SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 40 of 501

CVESummaryPriorityPublished
CVE-2019-16117Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.EXPLOITMEDIUM 6.1EPSS 4.61%8 September 2019
CVE-2019-16113Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.EXPLOIT ×3HIGH 8.8EPSS 78.0%8 September 2019
CVE-2019-15029FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database).EXPLOITHIGH 8.8EPSS 12.3%5 September 2019
CVE-2019-14339This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.EXPLOITMEDIUM 5.5EPSS 5.39%5 September 2019
CVE-2019-15954An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side.EXPLOITCRITICAL 9.9EPSS 78.7%5 September 2019
CVE-2019-15949Nagios XI Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 77.0%5 September 2019
CVE-2019-10677Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd…EXPLOITMEDIUM 6.1EPSS 7.25%5 September 2019
CVE-2019-14470cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.EXPLOITMEDIUM 6.1EPSS 83.0%4 September 2019
CVE-2019-15814Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.EXPLOITMEDIUM 5.4EPSS 1.58%4 September 2019
CVE-2019-15813Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.EXPLOIT ×2HIGH 8.8EPSS 33.2%4 September 2019
CVE-2019-10709AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.EXPLOITCRITICAL 9.8EPSS 11.5%4 September 2019
CVE-2019-15889The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.EXPLOITMEDIUM 6.1EPSS 11.4%3 September 2019
CVE-2019-1125An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory.EXPLOITMEDIUM 5.6EPSS 4.52%3 September 2019
CVE-2019-15811In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.EXPLOITMEDIUM 6.1EPSS 6.99%29 August 2019
CVE-2019-15752Docker Desktop Community Edition Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 31.9%28 August 2019
CVE-2019-13237In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and…EXPLOITMEDIUM 4.3EPSS 7.35%27 August 2019
CVE-2019-13236In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.EXPLOITMEDIUM 6.1EPSS 3.11%27 August 2019
CVE-2019-13235In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.EXPLOITMEDIUM 6.1EPSS 2.90%27 August 2019
CVE-2019-13234In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.EXPLOITMEDIUM 6.1EPSS 2.90%27 August 2019
CVE-2019-15637Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS.EXPLOITHIGH 8.1EPSS 14.3%26 August 2019
CVE-2019-15501Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.EXPLOITMEDIUM 6.1EPSS 7.42%26 August 2019
CVE-2019-15092The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter…EXPLOITHIGH 7.3EPSS 5.14%23 August 2019
CVE-2019-11013Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability.EXPLOITMEDIUM 6.5EPSS 27.4%22 August 2019
CVE-2019-1937A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session…EXPLOITCRITICAL 9.8EPSS 75.9%21 August 2019
CVE-2019-1935A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User…EXPLOITCRITICAL 9.8EPSS 83.4%21 August 2019
CVE-2019-12624A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an…EXPLOITHIGH 8.8EPSS 18.2%21 August 2019
CVE-2019-8050Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 40.6%20 August 2019
CVE-2019-8049Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 19.7%20 August 2019
CVE-2019-8048Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability.EXPLOITCRITICAL 9.8EPSS 34.6%20 August 2019
CVE-2019-8046Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 17.9%20 August 2019
CVE-2019-8045Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference…EXPLOITCRITICAL 9.8EPSS 16.0%20 August 2019
CVE-2019-8044Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability.EXPLOITCRITICAL 9.8EPSS 14.5%20 August 2019
CVE-2019-8043Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability.EXPLOITHIGH 7.5EPSS 13.4%20 August 2019
CVE-2019-8042Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 16.8%20 August 2019
CVE-2019-8041Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.EXPLOITCRITICAL 9.8EPSS 17.9%20 August 2019
CVE-2019-8024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability.EXPLOITCRITICAL 9.8EPSS 15.1%20 August 2019
CVE-2019-8017Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference…EXPLOITCRITICAL 9.8EPSS 13.3%20 August 2019
CVE-2019-8016Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability.EXPLOITCRITICAL 9.8EPSS 22.0%20 August 2019
CVE-2019-14430plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.EXPLOITMEDIUM 5.3EPSS 2.98%20 August 2019
CVE-2019-13069extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM.EXPLOITHIGH 7.8EPSS 1.17%17 August 2019
CVE-2015-9323The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.EXPLOITCRITICAL 9.8EPSS 46.1%16 August 2019
CVE-2019-15107Webmin Command Injection VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.8%16 August 2019
CVE-2019-15106One can bypass the user password requirement and execute commands on the server.EXPLOITCRITICAL 9.8EPSS 25.5%16 August 2019
CVE-2019-15105There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter.EXPLOITHIGH 8.8EPSS 7.79%16 August 2019
CVE-2019-15104There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter.EXPLOITHIGH 8.8EPSS 7.79%16 August 2019
CVE-2019-15084As a result, a local attacker can escalate to SYSTEM.EXPLOITHIGH 7.8EPSS 0.94%16 August 2019
CVE-2019-9851LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from.EXPLOITCRITICAL 9.8EPSS 78.3%15 August 2019
CVE-2019-14422The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code.EXPLOITHIGH 8.8EPSS 16.4%15 August 2019
CVE-2019-15081OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.EXPLOITMEDIUM 4.8EPSS 1.95%15 August 2019
CVE-2019-1184An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls.EXPLOITMEDIUM 6.7EPSS 70.2%14 August 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.