Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,136 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 97 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-15568 | TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. | CRITICAL 9.8EPSS 29.0% | 30 January 2021 |
| CVE-2021-25646 | Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. | HIGH 8.8EPSS 99.0% | 29 January 2021 |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 54.3% | 29 January 2021 |
| CVE-2021-3337 | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit. | HIGH 7.5EPSS 11.5% | 28 January 2021 |
| CVE-2020-35754 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. | HIGH 7.2EPSS 10.5% | 28 January 2021 |
| CVE-2021-22875 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter. | MEDIUM 6.1EPSS 18.2% | 28 January 2021 |
| CVE-2021-22874 | Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter. | MEDIUM 6.1EPSS 18.2% | 28 January 2021 |
| CVE-2020-4888 | IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. | HIGH 8.8EPSS 62.0% | 28 January 2021 |
| CVE-2021-26117 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. | HIGH 7.5EPSS 11.3% | 27 January 2021 |
| CVE-2021-3317 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | HIGH 8.8EPSS 41.4% | 26 January 2021 |
| CVE-2021-3156 | Sudo Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 100.0% | 26 January 2021 |
| CVE-2021-3297 | On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. | HIGH 7.8EPSS 20.5% | 26 January 2021 |
| CVE-2021-3291 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command. | HIGH 7.2EPSS 16.8% | 26 January 2021 |
| CVE-2021-3278 | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . | CRITICAL 9.8EPSS 25.3% | 26 January 2021 |
| CVE-2021-3223 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | HIGH 7.5EPSS 18.5% | 26 January 2021 |
| CVE-2021-22873 | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. | MEDIUM 6.1EPSS 69.6% | 26 January 2021 |
| CVE-2020-36230 | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. | HIGH 7.5EPSS 12.3% | 26 January 2021 |
| CVE-2020-36228 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. | HIGH 7.5EPSS 84.2% | 26 January 2021 |
| CVE-2020-36227 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service. | HIGH 7.5EPSS 77.7% | 26 January 2021 |
| CVE-2020-36222 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | HIGH 7.5EPSS 77.7% | 26 January 2021 |
| CVE-2020-36221 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck). | HIGH 7.5EPSS 84.2% | 26 January 2021 |
| CVE-2020-35576 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577. | HIGH 8.8EPSS 42.3% | 26 January 2021 |
| CVE-2020-23826 | The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. | HIGH 8.8EPSS 12.6% | 26 January 2021 |
| CVE-2020-12513 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. | HIGH 8.8EPSS 31.1% | 22 January 2021 |
| CVE-2020-27858 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. | HIGH 7.5EPSS 73.8% | 20 January 2021 |
| CVE-2020-25687 | A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. | MEDIUM 5.9EPSS 86.7% | 20 January 2021 |
| CVE-2020-25682 | A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. | HIGH 8.1EPSS 70.8% | 20 January 2021 |
| CVE-2020-25681 | A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. | HIGH 8.1EPSS 81.2% | 20 January 2021 |
| CVE-2020-25683 | A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. | MEDIUM 5.9EPSS 86.0% | 20 January 2021 |
| CVE-2021-2114 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). | HIGH 8.2EPSS 59.3% | 20 January 2021 |
| CVE-2021-2109 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). | HIGH 7.2EPSS 70.4% | 20 January 2021 |
| CVE-2021-2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). | MEDIUM 4.9EPSS 10.1% | 20 January 2021 |
| CVE-2020-14756 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). | CRITICAL 9.8EPSS 74.8% | 20 January 2021 |
| CVE-2021-3110 | The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. | CRITICAL 9.8EPSS 18.7% | 20 January 2021 |
| CVE-2020-25385 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page. | MEDIUM 6.1EPSS 16.2% | 20 January 2021 |
| CVE-2020-19364 | OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. | HIGH 8.8EPSS 70.6% | 20 January 2021 |
| CVE-2020-19360 | Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure. | HIGH 7.5EPSS 17.3% | 20 January 2021 |
| CVE-2020-23342 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. | HIGH 8.8EPSS 12.4% | 19 January 2021 |
| CVE-2021-3177 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to… | CRITICAL 9.8EPSS 23.3% | 19 January 2021 |
| CVE-2020-36193 | PEAR Archive_Tar Improper Link Resolution Vulnerability | KEVHIGH 7.5EPSS 70.6% | 18 January 2021 |
| CVE-2021-25294 | OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. | CRITICAL 9.8EPSS 10.7% | 18 January 2021 |
| CVE-2021-21251 | In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. | HIGH 8.8EPSS 12.7% | 15 January 2021 |
| CVE-2021-21246 | However for the `/users/{id}` endpoint there are no security checks enforced so it is possible to retrieve arbitrary user details including their Access Tokens! | HIGH 7.5EPSS 49.1% | 15 January 2021 |
| CVE-2021-21242 | In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. | CRITICAL 9.8EPSS 74.2% | 15 January 2021 |
| CVE-2021-21243 | In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. | CRITICAL 9.8EPSS 54.5% | 15 January 2021 |
| CVE-2020-35749 | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php. | HIGH 7.7EPSS 30.5% | 15 January 2021 |
| CVE-2020-6572 | Google Chrome Media Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 10.6% | 14 January 2021 |
| CVE-2021-24122 | When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. | MEDIUM 5.9EPSS 22.9% | 14 January 2021 |
| CVE-2020-27265 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66,… | CRITICAL 9.8EPSS 10.1% | 14 January 2021 |
| CVE-2020-35578 | Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands. | HIGH 7.2EPSS 81.9% | 13 January 2021 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.