Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 95 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-25297 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 56.7% | 15 February 2021 |
| CVE-2021-25296 | Nagios XI OS Command Injection | KEVHIGH 8.8EPSS 72.2% | 15 February 2021 |
| CVE-2021-23337 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | HIGH 7.2EPSS 21.3% | 15 February 2021 |
| CVE-2021-23336 | The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector… | MEDIUM 5.9EPSS 36.0% | 15 February 2021 |
| CVE-2021-27212 | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. | HIGH 7.5EPSS 64.1% | 14 February 2021 |
| CVE-2020-27868 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. | CRITICAL 9.8EPSS 81.8% | 12 February 2021 |
| CVE-2020-27864 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. | HIGH 8.8EPSS 10.1% | 12 February 2021 |
| CVE-2021-21311 | Adminer Server-Side Request Forgery Vulnerability | KEVHIGH 7.2EPSS 90.5% | 11 February 2021 |
| CVE-2021-21042 | Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack. | MEDIUM 6.5EPSS 14.7% | 11 February 2021 |
| CVE-2021-21029 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-site Scripting vulnerability via 'file' parameter. | MEDIUM 4.8EPSS 84.6% | 11 February 2021 |
| CVE-2021-21017 | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 86.3% | 11 February 2021 |
| CVE-2021-21307 | Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. | CRITICAL 9.8EPSS 89.2% | 11 February 2021 |
| CVE-2021-22881 | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. | MEDIUM 6.1EPSS 87.3% | 11 February 2021 |
| CVE-2021-22658 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. | CRITICAL 9.8EPSS 12.7% | 11 February 2021 |
| CVE-2021-22654 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information. | HIGH 7.5EPSS 12.2% | 11 February 2021 |
| CVE-2021-22652 | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized attacker to change the configuration and obtain code execution. | CRITICAL 9.8EPSS 36.8% | 11 February 2021 |
| CVE-2020-27871 | This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. | HIGH 7.2EPSS 90.8% | 10 February 2021 |
| CVE-2020-13548 | In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. | HIGH 8.8EPSS 65.8% | 10 February 2021 |
| CVE-2021-27179 | It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string. | HIGH 7.5EPSS 13.9% | 10 February 2021 |
| CVE-2021-27178 | An issue was discovered on FiberHome HG6245D devices through RP2613. | HIGH 7.5EPSS 18.2% | 10 February 2021 |
| CVE-2021-27177 | It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server. | CRITICAL 9.8EPSS 19.7% | 10 February 2021 |
| CVE-2021-27176 | An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions. | HIGH 7.5EPSS 18.7% | 10 February 2021 |
| CVE-2021-27175 | An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions. | HIGH 7.5EPSS 18.2% | 10 February 2021 |
| CVE-2021-27174 | An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions. | HIGH 7.5EPSS 18.7% | 10 February 2021 |
| CVE-2021-27173 | This will remove firewall rules and allow an attacker to reach the telnet server (used for the CLI). | HIGH 7.5EPSS 12.7% | 10 February 2021 |
| CVE-2021-27172 | A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh. | CRITICAL 9.8EPSS 19.8% | 10 February 2021 |
| CVE-2021-27171 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 17.8% | 10 February 2021 |
| CVE-2021-27170 | By default, there are no firewall rules for IPv6 connectivity, exposing the internal management interfaces to the Internet. | CRITICAL 9.8EPSS 15.9% | 10 February 2021 |
| CVE-2021-27169 | An issue was discovered on FiberHome AN5506-04-FA devices with firmware RP2631. | CRITICAL 9.8EPSS 19.8% | 10 February 2021 |
| CVE-2021-27168 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 19.8% | 10 February 2021 |
| CVE-2021-27167 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 14.6% | 10 February 2021 |
| CVE-2021-27166 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 19.8% | 10 February 2021 |
| CVE-2021-27165 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 19.8% | 10 February 2021 |
| CVE-2021-27164 | The web daemon contains the hardcoded admin / aisadmin credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27163 | The web daemon contains the hardcoded admin / tele1234 credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27162 | The web daemon contains the hardcoded user / tattoo@home credentials for an ISP. | CRITICAL 9.8EPSS 26.8% | 10 February 2021 |
| CVE-2021-27161 | The web daemon contains the hardcoded admin / 1234 credentials for an ISP. | CRITICAL 9.8EPSS 17.1% | 10 February 2021 |
| CVE-2021-27160 | The web daemon contains the hardcoded user / 888888 credentials for an ISP. | CRITICAL 9.8EPSS 17.1% | 10 February 2021 |
| CVE-2021-27159 | The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27158 | The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27157 | The web daemon contains the hardcoded admin / 888888 credentials for an ISP. | CRITICAL 9.8EPSS 15.0% | 10 February 2021 |
| CVE-2021-27156 | An issue was discovered on FiberHome HG6245D devices through RP2613. | CRITICAL 9.8EPSS 15.0% | 10 February 2021 |
| CVE-2021-27155 | The web daemon contains the hardcoded admin / 3UJUh2VemEfUtesEchEC2d2e credentials for an ISP. | CRITICAL 9.8EPSS 20.3% | 10 February 2021 |
| CVE-2021-27154 | The web daemon contains the hardcoded admin / G0R2U1P2ag credentials for an ISP. | CRITICAL 9.8EPSS 20.3% | 10 February 2021 |
| CVE-2021-27153 | The web daemon contains the hardcoded trueadmin / admintrue credentials for an ISP. | CRITICAL 9.8EPSS 20.3% | 10 February 2021 |
| CVE-2021-27152 | The web daemon contains the hardcoded awnfibre / fibre@dm!n credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27151 | The web daemon contains the hardcoded rootmet / m3tr0r00t credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27150 | The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP. | CRITICAL 9.8EPSS 20.3% | 10 February 2021 |
| CVE-2021-27149 | The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27148 | The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.