SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 39 of 501

CVESummaryPriorityPublished
CVE-2019-1322Microsoft Windows Privilege Escalation VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 19.2%10 October 2019
CVE-2019-15715MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.EXPLOITHIGH 7.2EPSS 30.0%9 October 2019
CVE-2019-17124Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.EXPLOITCRITICAL 9.8EPSS 22.5%9 October 2019
CVE-2019-13529An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior.EXPLOITHIGH 8.8EPSS 3.11%9 October 2019
CVE-2019-10969Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.EXPLOITHIGH 7.2EPSS 10.6%8 October 2019
CVE-2019-10963Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure.EXPLOITMEDIUM 4.3EPSS 6.50%8 October 2019
CVE-2019-17240bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.EXPLOIT ×2CRITICAL 9.8EPSS 39.6%6 October 2019
CVE-2019-17225Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.EXPLOITMEDIUM 5.4EPSS 1.94%6 October 2019
CVE-2019-17132vBulletin through 5.5.4 mishandles custom avatars.EXPLOITCRITICAL 9.8EPSS 11.7%4 October 2019
CVE-2019-11932A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to…EXPLOITHIGH 8.8EPSS 44.5%3 October 2019
CVE-2019-16116EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file.EXPLOITMEDIUM 4.3EPSS 3.68%2 October 2019
CVE-2019-17080mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs.EXPLOITHIGH 7.8EPSS 8.20%2 October 2019
CVE-2019-15039It had a possible remote code execution issue.EXPLOITCRITICAL 9.8EPSS 12.9%1 October 2019
CVE-2019-16902In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.EXPLOITHIGH 7.5EPSS 9.73%27 September 2019
CVE-2019-12562Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page.EXPLOITMEDIUM 6.1EPSS 6.17%26 September 2019
CVE-2019-16667diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.EXPLOITHIGH 8.8EPSS 54.5%26 September 2019
CVE-2019-16894download.php in inoERP 4.15 allows SQL injection through insecure deserialization.EXPLOITCRITICAL 9.8EPSS 3.02%26 September 2019
CVE-2019-10092In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page.EXPLOITMEDIUM 6.1EPSS 81.5%26 September 2019
CVE-2019-10098In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.EXPLOITMEDIUM 6.1EPSS 74.0%25 September 2019
CVE-2019-16701pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.EXPLOITHIGH 8.8EPSS 19.6%25 September 2019
CVE-2019-16759vBulletin PHP Module Remote Code Execution VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.7%24 September 2019
CVE-2019-16724File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.EXPLOITCRITICAL 9.8EPSS 72.2%24 September 2019
CVE-2019-16383MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database.EXPLOITCRITICAL 9.4EPSS 5.19%24 September 2019
CVE-2019-13063Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page.EXPLOITHIGH 7.5EPSS 27.2%23 September 2019
CVE-2019-16702Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.EXPLOITCRITICAL 9.8EPSS 10.7%23 September 2019
CVE-2019-16693phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.EXPLOITCRITICAL 9.8EPSS 4.34%22 September 2019
CVE-2019-16692phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.EXPLOITCRITICAL 9.8EPSS 10.3%22 September 2019
CVE-2019-16679Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.EXPLOITMEDIUM 4.9EPSS 7.03%21 September 2019
CVE-2019-16645Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker.EXPLOITHIGH 8.6EPSS 8.18%20 September 2019
CVE-2019-16531LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.EXPLOITHIGH 8.8EPSS 2.55%20 September 2019
CVE-2019-15943vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset…EXPLOITHIGH 8.8EPSS 8.72%19 September 2019
CVE-2019-16399Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials.EXPLOITCRITICAL 9.8EPSS 7.08%18 September 2019
CVE-2019-16197In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.EXPLOITMEDIUM 6.1EPSS 2.99%16 September 2019
CVE-2019-16294SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.EXPLOITHIGH 7.8EPSS 9.83%14 September 2019
CVE-2019-5485NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability.EXPLOITCRITICAL 10.0EPSS 58.8%13 September 2019
CVE-2019-11660This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.EXPLOITHIGH 7.8EPSS 7.85%13 September 2019
CVE-2019-12922A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.EXPLOITMEDIUM 6.5EPSS 10.1%13 September 2019
CVE-2019-1262A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.EXPLOITMEDIUM 5.4EPSS 2.99%11 September 2019
CVE-2019-1253Microsoft Windows AppX Deployment Server Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 11.6%11 September 2019
CVE-2019-1245An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.EXPLOITMEDIUM 6.5EPSS 12.9%11 September 2019
CVE-2019-1244An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.EXPLOITMEDIUM 6.5EPSS 12.1%11 September 2019
CVE-2019-1215Microsoft Windows Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 19.3%11 September 2019
CVE-2019-3759The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability.EXPLOITHIGH 8.1EPSS 3.23%11 September 2019
CVE-2019-8449The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.EXPLOITMEDIUM 5.3EPSS 84.8%11 September 2019
CVE-2019-16223WordPress before 5.2.3 allows XSS in post previews by authenticated users.EXPLOITMEDIUM 5.4EPSS 5.18%11 September 2019
CVE-2019-16173LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin.EXPLOITMEDIUM 5.4EPSS 3.67%9 September 2019
CVE-2019-16172LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin.EXPLOITMEDIUM 5.4EPSS 4.61%9 September 2019
CVE-2019-10669There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function.EXPLOITHIGH 7.2EPSS 80.7%9 September 2019
CVE-2019-16119SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.EXPLOITCRITICAL 9.8EPSS 24.8%8 September 2019
CVE-2019-16118Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.EXPLOITMEDIUM 6.1EPSS 5.30%8 September 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.