Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 93 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-28133 | Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. | MEDIUM 4.3EPSS 16.3% | 18 March 2021 |
| CVE-2021-28419 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases. | HIGH 7.2EPSS 10.7% | 18 March 2021 |
| CVE-2020-17525 | Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. | HIGH 7.5EPSS 40.1% | 17 March 2021 |
| CVE-2021-28295 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | HIGH 7.5EPSS 15.9% | 16 March 2021 |
| CVE-2021-27890 | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. | HIGH 8.8EPSS 10.6% | 15 March 2021 |
| CVE-2021-21056 | Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. | HIGH 7.8EPSS 21.2% | 12 March 2021 |
| CVE-2021-28143 | /jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools). | HIGH 8.0EPSS 45.7% | 11 March 2021 |
| CVE-2020-29045 | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php. | CRITICAL 9.8EPSS 30.8% | 11 March 2021 |
| CVE-2021-27084 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability | HIGH 7.8EPSS 62.1% | 11 March 2021 |
| CVE-2021-27083 | Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | HIGH 7.8EPSS 61.9% | 11 March 2021 |
| CVE-2021-27076 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH 8.8EPSS 14.4% | 11 March 2021 |
| CVE-2021-26897 | Windows DNS Server Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 11.6% | 11 March 2021 |
| CVE-2021-26877 | Windows DNS Server Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 16.5% | 11 March 2021 |
| CVE-2021-26863 | Windows Win32k Elevation of Privilege Vulnerability | HIGH 7.0EPSS 11.8% | 11 March 2021 |
| CVE-2021-26411 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVHIGH 8.8EPSS 80.8% | 11 March 2021 |
| CVE-2020-13936 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. | HIGH 8.8EPSS 22.7% | 10 March 2021 |
| CVE-2020-29238 | An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request. | HIGH 7.5EPSS 16.5% | 10 March 2021 |
| CVE-2021-28116 | Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. | MEDIUM 5.3EPSS 12.9% | 9 March 2021 |
| CVE-2021-21300 | In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such… | HIGH 7.5EPSS 88.5% | 9 March 2021 |
| CVE-2021-21295 | In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. | MEDIUM 5.9EPSS 18.9% | 9 March 2021 |
| CVE-2021-21177 | Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | MEDIUM 6.5EPSS 17.3% | 9 March 2021 |
| CVE-2021-21166 | Google Chromium Race Condition Vulnerability | KEVHIGH 8.8EPSS 26.7% | 9 March 2021 |
| CVE-2021-21480 | SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). | HIGH 8.8EPSS 50.9% | 9 March 2021 |
| CVE-2020-27838 | The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. | MEDIUM 6.5EPSS 17.9% | 8 March 2021 |
| CVE-2021-26294 | They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as… | HIGH 7.5EPSS 16.9% | 7 March 2021 |
| CVE-2020-29134 | The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. | HIGH 8.6EPSS 27.2% | 5 March 2021 |
| CVE-2021-27907 | Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. | MEDIUM 5.4EPSS 86.4% | 5 March 2021 |
| CVE-2021-27965 | The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request. | CRITICAL 9.8EPSS 11.8% | 5 March 2021 |
| CVE-2021-27964 | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. | CRITICAL 9.8EPSS 47.5% | 5 March 2021 |
| CVE-2021-27314 | SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page. | CRITICAL 9.8EPSS 12.4% | 5 March 2021 |
| CVE-2020-8298 | fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods. | CRITICAL 9.8EPSS 11.2% | 4 March 2021 |
| CVE-2020-24913 | A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request. | CRITICAL 9.8EPSS 40.9% | 4 March 2021 |
| CVE-2021-27931 | LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. | CRITICAL 9.1EPSS 18.1% | 3 March 2021 |
| CVE-2021-22884 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. | HIGH 7.5EPSS 32.4% | 3 March 2021 |
| CVE-2021-22883 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. | HIGH 7.5EPSS 74.4% | 3 March 2021 |
| CVE-2021-22681 | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | KEVCRITICAL 9.8EPSS 63.6% | 3 March 2021 |
| CVE-2021-21978 | VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. | CRITICAL 9.8EPSS 99.0% | 3 March 2021 |
| CVE-2020-29047 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. | CRITICAL 9.8EPSS 16.0% | 3 March 2021 |
| CVE-2021-27078 | Microsoft Exchange Server Remote Code Execution Vulnerability | CRITICAL 9.1EPSS 20.6% | 3 March 2021 |
| CVE-2021-27065 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 99.9% | 3 March 2021 |
| CVE-2021-26858 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 93.7% | 3 March 2021 |
| CVE-2021-26857 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVHIGH 7.8EPSS 95.8% | 3 March 2021 |
| CVE-2021-26855 | Microsoft Exchange Server Remote Code Execution Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 3 March 2021 |
| CVE-2021-26854 | Microsoft Exchange Server Remote Code Execution Vulnerability | MEDIUM 6.6EPSS 23.6% | 3 March 2021 |
| CVE-2021-26412 | Microsoft Exchange Server Remote Code Execution Vulnerability | CRITICAL 9.1EPSS 33.8% | 3 March 2021 |
| CVE-2021-27886 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. | CRITICAL 9.8EPSS 45.6% | 2 March 2021 |
| CVE-2021-27878 | Veritas Backup Exec Agent Command Execution Vulnerability | KEVHIGH 8.8EPSS 24.0% | 1 March 2021 |
| CVE-2021-27877 | Veritas Backup Exec Agent Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 64.9% | 1 March 2021 |
| CVE-2021-27876 | Veritas Backup Exec Agent File Access Vulnerability | KEVHIGH 8.1EPSS 13.5% | 1 March 2021 |
| CVE-2021-25833 | The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. | CRITICAL 9.8EPSS 43.5% | 1 March 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.