Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 94 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-25832 | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. | CRITICAL 9.8EPSS 12.6% | 1 March 2021 |
| CVE-2021-25831 | An attacker must request the conversion of the crafted file from PPTT into PPTX format. | CRITICAL 9.8EPSS 11.5% | 1 March 2021 |
| CVE-2021-25830 | An attacker must request the conversion of the crafted file from DOCT into DOCX format. | CRITICAL 9.8EPSS 11.8% | 1 March 2021 |
| CVE-2021-25122 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B… | HIGH 7.5EPSS 18.1% | 1 March 2021 |
| CVE-2021-27132 | SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header. | CRITICAL 9.8EPSS 16.5% | 27 February 2021 |
| CVE-2021-3197 | The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. | CRITICAL 9.8EPSS 72.3% | 27 February 2021 |
| CVE-2021-25283 | The jinja renderer does not protect against server side template injection attacks. | CRITICAL 9.8EPSS 10.5% | 27 February 2021 |
| CVE-2021-25282 | The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. | CRITICAL 9.1EPSS 92.4% | 27 February 2021 |
| CVE-2021-25281 | Thus, an attacker can remotely run any wheel modules on the master. | CRITICAL 9.8EPSS 73.1% | 27 February 2021 |
| CVE-2021-27198 | Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. | CRITICAL 9.8EPSS 13.6% | 26 February 2021 |
| CVE-2020-27223 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS)… | MEDIUM 5.3EPSS 78.0% | 26 February 2021 |
| CVE-2021-26701 | .NET Core Remote Code Execution Vulnerability | HIGH 8.1EPSS 30.1% | 25 February 2021 |
| CVE-2021-24094 | Windows TCP/IP Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 22.1% | 25 February 2021 |
| CVE-2021-24093 | Windows Graphics Component Remote Code Execution Vulnerability | HIGH 8.8EPSS 46.1% | 25 February 2021 |
| CVE-2021-24086 | Windows TCP/IP Denial of Service Vulnerability | HIGH 7.5EPSS 59.0% | 25 February 2021 |
| CVE-2021-24078 | Windows DNS Server Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 11.9% | 25 February 2021 |
| CVE-2021-24074 | Windows TCP/IP Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 25.7% | 25 February 2021 |
| CVE-2021-1732 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 78.4% | 25 February 2021 |
| CVE-2021-27670 | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. | CRITICAL 9.8EPSS 61.3% | 25 February 2021 |
| CVE-2021-1388 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. | CRITICAL 10.0EPSS 14.8% | 24 February 2021 |
| CVE-2020-11987 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. | HIGH 8.2EPSS 13.3% | 24 February 2021 |
| CVE-2021-21974 | OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. | HIGH 8.8EPSS 45.1% | 24 February 2021 |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability | KEVMEDIUM 5.3EPSS 87.6% | 24 February 2021 |
| CVE-2021-21972 | VMware vCenter Server Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 24 February 2021 |
| CVE-2021-21618 | Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | MEDIUM 5.4EPSS 81.8% | 24 February 2021 |
| CVE-2021-21616 | Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | MEDIUM 4.6EPSS 78.8% | 24 February 2021 |
| CVE-2021-20660 | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors. | MEDIUM 6.1EPSS 47.2% | 24 February 2021 |
| CVE-2021-3407 | Double free of object during linearization may lead to memory corruption and other potential consequences. | MEDIUM 5.5EPSS 50.2% | 23 February 2021 |
| CVE-2020-16243 | Multiple buffer overflow vulnerabilities exist when LeviStudioU (Version 2019-09-21 and prior) processes project files. | HIGH 7.8EPSS 12.4% | 23 February 2021 |
| CVE-2020-28429 | All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. | CRITICAL 9.8EPSS 63.3% | 23 February 2021 |
| CVE-2020-29453 | The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF… | MEDIUM 5.3EPSS 23.9% | 22 February 2021 |
| CVE-2021-3120 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. | CRITICAL 9.8EPSS 36.8% | 22 February 2021 |
| CVE-2020-21224 | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. | CRITICAL 9.8EPSS 38.7% | 22 February 2021 |
| CVE-2021-26120 | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. | CRITICAL 9.8EPSS 82.3% | 22 February 2021 |
| CVE-2021-27513 | The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside." | HIGH 8.8EPSS 28.4% | 22 February 2021 |
| CVE-2019-25024 | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. | CRITICAL 9.8EPSS 27.6% | 19 February 2021 |
| CVE-2021-26747 | Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. | CRITICAL 9.8EPSS 54.8% | 18 February 2021 |
| CVE-2020-8625 | BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. | HIGH 8.1EPSS 64.2% | 17 February 2021 |
| CVE-2021-27224 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code. | HIGH 7.5EPSS 38.0% | 17 February 2021 |
| CVE-2021-27104 | Accellion FTA OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 56.7% | 16 February 2021 |
| CVE-2021-27103 | Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability | KEVCRITICAL 9.8EPSS 11.4% | 16 February 2021 |
| CVE-2021-23840 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. | HIGH 7.5EPSS 50.7% | 16 February 2021 |
| CVE-2021-21315 | System Information Library for Node.JS Command Injection | KEVHIGH 7.8EPSS 90.7% | 16 February 2021 |
| CVE-2021-3239 | E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell. | CRITICAL 9.8EPSS 18.4% | 15 February 2021 |
| CVE-2020-28337 | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. | HIGH 7.2EPSS 16.6% | 15 February 2021 |
| CVE-2020-24899 | Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. | HIGH 8.8EPSS 16.6% | 15 February 2021 |
| CVE-2020-22427 | NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. | HIGH 7.2EPSS 14.3% | 15 February 2021 |
| CVE-2020-35775 | CITSmart before 9.1.2.23 allows LDAP Injection. | CRITICAL 9.8EPSS 13.3% | 15 February 2021 |
| CVE-2021-25299 | Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). | MEDIUM 6.1EPSS 97.8% | 15 February 2021 |
| CVE-2021-25298 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 75.1% | 15 February 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.