Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,992 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 96 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2021-27147 | The web daemon contains the hardcoded admin / admin credentials for an ISP. | CRITICAL 9.8EPSS 17.1% | 10 February 2021 |
| CVE-2021-27146 | The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. | CRITICAL 9.8EPSS 20.3% | 10 February 2021 |
| CVE-2021-27145 | The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | CRITICAL 9.8EPSS 23.6% | 10 February 2021 |
| CVE-2021-27144 | The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP. | CRITICAL 9.8EPSS 21.9% | 10 February 2021 |
| CVE-2021-27143 | The web daemon contains the hardcoded user / user1234 credentials for an ISP. | CRITICAL 9.8EPSS 16.0% | 10 February 2021 |
| CVE-2021-27142 | The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions. | HIGH 7.5EPSS 15.7% | 10 February 2021 |
| CVE-2021-27141 | Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. | CRITICAL 9.8EPSS 15.8% | 10 February 2021 |
| CVE-2021-27140 | An issue was discovered on FiberHome HG6245D devices through RP2613. | HIGH 7.5EPSS 18.9% | 10 February 2021 |
| CVE-2021-27139 | An issue was discovered on FiberHome HG6245D devices through RP2613. | HIGH 7.5EPSS 16.2% | 10 February 2021 |
| CVE-2020-28871 | Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload. | CRITICAL 9.8EPSS 85.8% | 10 February 2021 |
| CVE-2021-21479 | In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system. | CRITICAL 9.1EPSS 10.1% | 9 February 2021 |
| CVE-2021-21477 | SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed… | CRITICAL 9.9EPSS 29.8% | 9 February 2021 |
| CVE-2020-13117 | Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request. | CRITICAL 9.8EPSS 68.6% | 9 February 2021 |
| CVE-2021-25140 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. | CRITICAL 9.8EPSS 12.0% | 9 February 2021 |
| CVE-2020-25237 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). | HIGH 8.1EPSS 20.6% | 9 February 2021 |
| CVE-2021-21148 | Google Chromium V8 Heap Buffer Overflow Vulnerability | KEVHIGH 8.8EPSS 20.0% | 9 February 2021 |
| CVE-2021-21135 | Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | MEDIUM 6.5EPSS 19.2% | 9 February 2021 |
| CVE-2021-21132 | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. | CRITICAL 9.6EPSS 23.4% | 9 February 2021 |
| CVE-2021-21123 | Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | MEDIUM 6.5EPSS 10.9% | 9 February 2021 |
| CVE-2021-21118 | Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | HIGH 8.8EPSS 16.8% | 9 February 2021 |
| CVE-2020-22840 | Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php. | MEDIUM 6.1EPSS 13.8% | 9 February 2021 |
| CVE-2021-26915 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet. | HIGH 8.1EPSS 41.8% | 8 February 2021 |
| CVE-2021-26914 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject. | HIGH 8.1EPSS 77.7% | 8 February 2021 |
| CVE-2021-26913 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet. | HIGH 8.1EPSS 13.3% | 8 February 2021 |
| CVE-2021-26912 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet. | HIGH 8.1EPSS 41.0% | 8 February 2021 |
| CVE-2021-22502 | Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 96.7% | 8 February 2021 |
| CVE-2020-13947 | An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. | MEDIUM 6.1EPSS 79.0% | 8 February 2021 |
| CVE-2021-21305 | In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. | HIGH 8.8EPSS 12.7% | 8 February 2021 |
| CVE-2021-22122 | An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting… | MEDIUM 6.1EPSS 10.5% | 8 February 2021 |
| CVE-2021-3293 | emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file. | MEDIUM 5.3EPSS 19.9% | 8 February 2021 |
| CVE-2021-3122 | CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as… | CRITICAL 9.8EPSS 87.3% | 7 February 2021 |
| CVE-2020-36243 | The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. | HIGH 8.8EPSS 64.1% | 7 February 2021 |
| CVE-2021-26723 | Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS. | MEDIUM 6.1EPSS 12.6% | 6 February 2021 |
| CVE-2020-35765 | doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do. | HIGH 8.8EPSS 27.3% | 5 February 2021 |
| CVE-2020-13580 | An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. | HIGH 7.8EPSS 70.7% | 4 February 2021 |
| CVE-2020-13579 | An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. | HIGH 7.8EPSS 70.7% | 4 February 2021 |
| CVE-2021-20016 | SonicWall SSLVPN SMA100 SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 40.0% | 4 February 2021 |
| CVE-2021-3401 | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler for a .desktop… | CRITICAL 9.8EPSS 10.5% | 4 February 2021 |
| CVE-2021-26024 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account. | MEDIUM 5.3EPSS 19.0% | 3 February 2021 |
| CVE-2021-26023 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. | MEDIUM 6.1EPSS 25.2% | 3 February 2021 |
| CVE-2021-25274 | As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. | CRITICAL 9.8EPSS 36.4% | 3 February 2021 |
| CVE-2020-17523 | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | CRITICAL 9.8EPSS 85.9% | 3 February 2021 |
| CVE-2020-28653 | Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet. | CRITICAL 9.8EPSS 78.7% | 3 February 2021 |
| CVE-2020-18568 | The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution. | CRITICAL 9.8EPSS 14.6% | 2 February 2021 |
| CVE-2020-25506 | D-Link DNS-320 Device Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 2 February 2021 |
| CVE-2021-3378 | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp. | CRITICAL 9.8EPSS 97.5% | 1 February 2021 |
| CVE-2021-21287 | In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. | HIGH 7.7EPSS 24.8% | 1 February 2021 |
| CVE-2020-13564 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. | MEDIUM 6.1EPSS 75.9% | 1 February 2021 |
| CVE-2020-13563 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. | MEDIUM 6.1EPSS 75.9% | 1 February 2021 |
| CVE-2020-13562 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. | MEDIUM 6.1EPSS 77.7% | 1 February 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.