SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 36 of 501

CVESummaryPriorityPublished
CVE-2014-3136Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev.EXPLOITHIGH 8.8EPSS 2.89%27 December 2019
CVE-2013-4985Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video streamEXPLOITHIGH 7.5EPSS 8.97%27 December 2019
CVE-2013-4982AVTECH AVN801 DVR has a security bypass via the administration login captchaEXPLOITCRITICAL 9.8EPSS 13.1%27 December 2019
CVE-2013-4976Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentialsEXPLOITCRITICAL 9.8EPSS 36.1%27 December 2019
CVE-2013-4975Hikvision DS-2CD7153-E IP Camera has Privilege EscalationEXPLOITHIGH 8.8EPSS 12.3%27 December 2019
CVE-2013-4868Karotz API 12.07.19.00: Session Token Information DisclosureEXPLOITMEDIUM 5.3EPSS 4.96%27 December 2019
CVE-2013-4867Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijackingEXPLOITMEDIUM 6.3EPSS 1.56%27 December 2019
CVE-2013-4859INSTEON Hub 2242-222 lacks Web and API authenticationEXPLOITHIGH 8.1EPSS 6.97%27 December 2019
CVE-2013-4743Static HTTP Server 1.0 has a Local OverflowEXPLOITCRITICAL 9.8EPSS 8.40%27 December 2019
CVE-2013-4692Xorbin Analog Flash Clock 1.0 extension for Joomia has XSSEXPLOIT ×2MEDIUM 6.1EPSS 2.45%27 December 2019
CVE-2013-4695Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code ExecutionEXPLOITHIGH 7.8EPSS 5.28%27 December 2019
CVE-2013-4665SPBAS Business Automation Software 2012 has CSRF.EXPLOITMEDIUM 6.5EPSS 1.33%27 December 2019
CVE-2013-4664SPBAS Business Automation Software 2012 has XSS.EXPLOITMEDIUM 6.1EPSS 2.22%27 December 2019
CVE-2019-19781Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution VulnerabilityKEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0%27 December 2019
CVE-2019-19985The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.EXPLOITMEDIUM 5.3EPSS 71.4%26 December 2019
CVE-2019-16451Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 34.7%19 December 2019
CVE-2019-19844Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.EXPLOITCRITICAL 9.8EPSS 53.6%18 December 2019
CVE-2019-8820Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 9.54%18 December 2019
CVE-2019-8765Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 6.93%18 December 2019
CVE-2019-8717A memory corruption issue was addressed with improved memory handling.EXPLOITHIGH 7.8EPSS 1.29%18 December 2019
CVE-2019-8690Processing maliciously crafted web content may lead to universal cross site scripting.EXPLOITMEDIUM 6.1EPSS 4.54%18 December 2019
CVE-2019-8689Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 12.9%18 December 2019
CVE-2019-8672Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 11.0%18 December 2019
CVE-2019-8671Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 7.71%18 December 2019
CVE-2019-8663A remote attacker may be able to leak memory.EXPLOITMEDIUM 5.3EPSS 6.69%18 December 2019
CVE-2019-8662An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.EXPLOIT ×2CRITICAL 9.8EPSS 9.78%18 December 2019
CVE-2019-8661A use after free issue was addressed with improved memory management.EXPLOITCRITICAL 9.8EPSS 10.3%18 December 2019
CVE-2019-8660A memory corruption issue was addressed with improved input validation.EXPLOITCRITICAL 9.8EPSS 13.8%18 December 2019
CVE-2019-8649Processing maliciously crafted web content may lead to universal cross site scripting.EXPLOITMEDIUM 6.1EPSS 4.54%18 December 2019
CVE-2019-8647A use after free issue was addressed with improved memory management.EXPLOITCRITICAL 9.8EPSS 13.5%18 December 2019
CVE-2019-8646An out-of-bounds read was addressed with improved input validation.EXPLOITHIGH 7.5EPSS 11.0%18 December 2019
CVE-2019-8641An out-of-bounds read was addressed with improved input validation.EXPLOIT ×2CRITICAL 9.8EPSS 17.0%18 December 2019
CVE-2019-8624An out-of-bounds read was addressed with improved input validation.EXPLOITHIGH 7.5EPSS 6.90%18 December 2019
CVE-2019-8623Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 8.29%18 December 2019
CVE-2019-8622Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 8.29%18 December 2019
CVE-2019-8613A use after free issue was addressed with improved memory management.EXPLOITCRITICAL 9.8EPSS 13.3%18 December 2019
CVE-2019-8611Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 7.71%18 December 2019
CVE-2019-8605Apple Multiple Products Use-After-Free VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 17.5%18 December 2019
CVE-2019-8591A type confusion issue was addressed with improved memory handling.EXPLOITHIGH 7.1EPSS 4.44%18 December 2019
CVE-2019-8565A race condition was addressed with additional validation.EXPLOITHIGH 7.0EPSS 13.5%18 December 2019
CVE-2019-8558Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 7.54%18 December 2019
CVE-2019-8518Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 10.5%18 December 2019
CVE-2019-8514A logic issue was addressed with improved state management.EXPLOITHIGH 7.8EPSS 3.10%18 December 2019
CVE-2019-8513A local user may be able to execute arbitrary shell commands.EXPLOITHIGH 7.8EPSS 2.92%18 December 2019
CVE-2019-8506Apple Multiple Products Type Confusion VulnerabilityKEVEXPLOITHIGH 8.8EPSS 18.1%18 December 2019
CVE-2019-7286Apple Multiple Products Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.8EPSS 15.6%18 December 2019
CVE-2019-4716IBM Planning Analytics Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 86.4%18 December 2019
CVE-2019-19742On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.EXPLOITMEDIUM 4.8EPSS 19.8%18 December 2019
CVE-2019-19241For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface.EXPLOITHIGH 7.8EPSS 1.09%17 December 2019
CVE-2012-2237Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,…EXPLOITMEDIUM 6.1EPSS 2.87%17 December 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.