SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 38 of 501

CVESummaryPriorityPublished
CVE-2019-18873FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header.EXPLOITCRITICAL 9.0EPSS 8.15%12 November 2019
CVE-2019-18862maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.EXPLOITHIGH 7.8EPSS 1.14%11 November 2019
CVE-2019-18818strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.EXPLOIT ×2CRITICAL 9.8EPSS 97.6%7 November 2019
CVE-2014-9014Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a ..EXPLOIT ×2MEDIUM 4.3EPSS 11.6%6 November 2019
CVE-2014-9013The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of…EXPLOIT ×2HIGH 8.8EPSS 46.9%6 November 2019
CVE-2019-10529Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…EXPLOITHIGH 8.1EPSS 1.74%6 November 2019
CVE-2013-5123The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.EXPLOITMEDIUM 5.9EPSS 7.99%5 November 2019
CVE-2019-1978A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering…EXPLOITMEDIUM 5.8EPSS 9.38%5 November 2019
CVE-2013-6275Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.EXPLOITMEDIUM 6.5EPSS 2.07%5 November 2019
CVE-2013-6364Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address bookEXPLOITHIGH 8.8EPSS 2.08%5 November 2019
CVE-2013-2261Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information DisclosureEXPLOITHIGH 7.5EPSS 11.6%4 November 2019
CVE-2013-4103Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user inputEXPLOITCRITICAL 9.8EPSS 6.87%4 November 2019
CVE-2013-2227GLPI 0.83.7 has Local File Inclusion in common.tabs.php.EXPLOITHIGH 7.5EPSS 13.0%1 November 2019
CVE-2011-3923Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.EXPLOITCRITICAL 9.8EPSS 89.5%1 November 2019
CVE-2013-2739MiniDLNA has heap-based buffer overflowEXPLOITCRITICAL 9.8EPSS 4.70%1 November 2019
CVE-2019-18396A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi.EXPLOITHIGH 7.2EPSS 16.2%31 October 2019
CVE-2013-1391Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.EXPLOITHIGH 7.5EPSS 76.1%30 October 2019
CVE-2012-0694SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.EXPLOIT ×2CRITICAL 9.8EPSS 67.3%29 October 2019
CVE-2019-3978RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291.EXPLOITHIGH 7.5EPSS 10.3%29 October 2019
CVE-2019-11043PHP FastCGI Process Manager (FPM) Buffer Overflow VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.8%28 October 2019
CVE-2019-14931An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell.EXPLOITCRITICAL 9.8EPSS 58.1%28 October 2019
CVE-2019-14927An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).EXPLOITHIGH 7.5EPSS 41.8%28 October 2019
CVE-2019-16662An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.EXPLOIT ×2CRITICAL 9.8EPSS 97.7%28 October 2019
CVE-2019-18418clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.EXPLOITCRITICAL 9.8EPSS 4.00%24 October 2019
CVE-2019-10475A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.EXPLOITMEDIUM 6.1EPSS 57.7%23 October 2019
CVE-2019-17424A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.EXPLOITHIGH 7.8EPSS 13.4%22 October 2019
CVE-2019-17220Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.EXPLOITMEDIUM 6.1EPSS 4.02%21 October 2019
CVE-2019-9491Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.EXPLOITHIGH 7.8EPSS 12.9%21 October 2019
CVE-2019-10716An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.EXPLOITHIGH 7.7EPSS 4.10%21 October 2019
CVE-2019-8197Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 16.8%17 October 2019
CVE-2019-8196Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability.EXPLOITCRITICAL 9.8EPSS 22.9%17 October 2019
CVE-2019-8195Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability.EXPLOITCRITICAL 9.8EPSS 22.9%17 October 2019
CVE-2019-15627Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact.EXPLOITHIGH 7.1EPSS 1.31%17 October 2019
CVE-2019-14287In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID.EXPLOITHIGH 8.8EPSS 63.8%17 October 2019
CVE-2019-17671In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.EXPLOITMEDIUM 5.3EPSS 36.5%17 October 2019
CVE-2019-3025Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications.EXPLOITCRITICAL 9.0EPSS 14.5%16 October 2019
CVE-2019-3010Oracle Solaris Privilege Escalation VulnerabilityKEVEXPLOITHIGH 8.8EPSS 13.4%16 October 2019
CVE-2019-17662ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server.EXPLOITCRITICAL 9.8EPSS 96.8%16 October 2019
CVE-2019-17624"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap.EXPLOITHIGH 7.8EPSS 3.69%16 October 2019
CVE-2019-14737Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.EXPLOITHIGH 7.8EPSS 1.66%14 October 2019
CVE-2019-16278Nostromo nhttpd Directory Traversal VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.0%14 October 2019
CVE-2019-2215Android Kernel Use-After-Free VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 72.1%11 October 2019
CVE-2019-17504A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.EXPLOITMEDIUM 6.1EPSS 2.84%11 October 2019
CVE-2019-17503This file exposes SQL database information such as database version, table name, column name, etc.EXPLOITMEDIUM 5.3EPSS 48.3%11 October 2019
CVE-2019-1364An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 2.88%10 October 2019
CVE-2019-1347A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.EXPLOITMEDIUM 6.5EPSS 14.9%10 October 2019
CVE-2019-1346A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.EXPLOITMEDIUM 6.5EPSS 10.9%10 October 2019
CVE-2019-1345An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.EXPLOITMEDIUM 5.5EPSS 3.04%10 October 2019
CVE-2019-1344An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'.EXPLOITMEDIUM 5.5EPSS 3.07%10 October 2019
CVE-2019-1343A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.EXPLOITMEDIUM 6.5EPSS 10.9%10 October 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.