SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 95 of 348

CVESummaryPriorityPublished
CVE-2021-25297Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 56.7%15 February 2021
CVE-2021-25296Nagios XI OS Command InjectionKEVHIGH 8.8EPSS 72.2%15 February 2021
CVE-2021-23337Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.HIGH 7.2EPSS 21.3%15 February 2021
CVE-2021-23336The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector…MEDIUM 5.9EPSS 36.0%15 February 2021
CVE-2021-27212In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp.HIGH 7.5EPSS 64.1%14 February 2021
CVE-2020-27868This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395.CRITICAL 9.8EPSS 81.8%12 February 2021
CVE-2020-27864This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders.HIGH 8.8EPSS 10.1%12 February 2021
CVE-2021-21311Adminer Server-Side Request Forgery VulnerabilityKEVHIGH 7.2EPSS 90.5%11 February 2021
CVE-2021-21042Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack.MEDIUM 6.5EPSS 14.7%11 February 2021
CVE-2021-21029Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter.MEDIUM 4.8EPSS 84.6%11 February 2021
CVE-2021-21017Adobe Acrobat and Reader Heap-based Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 86.3%11 February 2021
CVE-2021-21307Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development.CRITICAL 9.8EPSS 89.2%11 February 2021
CVE-2021-22881The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability.MEDIUM 6.1EPSS 87.3%11 February 2021
CVE-2021-22658Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.CRITICAL 9.8EPSS 12.7%11 February 2021
CVE-2021-22654Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.HIGH 7.5EPSS 12.2%11 February 2021
CVE-2021-22652Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution.CRITICAL 9.8EPSS 36.8%11 February 2021
CVE-2020-27871This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1.HIGH 7.2EPSS 90.8%10 February 2021
CVE-2020-13548In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution.HIGH 8.8EPSS 65.8%10 February 2021
CVE-2021-27179It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string.HIGH 7.5EPSS 13.9%10 February 2021
CVE-2021-27178An issue was discovered on FiberHome HG6245D devices through RP2613.HIGH 7.5EPSS 18.2%10 February 2021
CVE-2021-27177It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server.CRITICAL 9.8EPSS 19.7%10 February 2021
CVE-2021-27176An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.HIGH 7.5EPSS 18.7%10 February 2021
CVE-2021-27175An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.HIGH 7.5EPSS 18.2%10 February 2021
CVE-2021-27174An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.HIGH 7.5EPSS 18.7%10 February 2021
CVE-2021-27173This will remove firewall rules and allow an attacker to reach the telnet server (used for the CLI).HIGH 7.5EPSS 12.7%10 February 2021
CVE-2021-27172A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.CRITICAL 9.8EPSS 19.8%10 February 2021
CVE-2021-27171An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 17.8%10 February 2021
CVE-2021-27170By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet.CRITICAL 9.8EPSS 15.9%10 February 2021
CVE-2021-27169An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631.CRITICAL 9.8EPSS 19.8%10 February 2021
CVE-2021-27168An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 19.8%10 February 2021
CVE-2021-27167An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 14.6%10 February 2021
CVE-2021-27166An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 19.8%10 February 2021
CVE-2021-27165An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 19.8%10 February 2021
CVE-2021-27164The web daemon contains the hardcoded admin / aisadmin credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27163The web daemon contains the hardcoded admin / tele1234 credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27162The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.CRITICAL 9.8EPSS 26.8%10 February 2021
CVE-2021-27161The web daemon contains the hardcoded admin / 1234 credentials for an ISP.CRITICAL 9.8EPSS 17.1%10 February 2021
CVE-2021-27160The web daemon contains the hardcoded user / 888888 credentials for an ISP.CRITICAL 9.8EPSS 17.1%10 February 2021
CVE-2021-27159The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27158The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27157The web daemon contains the hardcoded admin / 888888 credentials for an ISP.CRITICAL 9.8EPSS 15.0%10 February 2021
CVE-2021-27156An issue was discovered on FiberHome HG6245D devices through RP2613.CRITICAL 9.8EPSS 15.0%10 February 2021
CVE-2021-27155The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP.CRITICAL 9.8EPSS 20.3%10 February 2021
CVE-2021-27154The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP.CRITICAL 9.8EPSS 20.3%10 February 2021
CVE-2021-27153The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP.CRITICAL 9.8EPSS 20.3%10 February 2021
CVE-2021-27152The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27151The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27150The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.CRITICAL 9.8EPSS 20.3%10 February 2021
CVE-2021-27149The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27148The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.