | KEVHIGH 7.5EPSS 78.3% | 31 March 2021 |
| CVE-2021-22992 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page… | CRITICAL 9.8EPSS 72.7% | 31 March 2021 |
| CVE-2021-22987 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also… | CRITICAL 9.9EPSS 13.7% | 31 March 2021 |
| CVE-2021-22988 | On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command… | HIGH 8.8EPSS 10.4% | 31 March 2021 |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 31 March 2021 |
| CVE-2020-24391 | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. | CRITICAL 9.8EPSS 74.5% | 30 March 2021 |
| CVE-2021-21630 | Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | MEDIUM 5.4EPSS 72.4% | 30 March 2021 |
| CVE-2021-21628 | Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | MEDIUM 5.4EPSS 81.4% | 30 March 2021 |
| CVE-2021-26919 | Apache Druid allows users to read data from other database systems using JDBC. | HIGH 8.8EPSS 22.8% | 30 March 2021 |
| CVE-2021-25162 | A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x:… | HIGH 8.1EPSS 25.6% | 30 March 2021 |
| CVE-2021-25161 | A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and… | MEDIUM 6.1EPSS 16.4% | 30 March 2021 |
| CVE-2021-25159 | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14… | MEDIUM 6.5EPSS 12.6% | 30 March 2021 |
| CVE-2021-25158 | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba… | MEDIUM 5.9EPSS 30.5% | 30 March 2021 |
| CVE-2021-25157 | A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below;… | MEDIUM 4.9EPSS 10.3% | 30 March 2021 |
| CVE-2021-25156 | A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and… | MEDIUM 4.9EPSS 39.6% | 30 March 2021 |
| CVE-2021-25155 | A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14… | MEDIUM 6.5EPSS 12.4% | 30 March 2021 |
| CVE-2021-27276 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. | HIGH 7.1EPSS 72.5% | 29 March 2021 |
| CVE-2021-27275 | This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. | HIGH 8.3EPSS 73.3% | 29 March 2021 |
| CVE-2021-27273 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. | HIGH 8.8EPSS 65.0% | 29 March 2021 |
| CVE-2021-27272 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. | HIGH 7.1EPSS 73.8% | 29 March 2021 |
| CVE-2021-21389 | The vulnerability has been fixed in BuddyPress 7.2.1. | HIGH 8.8EPSS 13.5% | 26 March 2021 |
| CVE-2020-19625 | Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter. | CRITICAL 9.8EPSS 13.1% | 26 March 2021 |
| CVE-2021-22506 | Micro Focus Access Manager Information Leakage Vulnerability | KEVHIGH 7.5EPSS 25.7% | 26 March 2021 |
| CVE-2021-22889 | Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. | MEDIUM 6.1EPSS 36.3% | 25 March 2021 |
| CVE-2021-22888 | Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. | MEDIUM 6.1EPSS 19.8% | 25 March 2021 |
| CVE-2021-3450 | Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. | HIGH 7.4EPSS 18.3% | 25 March 2021 |
| CVE-2021-3449 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. | MEDIUM 5.9EPSS 63.5% | 25 March 2021 |
| CVE-2021-29156 | ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. | HIGH 7.5EPSS 76.4% | 25 March 2021 |
| CVE-2021-1384 | A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. | HIGH 7.2EPSS 35.4% | 24 March 2021 |
| CVE-2021-22192 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server. | HIGH 8.8EPSS 13.1% | 24 March 2021 |
| CVE-2021-21402 | In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. | MEDIUM 6.5EPSS 80.3% | 23 March 2021 |
| CVE-2021-21351 | In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. | CRITICAL 9.1EPSS 82.1% | 23 March 2021 |
| CVE-2021-21350 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. | CRITICAL 9.8EPSS 15.2% | 23 March 2021 |
| CVE-2021-21349 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. | HIGH 8.6EPSS 46.8% | 23 March 2021 |
| CVE-2021-21348 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. | HIGH 7.5EPSS 13.8% | 23 March 2021 |
| CVE-2021-21347 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. | CRITICAL 9.8EPSS 14.3% | 23 March 2021 |
| CVE-2021-21346 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. | CRITICAL 9.8EPSS 76.4% | 23 March 2021 |
| CVE-2021-21345 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. | CRITICAL 9.9EPSS 72.3% | 23 March 2021 |
| CVE-2021-21344 | In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. | CRITICAL 9.8EPSS 76.0% | 23 March 2021 |
| CVE-2021-21343 | In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. | HIGH 7.5EPSS 46.7% | 23 March 2021 |
| CVE-2021-21342 | In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. | CRITICAL 9.1EPSS 50.0% | 23 March 2021 |
| CVE-2021-21341 | In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating… | HIGH 7.5EPSS 77.8% | 23 March 2021 |
| CVE-2021-25921 | In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. | MEDIUM 5.4EPSS 91.1% | 22 March 2021 |
| CVE-2021-25919 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. | MEDIUM 4.8EPSS 69.9% | 22 March 2021 |
| CVE-2021-26295 | Apache OFBiz has unsafe deserialization prior to 17.12.06. | CRITICAL 9.8EPSS 97.8% | 22 March 2021 |
| CVE-2021-27928 | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. | HIGH 7.2EPSS 38.4% | 19 March 2021 |
| CVE-2021-27358 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. | HIGH 7.5EPSS 83.0% | 18 March 2021 |
| CVE-2021-24146 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example. | HIGH 7.5EPSS 31.0% | 18 March 2021 |
| CVE-2021-24145 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request. | HIGH 7.2EPSS 87.2% | 18 March 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.