VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1123 of 1178 · EPSS data 2026.08.05
ReviewHigh
CVE-2020-28873

fluxbb

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2021-21193

Google Chromium Blink

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2021-27085

Microsoft Internet Explorer

CVE-2021-27085 affects Microsoft Internet Explorer. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVMedium
CVE-2021-27059

Microsoft Office

CVE-2021-27059 affects Microsoft Office. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2021-26411

Microsoft Internet Explorer

CVE-2021-26411 affects Microsoft Internet Explorer. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
PriorityHigh
CVE-2020-29238

expressvpn

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

FIRST EPSS indicates an elevated probability of exploitation.
CISA KEVHigh
CVE-2021-21166

Google Chromium

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2020-27575

rumpus

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to command injection due to insufficient validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-27574

rumpus

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the authenticated user.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-27365

cloud backup, linux kernel

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-27364

cloud backup, linux kernel

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2021-25337

Samsung Mobile Devices

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewCritical
CVE-2020-24914

qcubed

A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable "strProfileData" and allows an unauthenticated attacker to execute code via a crafted POST request.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2020-24913

qcubed

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2020-24036

fork cms

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

The CVSS severity warrants an early asset and exposure review.