Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 39 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-1322 | Microsoft Windows Privilege Escalation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 19.2% | 10 October 2019 |
| CVE-2019-15715 | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. | EXPLOITHIGH 7.2EPSS 30.0% | 9 October 2019 |
| CVE-2019-17124 | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. | EXPLOITCRITICAL 9.8EPSS 22.5% | 9 October 2019 |
| CVE-2019-13529 | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. | EXPLOITHIGH 8.8EPSS 3.11% | 9 October 2019 |
| CVE-2019-10969 | Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution. | EXPLOITHIGH 7.2EPSS 10.6% | 8 October 2019 |
| CVE-2019-10963 | Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. | EXPLOITMEDIUM 4.3EPSS 6.50% | 8 October 2019 |
| CVE-2019-17240 | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 39.6% | 6 October 2019 |
| CVE-2019-17225 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue. | EXPLOITMEDIUM 5.4EPSS 1.94% | 6 October 2019 |
| CVE-2019-17132 | vBulletin through 5.5.4 mishandles custom avatars. | EXPLOITCRITICAL 9.8EPSS 11.7% | 4 October 2019 |
| CVE-2019-11932 | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to… | EXPLOITHIGH 8.8EPSS 44.5% | 3 October 2019 |
| CVE-2019-16116 | EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. | EXPLOITMEDIUM 4.3EPSS 3.68% | 2 October 2019 |
| CVE-2019-17080 | mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. | EXPLOITHIGH 7.8EPSS 8.20% | 2 October 2019 |
| CVE-2019-15039 | It had a possible remote code execution issue. | EXPLOIT ✓CRITICAL 9.8EPSS 12.9% | 1 October 2019 |
| CVE-2019-16902 | In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname. | EXPLOITHIGH 7.5EPSS 9.73% | 27 September 2019 |
| CVE-2019-12562 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. | EXPLOITMEDIUM 6.1EPSS 6.17% | 26 September 2019 |
| CVE-2019-16667 | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. | EXPLOITHIGH 8.8EPSS 54.5% | 26 September 2019 |
| CVE-2019-16894 | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. | EXPLOITCRITICAL 9.8EPSS 3.02% | 26 September 2019 |
| CVE-2019-10092 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. | EXPLOITMEDIUM 6.1EPSS 81.5% | 26 September 2019 |
| CVE-2019-10098 | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. | EXPLOITMEDIUM 6.1EPSS 74.0% | 25 September 2019 |
| CVE-2019-16701 | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value. | EXPLOITHIGH 8.8EPSS 19.6% | 25 September 2019 |
| CVE-2019-16759 | vBulletin PHP Module Remote Code Execution Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 99.7% | 24 September 2019 |
| CVE-2019-16724 | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331. | EXPLOITCRITICAL 9.8EPSS 72.2% | 24 September 2019 |
| CVE-2019-16383 | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. | EXPLOITCRITICAL 9.4EPSS 5.19% | 24 September 2019 |
| CVE-2019-13063 | Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. | EXPLOITHIGH 7.5EPSS 27.2% | 23 September 2019 |
| CVE-2019-16702 | Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI. | EXPLOITCRITICAL 9.8EPSS 10.7% | 23 September 2019 |
| CVE-2019-16693 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | EXPLOITCRITICAL 9.8EPSS 4.34% | 22 September 2019 |
| CVE-2019-16692 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | EXPLOITCRITICAL 9.8EPSS 10.3% | 22 September 2019 |
| CVE-2019-16679 | Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion. | EXPLOITMEDIUM 4.9EPSS 7.03% | 21 September 2019 |
| CVE-2019-16645 | Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. | EXPLOITHIGH 8.6EPSS 8.18% | 20 September 2019 |
| CVE-2019-16531 | LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. | EXPLOITHIGH 8.8EPSS 2.55% | 20 September 2019 |
| CVE-2019-15943 | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset… | EXPLOITHIGH 8.8EPSS 8.72% | 19 September 2019 |
| CVE-2019-16399 | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. | EXPLOITCRITICAL 9.8EPSS 7.08% | 18 September 2019 |
| CVE-2019-16197 | In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS. | EXPLOITMEDIUM 6.1EPSS 2.99% | 16 September 2019 |
| CVE-2019-16294 | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. | EXPLOITHIGH 7.8EPSS 9.83% | 14 September 2019 |
| CVE-2019-5485 | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. | EXPLOITCRITICAL 10.0EPSS 58.8% | 13 September 2019 |
| CVE-2019-11660 | This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges. | EXPLOIT ✓HIGH 7.8EPSS 7.85% | 13 September 2019 |
| CVE-2019-12922 | A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. | EXPLOITMEDIUM 6.5EPSS 10.1% | 13 September 2019 |
| CVE-2019-1262 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. | EXPLOITMEDIUM 5.4EPSS 2.99% | 11 September 2019 |
| CVE-2019-1253 | Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 11.6% | 11 September 2019 |
| CVE-2019-1245 | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. | EXPLOIT ✓MEDIUM 6.5EPSS 12.9% | 11 September 2019 |
| CVE-2019-1244 | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. | EXPLOIT ✓MEDIUM 6.5EPSS 12.1% | 11 September 2019 |
| CVE-2019-1215 | Microsoft Windows Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 19.3% | 11 September 2019 |
| CVE-2019-3759 | The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. | EXPLOITHIGH 8.1EPSS 3.23% | 11 September 2019 |
| CVE-2019-8449 | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability. | EXPLOITMEDIUM 5.3EPSS 84.8% | 11 September 2019 |
| CVE-2019-16223 | WordPress before 5.2.3 allows XSS in post previews by authenticated users. | EXPLOITMEDIUM 5.4EPSS 5.18% | 11 September 2019 |
| CVE-2019-16173 | LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. | EXPLOIT ✓MEDIUM 5.4EPSS 3.67% | 9 September 2019 |
| CVE-2019-16172 | LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. | EXPLOIT ✓MEDIUM 5.4EPSS 4.61% | 9 September 2019 |
| CVE-2019-10669 | There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. | EXPLOIT ✓HIGH 7.2EPSS 80.7% | 9 September 2019 |
| CVE-2019-16119 | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. | EXPLOITCRITICAL 9.8EPSS 24.8% | 8 September 2019 |
| CVE-2019-16118 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. | EXPLOITMEDIUM 6.1EPSS 5.30% | 8 September 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.