SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 93 of 348

CVESummaryPriorityPublished
CVE-2021-28133Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen.MEDIUM 4.3EPSS 16.3%18 March 2021
CVE-2021-28419The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.HIGH 7.2EPSS 10.7%18 March 2021
CVE-2020-17525Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL.HIGH 7.5EPSS 40.1%17 March 2021
CVE-2021-28295Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.HIGH 7.5EPSS 15.9%16 March 2021
CVE-2021-27890SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.HIGH 8.8EPSS 10.6%15 March 2021
CVE-2021-21056Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file.HIGH 7.8EPSS 21.2%12 March 2021
CVE-2021-28143/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).HIGH 8.0EPSS 45.7%11 March 2021
CVE-2020-29045The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.CRITICAL 9.8EPSS 30.8%11 March 2021
CVE-2021-27084Visual Studio Code Java Extension Pack Remote Code Execution VulnerabilityHIGH 7.8EPSS 62.1%11 March 2021
CVE-2021-27083Remote Development Extension for Visual Studio Code Remote Code Execution VulnerabilityHIGH 7.8EPSS 61.9%11 March 2021
CVE-2021-27076Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH 8.8EPSS 14.4%11 March 2021
CVE-2021-26897Windows DNS Server Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 11.6%11 March 2021
CVE-2021-26877Windows DNS Server Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 16.5%11 March 2021
CVE-2021-26863Windows Win32k Elevation of Privilege VulnerabilityHIGH 7.0EPSS 11.8%11 March 2021
CVE-2021-26411Microsoft Internet Explorer Memory Corruption VulnerabilityKEVHIGH 8.8EPSS 80.8%11 March 2021
CVE-2020-13936An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container.HIGH 8.8EPSS 22.7%10 March 2021
CVE-2020-29238An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.HIGH 7.5EPSS 16.5%10 March 2021
CVE-2021-28116Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data.MEDIUM 5.3EPSS 12.9%9 March 2021
CVE-2021-21300In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such…HIGH 7.5EPSS 88.5%9 March 2021
CVE-2021-21295In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling.MEDIUM 5.9EPSS 18.9%9 March 2021
CVE-2021-21177Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.MEDIUM 6.5EPSS 17.3%9 March 2021
CVE-2021-21166Google Chromium Race Condition VulnerabilityKEVHIGH 8.8EPSS 26.7%9 March 2021
CVE-2021-21480SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).HIGH 8.8EPSS 50.9%9 March 2021
CVE-2020-27838The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later.MEDIUM 6.5EPSS 17.9%8 March 2021
CVE-2021-26294They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as…HIGH 7.5EPSS 16.9%7 March 2021
CVE-2020-29134The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64.HIGH 8.6EPSS 27.2%5 March 2021
CVE-2021-27907Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information.MEDIUM 5.4EPSS 86.4%5 March 2021
CVE-2021-27965The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.CRITICAL 9.8EPSS 11.8%5 March 2021
CVE-2021-27964SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload.CRITICAL 9.8EPSS 47.5%5 March 2021
CVE-2021-27314SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.CRITICAL 9.8EPSS 12.4%5 March 2021
CVE-2020-8298fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.CRITICAL 9.8EPSS 11.2%4 March 2021
CVE-2020-24913A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.CRITICAL 9.8EPSS 40.9%4 March 2021
CVE-2021-27931LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp.CRITICAL 9.1EPSS 18.1%3 March 2021
CVE-2021-22884Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”.HIGH 7.5EPSS 32.4%3 March 2021
CVE-2021-22883Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established.HIGH 7.5EPSS 74.4%3 March 2021
CVE-2021-22681Rockwell Multiple Products Insufficient Protected Credentials VulnerabilityKEVCRITICAL 9.8EPSS 63.6%3 March 2021
CVE-2021-21978VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability.CRITICAL 9.8EPSS 99.0%3 March 2021
CVE-2020-29047The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.CRITICAL 9.8EPSS 16.0%3 March 2021
CVE-2021-27078Microsoft Exchange Server Remote Code Execution VulnerabilityCRITICAL 9.1EPSS 20.6%3 March 2021
CVE-2021-27065Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 99.9%3 March 2021
CVE-2021-26858Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 93.7%3 March 2021
CVE-2021-26857Microsoft Exchange Server Remote Code Execution VulnerabilityKEVHIGH 7.8EPSS 95.8%3 March 2021
CVE-2021-26855Microsoft Exchange Server Remote Code Execution VulnerabilityKEVCRITICAL 9.1EPSS 100.0%3 March 2021
CVE-2021-26854Microsoft Exchange Server Remote Code Execution VulnerabilityMEDIUM 6.6EPSS 23.6%3 March 2021
CVE-2021-26412Microsoft Exchange Server Remote Code Execution VulnerabilityCRITICAL 9.1EPSS 33.8%3 March 2021
CVE-2021-27886rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request.CRITICAL 9.8EPSS 45.6%2 March 2021
CVE-2021-27878Veritas Backup Exec Agent Command Execution VulnerabilityKEVHIGH 8.8EPSS 24.0%1 March 2021
CVE-2021-27877Veritas Backup Exec Agent Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 64.9%1 March 2021
CVE-2021-27876Veritas Backup Exec Agent File Access VulnerabilityKEVHIGH 8.1EPSS 13.5%1 March 2021
CVE-2021-25833The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting.CRITICAL 9.8EPSS 43.5%1 March 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.