SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 96 of 348

CVESummaryPriorityPublished
CVE-2021-27147The web daemon contains the hardcoded admin / admin credentials for an ISP.CRITICAL 9.8EPSS 17.1%10 February 2021
CVE-2021-27146The web daemon contains the hardcoded admin / CUadmin credentials for an ISP.CRITICAL 9.8EPSS 20.3%10 February 2021
CVE-2021-27145The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.CRITICAL 9.8EPSS 23.6%10 February 2021
CVE-2021-27144The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.CRITICAL 9.8EPSS 21.9%10 February 2021
CVE-2021-27143The web daemon contains the hardcoded user / user1234 credentials for an ISP.CRITICAL 9.8EPSS 16.0%10 February 2021
CVE-2021-27142The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.HIGH 7.5EPSS 15.7%10 February 2021
CVE-2021-27141Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key.CRITICAL 9.8EPSS 15.8%10 February 2021
CVE-2021-27140An issue was discovered on FiberHome HG6245D devices through RP2613.HIGH 7.5EPSS 18.9%10 February 2021
CVE-2021-27139An issue was discovered on FiberHome HG6245D devices through RP2613.HIGH 7.5EPSS 16.2%10 February 2021
CVE-2020-28871Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.CRITICAL 9.8EPSS 85.8%10 February 2021
CVE-2021-21479In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.CRITICAL 9.1EPSS 10.1%9 February 2021
CVE-2021-21477SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed…CRITICAL 9.9EPSS 29.8%9 February 2021
CVE-2020-13117Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.CRITICAL 9.8EPSS 68.6%9 February 2021
CVE-2021-25140A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20.CRITICAL 9.8EPSS 12.0%9 February 2021
CVE-2020-25237A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2).HIGH 8.1EPSS 20.6%9 February 2021
CVE-2021-21148Google Chromium V8 Heap Buffer Overflow VulnerabilityKEVHIGH 8.8EPSS 20.0%9 February 2021
CVE-2021-21135Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.MEDIUM 6.5EPSS 19.2%9 February 2021
CVE-2021-21132Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.CRITICAL 9.6EPSS 23.4%9 February 2021
CVE-2021-21123Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.MEDIUM 6.5EPSS 10.9%9 February 2021
CVE-2021-21118Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.HIGH 8.8EPSS 16.8%9 February 2021
CVE-2020-22840Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.MEDIUM 6.1EPSS 13.8%9 February 2021
CVE-2021-26915NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.HIGH 8.1EPSS 41.8%8 February 2021
CVE-2021-26914NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.HIGH 8.1EPSS 77.7%8 February 2021
CVE-2021-26913NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.HIGH 8.1EPSS 13.3%8 February 2021
CVE-2021-26912NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.HIGH 8.1EPSS 41.0%8 February 2021
CVE-2021-22502Micro Focus Operation Bridge Report (OBR) Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 96.7%8 February 2021
CVE-2020-13947An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.MEDIUM 6.1EPSS 79.0%8 February 2021
CVE-2021-21305In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability.HIGH 8.8EPSS 12.7%8 February 2021
CVE-2021-22122An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting…MEDIUM 6.1EPSS 10.5%8 February 2021
CVE-2021-3293emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.MEDIUM 5.3EPSS 19.9%8 February 2021
CVE-2021-3122CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as…CRITICAL 9.8EPSS 87.3%7 February 2021
CVE-2020-36243The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php.HIGH 8.8EPSS 64.1%7 February 2021
CVE-2021-26723Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.MEDIUM 6.1EPSS 12.6%6 February 2021
CVE-2020-35765doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.HIGH 8.8EPSS 27.3%5 February 2021
CVE-2020-13580An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application.HIGH 7.8EPSS 70.7%4 February 2021
CVE-2020-13579An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application.HIGH 7.8EPSS 70.7%4 February 2021
CVE-2021-20016SonicWall SSLVPN SMA100 SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 40.0%4 February 2021
CVE-2021-3401Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler for a .desktop…CRITICAL 9.8EPSS 10.5%4 February 2021
CVE-2021-26024The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.MEDIUM 5.3EPSS 19.0%3 February 2021
CVE-2021-26023The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.MEDIUM 6.1EPSS 25.2%3 February 2021
CVE-2021-25274As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process.CRITICAL 9.8EPSS 36.4%3 February 2021
CVE-2020-17523Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.CRITICAL 9.8EPSS 85.9%3 February 2021
CVE-2020-28653Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.CRITICAL 9.8EPSS 78.7%3 February 2021
CVE-2020-18568The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.CRITICAL 9.8EPSS 14.6%2 February 2021
CVE-2020-25506D-Link DNS-320 Device Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%2 February 2021
CVE-2021-3378FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.CRITICAL 9.8EPSS 97.5%1 February 2021
CVE-2021-21287In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability.HIGH 7.7EPSS 24.8%1 February 2021
CVE-2020-13564A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.MEDIUM 6.1EPSS 75.9%1 February 2021
CVE-2020-13563A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.MEDIUM 6.1EPSS 75.9%1 February 2021
CVE-2020-13562A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7.MEDIUM 6.1EPSS 77.7%1 February 2021

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.