Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 36 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2014-3136 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. | EXPLOITHIGH 8.8EPSS 2.89% | 27 December 2019 |
| CVE-2013-4985 | Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream | EXPLOIT ✓HIGH 7.5EPSS 8.97% | 27 December 2019 |
| CVE-2013-4982 | AVTECH AVN801 DVR has a security bypass via the administration login captcha | EXPLOIT ✓CRITICAL 9.8EPSS 13.1% | 27 December 2019 |
| CVE-2013-4976 | Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials | EXPLOIT ✓CRITICAL 9.8EPSS 36.1% | 27 December 2019 |
| CVE-2013-4975 | Hikvision DS-2CD7153-E IP Camera has Privilege Escalation | EXPLOIT ✓HIGH 8.8EPSS 12.3% | 27 December 2019 |
| CVE-2013-4868 | Karotz API 12.07.19.00: Session Token Information Disclosure | EXPLOIT ✓MEDIUM 5.3EPSS 4.96% | 27 December 2019 |
| CVE-2013-4867 | Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking | EXPLOIT ✓MEDIUM 6.3EPSS 1.56% | 27 December 2019 |
| CVE-2013-4859 | INSTEON Hub 2242-222 lacks Web and API authentication | EXPLOIT ✓HIGH 8.1EPSS 6.97% | 27 December 2019 |
| CVE-2013-4743 | Static HTTP Server 1.0 has a Local Overflow | EXPLOITCRITICAL 9.8EPSS 8.40% | 27 December 2019 |
| CVE-2013-4692 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | EXPLOIT ×2 ✓MEDIUM 6.1EPSS 2.45% | 27 December 2019 |
| CVE-2013-4695 | Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution | EXPLOITHIGH 7.8EPSS 5.28% | 27 December 2019 |
| CVE-2013-4665 | SPBAS Business Automation Software 2012 has CSRF. | EXPLOITMEDIUM 6.5EPSS 1.33% | 27 December 2019 |
| CVE-2013-4664 | SPBAS Business Automation Software 2012 has XSS. | EXPLOITMEDIUM 6.1EPSS 2.22% | 27 December 2019 |
| CVE-2019-19781 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | KEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0% | 27 December 2019 |
| CVE-2019-19985 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. | EXPLOITMEDIUM 5.3EPSS 71.4% | 26 December 2019 |
| CVE-2019-16451 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 34.7% | 19 December 2019 |
| CVE-2019-19844 | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. | EXPLOIT ✓CRITICAL 9.8EPSS 53.6% | 18 December 2019 |
| CVE-2019-8820 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 9.54% | 18 December 2019 |
| CVE-2019-8765 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 6.93% | 18 December 2019 |
| CVE-2019-8717 | A memory corruption issue was addressed with improved memory handling. | EXPLOIT ✓HIGH 7.8EPSS 1.29% | 18 December 2019 |
| CVE-2019-8690 | Processing maliciously crafted web content may lead to universal cross site scripting. | EXPLOIT ✓MEDIUM 6.1EPSS 4.54% | 18 December 2019 |
| CVE-2019-8689 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 12.9% | 18 December 2019 |
| CVE-2019-8672 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 11.0% | 18 December 2019 |
| CVE-2019-8671 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 7.71% | 18 December 2019 |
| CVE-2019-8663 | A remote attacker may be able to leak memory. | EXPLOIT ✓MEDIUM 5.3EPSS 6.69% | 18 December 2019 |
| CVE-2019-8662 | An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 9.78% | 18 December 2019 |
| CVE-2019-8661 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓CRITICAL 9.8EPSS 10.3% | 18 December 2019 |
| CVE-2019-8660 | A memory corruption issue was addressed with improved input validation. | EXPLOIT ✓CRITICAL 9.8EPSS 13.8% | 18 December 2019 |
| CVE-2019-8649 | Processing maliciously crafted web content may lead to universal cross site scripting. | EXPLOIT ✓MEDIUM 6.1EPSS 4.54% | 18 December 2019 |
| CVE-2019-8647 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓CRITICAL 9.8EPSS 13.5% | 18 December 2019 |
| CVE-2019-8646 | An out-of-bounds read was addressed with improved input validation. | EXPLOIT ✓HIGH 7.5EPSS 11.0% | 18 December 2019 |
| CVE-2019-8641 | An out-of-bounds read was addressed with improved input validation. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 17.0% | 18 December 2019 |
| CVE-2019-8624 | An out-of-bounds read was addressed with improved input validation. | EXPLOIT ✓HIGH 7.5EPSS 6.90% | 18 December 2019 |
| CVE-2019-8623 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 8.29% | 18 December 2019 |
| CVE-2019-8622 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 8.29% | 18 December 2019 |
| CVE-2019-8613 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓CRITICAL 9.8EPSS 13.3% | 18 December 2019 |
| CVE-2019-8611 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 7.71% | 18 December 2019 |
| CVE-2019-8605 | Apple Multiple Products Use-After-Free Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 17.5% | 18 December 2019 |
| CVE-2019-8591 | A type confusion issue was addressed with improved memory handling. | EXPLOIT ✓HIGH 7.1EPSS 4.44% | 18 December 2019 |
| CVE-2019-8565 | A race condition was addressed with additional validation. | EXPLOIT ✓HIGH 7.0EPSS 13.5% | 18 December 2019 |
| CVE-2019-8558 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 7.54% | 18 December 2019 |
| CVE-2019-8518 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 10.5% | 18 December 2019 |
| CVE-2019-8514 | A logic issue was addressed with improved state management. | EXPLOIT ✓HIGH 7.8EPSS 3.10% | 18 December 2019 |
| CVE-2019-8513 | A local user may be able to execute arbitrary shell commands. | EXPLOIT ✓HIGH 7.8EPSS 2.92% | 18 December 2019 |
| CVE-2019-8506 | Apple Multiple Products Type Confusion Vulnerability | KEVEXPLOIT ✓HIGH 8.8EPSS 18.1% | 18 December 2019 |
| CVE-2019-7286 | Apple Multiple Products Memory Corruption Vulnerability | KEVEXPLOITHIGH 7.8EPSS 15.6% | 18 December 2019 |
| CVE-2019-4716 | IBM Planning Analytics Remote Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 86.4% | 18 December 2019 |
| CVE-2019-19742 | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. | EXPLOITMEDIUM 4.8EPSS 19.8% | 18 December 2019 |
| CVE-2019-19241 | For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. | EXPLOIT ✓HIGH 7.8EPSS 1.09% | 17 December 2019 |
| CVE-2012-2237 | Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,… | EXPLOIT ✓MEDIUM 6.1EPSS 2.87% | 17 December 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.