SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,662 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 37 of 501

CVESummaryPriorityPublished
CVE-2019-19743On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.EXPLOITMEDIUM 6.5EPSS 8.87%16 December 2019
CVE-2019-19731Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal.EXPLOITHIGH 7.5EPSS 11.6%16 December 2019
CVE-2019-19368A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1.EXPLOITMEDIUM 6.1EPSS 25.9%16 December 2019
CVE-2019-19774By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5…EXPLOITHIGH 8.8EPSS 12.5%13 December 2019
CVE-2019-19740Octeth Oempro 4.7 and 4.8 allow SQL injection.EXPLOITCRITICAL 9.8EPSS 5.76%12 December 2019
CVE-2019-19726OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit.EXPLOIT ×2HIGH 7.8EPSS 3.52%12 December 2019
CVE-2019-7004A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information.EXPLOITMEDIUM 5.4EPSS 2.18%12 December 2019
CVE-2013-5978Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a…EXPLOITMEDIUM 6.1EPSS 4.08%11 December 2019
CVE-2013-5743Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.EXPLOITCRITICAL 9.8EPSS 80.0%11 December 2019
CVE-2013-3691AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.EXPLOITHIGH 7.5EPSS 3.90%11 December 2019
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.7%11 December 2019
CVE-2019-1476An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 5.12%10 December 2019
CVE-2019-1458Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 74.3%10 December 2019
CVE-2019-6192A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.EXPLOITMEDIUM 4.4EPSS 1.74%10 December 2019
CVE-2015-7892Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.EXPLOITHIGH 7.8EPSS 1.35%9 December 2019
CVE-2014-0242mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.EXPLOITHIGH 7.5EPSS 8.53%9 December 2019
CVE-2012-1592A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.EXPLOITHIGH 8.8EPSS 28.5%5 December 2019
CVE-2019-19609The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be…EXPLOITHIGH 7.2EPSS 54.1%5 December 2019
CVE-2019-19576class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.EXPLOITCRITICAL 9.8EPSS 26.4%4 December 2019
CVE-2019-17554The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities.EXPLOITMEDIUM 5.5EPSS 12.2%4 December 2019
CVE-2019-19516Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.EXPLOITMEDIUM 6.5EPSS 9.63%2 December 2019
CVE-2019-12518Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 50.7%2 December 2019
CVE-2019-19245NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.EXPLOITCRITICAL 9.8EPSS 7.94%2 December 2019
CVE-2019-19493Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.EXPLOITMEDIUM 5.4EPSS 2.02%2 December 2019
CVE-2011-2523vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.EXPLOIT ×2CRITICAL 9.8EPSS 96.2%27 November 2019
CVE-2017-12945Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.EXPLOITHIGH 8.8EPSS 17.4%27 November 2019
CVE-2011-1939SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.EXPLOITCRITICAL 9.8EPSS 3.86%26 November 2019
CVE-2011-4090Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.EXPLOITMEDIUM 6.1EPSS 3.40%26 November 2019
CVE-2019-15276A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.EXPLOITMEDIUM 6.5EPSS 46.3%26 November 2019
CVE-2011-3596Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.EXPLOITHIGH 7.5EPSS 11.1%26 November 2019
CVE-2019-5825Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVEXPLOITMEDIUM 6.5EPSS 55.9%25 November 2019
CVE-2019-13720Google Chrome WebAudio Use-After-Free VulnerabilityKEVEXPLOITHIGH 8.8EPSS 73.0%25 November 2019
CVE-2013-6234Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an…EXPLOITHIGH 8.0EPSS 6.71%22 November 2019
CVE-2015-3140Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567EXPLOIT ×3HIGH 8.8EPSS 1.29%21 November 2019
CVE-2014-8356The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.EXPLOITHIGH 8.8EPSS 5.64%21 November 2019
CVE-2012-1001Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.EXPLOIT ×2MEDIUM 6.1EPSS 3.56%21 November 2019
CVE-2013-3314The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.EXPLOITHIGH 7.5EPSS 7.08%21 November 2019
CVE-2019-16758In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.EXPLOITHIGH 7.5EPSS 16.8%21 November 2019
CVE-2019-16405Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings.EXPLOITHIGH 7.2EPSS 27.0%21 November 2019
CVE-2012-1257Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.EXPLOITMEDIUM 5.5EPSS 0.74%20 November 2019
CVE-2011-2921ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.EXPLOITCRITICAL 9.8EPSS 83.1%19 November 2019
CVE-2011-1930This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.EXPLOITCRITICAL 9.8EPSS 20.5%14 November 2019
CVE-2019-5029An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1.EXPLOITCRITICAL 9.8EPSS 57.1%13 November 2019
CVE-2019-18951SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.EXPLOITHIGH 7.5EPSS 19.8%13 November 2019
CVE-2014-1214views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.EXPLOITHIGH 8.8EPSS 4.32%13 November 2019
CVE-2012-5193Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to…EXPLOITMEDIUM 6.1EPSS 1.79%13 November 2019
CVE-2012-4385letodms 3.3.6 has CSRF via change passwordEXPLOITMEDIUM 6.5EPSS 1.56%13 November 2019
CVE-2012-4384letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in CalendarEXPLOITMEDIUM 6.1EPSS 1.55%13 November 2019
CVE-2019-1429Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.5EPSS 77.3%12 November 2019
CVE-2019-1405Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 29.9%12 November 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.