SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 92 of 348

CVESummaryPriorityPublished
CVE-2021-21983Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the…MEDIUM 6.5EPSS 68.6%31 March 2021
CVE-2021-21975VMware Server Side Request Forgery in vRealize Operations Manager APIKEVHIGH 7.5EPSS 78.3%31 March 2021
CVE-2021-22992On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page…CRITICAL 9.8EPSS 72.7%31 March 2021
CVE-2021-22987On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also…CRITICAL 9.9EPSS 13.7%31 March 2021
CVE-2021-22988On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, TMUI, also referred to as the Configuration utility, has an authenticated remote command…HIGH 8.8EPSS 10.4%31 March 2021
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%31 March 2021
CVE-2020-24391mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way.CRITICAL 9.8EPSS 74.5%30 March 2021
CVE-2021-21630Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.MEDIUM 5.4EPSS 72.4%30 March 2021
CVE-2021-21628Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.MEDIUM 5.4EPSS 81.4%30 March 2021
CVE-2021-26919Apache Druid allows users to read data from other database systems using JDBC.HIGH 8.8EPSS 22.8%30 March 2021
CVE-2021-25162A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x:…HIGH 8.1EPSS 25.6%30 March 2021
CVE-2021-25161A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and…MEDIUM 6.1EPSS 16.4%30 March 2021
CVE-2021-25159A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14…MEDIUM 6.5EPSS 12.6%30 March 2021
CVE-2021-25158A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba…MEDIUM 5.9EPSS 30.5%30 March 2021
CVE-2021-25157A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below;…MEDIUM 4.9EPSS 10.3%30 March 2021
CVE-2021-25156A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and…MEDIUM 4.9EPSS 39.6%30 March 2021
CVE-2021-25155A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14…MEDIUM 6.5EPSS 12.4%30 March 2021
CVE-2021-27276This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.HIGH 7.1EPSS 72.5%29 March 2021
CVE-2021-27275This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.HIGH 8.3EPSS 73.3%29 March 2021
CVE-2021-27273This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.HIGH 8.8EPSS 65.0%29 March 2021
CVE-2021-27272This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.HIGH 7.1EPSS 73.8%29 March 2021
CVE-2021-21389The vulnerability has been fixed in BuddyPress 7.2.1.HIGH 8.8EPSS 13.5%26 March 2021
CVE-2020-19625Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.CRITICAL 9.8EPSS 13.1%26 March 2021
CVE-2021-22506Micro Focus Access Manager Information Leakage VulnerabilityKEVHIGH 7.5EPSS 25.7%26 March 2021
CVE-2021-22889Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped.MEDIUM 6.1EPSS 36.3%25 March 2021
CVE-2021-22888Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php.MEDIUM 6.1EPSS 19.8%25 March 2021
CVE-2021-3450Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check.HIGH 7.4EPSS 18.3%25 March 2021
CVE-2021-3449An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.MEDIUM 5.9EPSS 63.5%25 March 2021
CVE-2021-29156ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol.HIGH 7.5EPSS 76.4%25 March 2021
CVE-2021-1384A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user.HIGH 7.2EPSS 35.4%24 March 2021
CVE-2021-22192An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.HIGH 8.8EPSS 13.1%24 March 2021
CVE-2021-21402In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system.MEDIUM 6.5EPSS 80.3%23 March 2021
CVE-2021-21351In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.CRITICAL 9.1EPSS 82.1%23 March 2021
CVE-2021-21350In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream.CRITICAL 9.8EPSS 15.2%23 March 2021
CVE-2021-21349In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream.HIGH 8.6EPSS 46.8%23 March 2021
CVE-2021-21348In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return.HIGH 7.5EPSS 13.8%23 March 2021
CVE-2021-21347In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.CRITICAL 9.8EPSS 14.3%23 March 2021
CVE-2021-21346In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.CRITICAL 9.8EPSS 76.4%23 March 2021
CVE-2021-21345In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream.CRITICAL 9.9EPSS 72.3%23 March 2021
CVE-2021-21344In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream.CRITICAL 9.8EPSS 76.0%23 March 2021
CVE-2021-21343In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects.HIGH 7.5EPSS 46.7%23 March 2021
CVE-2021-21342In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects.CRITICAL 9.1EPSS 50.0%23 March 2021
CVE-2021-21341In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating…HIGH 7.5EPSS 77.8%23 March 2021
CVE-2021-25921In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section.MEDIUM 5.4EPSS 91.1%22 March 2021
CVE-2021-25919In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly.MEDIUM 4.8EPSS 69.9%22 March 2021
CVE-2021-26295Apache OFBiz has unsafe deserialization prior to 17.12.06.CRITICAL 9.8EPSS 97.8%22 March 2021
CVE-2021-27928A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL.HIGH 7.2EPSS 38.4%19 March 2021
CVE-2021-27358The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.HIGH 7.5EPSS 83.0%18 March 2021
CVE-2021-24146Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.HIGH 7.5EPSS 31.0%18 March 2021
CVE-2021-24145Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.HIGH 7.2EPSS 87.2%18 March 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.