SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 94 of 348

CVESummaryPriorityPublished
CVE-2021-25832A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.CRITICAL 9.8EPSS 12.6%1 March 2021
CVE-2021-25831An attacker must request the conversion of the crafted file from PPTT into PPTX format.CRITICAL 9.8EPSS 11.5%1 March 2021
CVE-2021-25830An attacker must request the conversion of the crafted file from DOCT into DOCX format.CRITICAL 9.8EPSS 11.8%1 March 2021
CVE-2021-25122When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B…HIGH 7.5EPSS 18.1%1 March 2021
CVE-2021-27132SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.CRITICAL 9.8EPSS 16.5%27 February 2021
CVE-2021-3197The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.CRITICAL 9.8EPSS 72.3%27 February 2021
CVE-2021-25283The jinja renderer does not protect against server side template injection attacks.CRITICAL 9.8EPSS 10.5%27 February 2021
CVE-2021-25282The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.CRITICAL 9.1EPSS 92.4%27 February 2021
CVE-2021-25281Thus, an attacker can remotely run any wheel modules on the master.CRITICAL 9.8EPSS 73.1%27 February 2021
CVE-2021-27198Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI.CRITICAL 9.8EPSS 13.6%26 February 2021
CVE-2020-27223In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS)…MEDIUM 5.3EPSS 78.0%26 February 2021
CVE-2021-26701.NET Core Remote Code Execution VulnerabilityHIGH 8.1EPSS 30.1%25 February 2021
CVE-2021-24094Windows TCP/IP Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 22.1%25 February 2021
CVE-2021-24093Windows Graphics Component Remote Code Execution VulnerabilityHIGH 8.8EPSS 46.1%25 February 2021
CVE-2021-24086Windows TCP/IP Denial of Service VulnerabilityHIGH 7.5EPSS 59.0%25 February 2021
CVE-2021-24078Windows DNS Server Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 11.9%25 February 2021
CVE-2021-24074Windows TCP/IP Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 25.7%25 February 2021
CVE-2021-1732Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 78.4%25 February 2021
CVE-2021-27670Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.CRITICAL 9.8EPSS 61.3%25 February 2021
CVE-2021-1388A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device.CRITICAL 10.0EPSS 14.8%24 February 2021
CVE-2020-11987Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel.HIGH 8.2EPSS 13.3%24 February 2021
CVE-2021-21974OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability.HIGH 8.8EPSS 45.1%24 February 2021
CVE-2021-21973VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) VulnerabilityKEVMEDIUM 5.3EPSS 87.6%24 February 2021
CVE-2021-21972VMware vCenter Server Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%24 February 2021
CVE-2021-21618Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.MEDIUM 5.4EPSS 81.8%24 February 2021
CVE-2021-21616Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.MEDIUM 4.6EPSS 78.8%24 February 2021
CVE-2021-20660Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.MEDIUM 6.1EPSS 47.2%24 February 2021
CVE-2021-3407Double free of object during linearization may lead to memory corruption and other potential consequences.MEDIUM 5.5EPSS 50.2%23 February 2021
CVE-2020-16243Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files.HIGH 7.8EPSS 12.4%23 February 2021
CVE-2020-28429All versions of package geojson2kml are vulnerable to Command Injection via the index.js file.CRITICAL 9.8EPSS 63.3%23 February 2021
CVE-2020-29453The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF…MEDIUM 5.3EPSS 23.9%22 February 2021
CVE-2021-3120An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server.CRITICAL 9.8EPSS 36.8%22 February 2021
CVE-2020-21224A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0.CRITICAL 9.8EPSS 38.7%22 February 2021
CVE-2021-26120Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.CRITICAL 9.8EPSS 82.3%22 February 2021
CVE-2021-27513The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."HIGH 8.8EPSS 28.4%22 February 2021
CVE-2019-25024OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.CRITICAL 9.8EPSS 27.6%19 February 2021
CVE-2021-26747Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.CRITICAL 9.8EPSS 54.8%18 February 2021
CVE-2020-8625BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features.HIGH 8.1EPSS 64.2%17 February 2021
CVE-2021-27224The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.HIGH 7.5EPSS 38.0%17 February 2021
CVE-2021-27104Accellion FTA OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 56.7%16 February 2021
CVE-2021-27103Accellion FTA Server-Side Request Forgery (SSRF) VulnerabilityKEVCRITICAL 9.8EPSS 11.4%16 February 2021
CVE-2021-23840Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform.HIGH 7.5EPSS 50.7%16 February 2021
CVE-2021-21315System Information Library for Node.JS Command InjectionKEVHIGH 7.8EPSS 90.7%16 February 2021
CVE-2021-3239E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.CRITICAL 9.8EPSS 18.4%15 February 2021
CVE-2020-28337A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature.HIGH 7.2EPSS 16.6%15 February 2021
CVE-2020-24899Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability.HIGH 8.8EPSS 16.6%15 February 2021
CVE-2020-22427NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability.HIGH 7.2EPSS 14.3%15 February 2021
CVE-2020-35775CITSmart before 9.1.2.23 allows LDAP Injection.CRITICAL 9.8EPSS 13.3%15 February 2021
CVE-2021-25299Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS).MEDIUM 6.1EPSS 97.8%15 February 2021
CVE-2021-25298Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 75.1%15 February 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.