Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 40 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-16117 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. | EXPLOITMEDIUM 6.1EPSS 4.61% | 8 September 2019 |
| CVE-2019-16113 | Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname. | EXPLOIT ×3 ✓HIGH 8.8EPSS 78.0% | 8 September 2019 |
| CVE-2019-15029 | FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). | EXPLOITHIGH 8.8EPSS 12.3% | 5 September 2019 |
| CVE-2019-14339 | This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key. | EXPLOITMEDIUM 5.5EPSS 5.39% | 5 September 2019 |
| CVE-2019-15954 | An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. | EXPLOIT ✓CRITICAL 9.9EPSS 78.7% | 5 September 2019 |
| CVE-2019-15949 | Nagios XI Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 77.0% | 5 September 2019 |
| CVE-2019-10677 | Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd… | EXPLOITMEDIUM 6.1EPSS 7.25% | 5 September 2019 |
| CVE-2019-14470 | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter. | EXPLOITMEDIUM 6.1EPSS 83.0% | 4 September 2019 |
| CVE-2019-15814 | Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML. | EXPLOITMEDIUM 5.4EPSS 1.58% | 4 September 2019 |
| CVE-2019-15813 | Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. | EXPLOIT ×2HIGH 8.8EPSS 33.2% | 4 September 2019 |
| CVE-2019-10709 | AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call. | EXPLOITCRITICAL 9.8EPSS 11.5% | 4 September 2019 |
| CVE-2019-15889 | The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. | EXPLOITMEDIUM 6.1EPSS 11.4% | 3 September 2019 |
| CVE-2019-1125 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. | EXPLOITMEDIUM 5.6EPSS 4.52% | 3 September 2019 |
| CVE-2019-15811 | In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | EXPLOITMEDIUM 6.1EPSS 6.99% | 29 August 2019 |
| CVE-2019-15752 | Docker Desktop Community Edition Privilege Escalation Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 31.9% | 28 August 2019 |
| CVE-2019-13237 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and… | EXPLOITMEDIUM 4.3EPSS 7.35% | 27 August 2019 |
| CVE-2019-13236 | In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface. | EXPLOITMEDIUM 6.1EPSS 3.11% | 27 August 2019 |
| CVE-2019-13235 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | EXPLOITMEDIUM 6.1EPSS 2.90% | 27 August 2019 |
| CVE-2019-13234 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | EXPLOITMEDIUM 6.1EPSS 2.90% | 27 August 2019 |
| CVE-2019-15637 | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. | EXPLOIT ✓HIGH 8.1EPSS 14.3% | 26 August 2019 |
| CVE-2019-15501 | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. | EXPLOITMEDIUM 6.1EPSS 7.42% | 26 August 2019 |
| CVE-2019-15092 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter… | EXPLOITHIGH 7.3EPSS 5.14% | 23 August 2019 |
| CVE-2019-11013 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. | EXPLOITMEDIUM 6.5EPSS 27.4% | 22 August 2019 |
| CVE-2019-1937 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session… | EXPLOITCRITICAL 9.8EPSS 75.9% | 21 August 2019 |
| CVE-2019-1935 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User… | EXPLOIT ✓CRITICAL 9.8EPSS 83.4% | 21 August 2019 |
| CVE-2019-12624 | A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an… | EXPLOITHIGH 8.8EPSS 18.2% | 21 August 2019 |
| CVE-2019-8050 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 40.6% | 20 August 2019 |
| CVE-2019-8049 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 19.7% | 20 August 2019 |
| CVE-2019-8048 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 34.6% | 20 August 2019 |
| CVE-2019-8046 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 17.9% | 20 August 2019 |
| CVE-2019-8045 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference… | EXPLOIT ✓CRITICAL 9.8EPSS 16.0% | 20 August 2019 |
| CVE-2019-8044 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 14.5% | 20 August 2019 |
| CVE-2019-8043 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 13.4% | 20 August 2019 |
| CVE-2019-8042 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 16.8% | 20 August 2019 |
| CVE-2019-8041 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 17.9% | 20 August 2019 |
| CVE-2019-8024 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 15.1% | 20 August 2019 |
| CVE-2019-8017 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference… | EXPLOIT ✓CRITICAL 9.8EPSS 13.3% | 20 August 2019 |
| CVE-2019-8016 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. | EXPLOIT ✓CRITICAL 9.8EPSS 22.0% | 20 August 2019 |
| CVE-2019-14430 | plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. | EXPLOITMEDIUM 5.3EPSS 2.98% | 20 August 2019 |
| CVE-2019-13069 | extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. | EXPLOITHIGH 7.8EPSS 1.17% | 17 August 2019 |
| CVE-2015-9323 | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | EXPLOITCRITICAL 9.8EPSS 46.1% | 16 August 2019 |
| CVE-2019-15107 | Webmin Command Injection Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.8% | 16 August 2019 |
| CVE-2019-15106 | One can bypass the user password requirement and execute commands on the server. | EXPLOITCRITICAL 9.8EPSS 25.5% | 16 August 2019 |
| CVE-2019-15105 | There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. | EXPLOITHIGH 8.8EPSS 7.79% | 16 August 2019 |
| CVE-2019-15104 | There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. | EXPLOITHIGH 8.8EPSS 7.79% | 16 August 2019 |
| CVE-2019-15084 | As a result, a local attacker can escalate to SYSTEM. | EXPLOITHIGH 7.8EPSS 0.94% | 16 August 2019 |
| CVE-2019-9851 | LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. | EXPLOITCRITICAL 9.8EPSS 78.3% | 15 August 2019 |
| CVE-2019-14422 | The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code. | EXPLOITHIGH 8.8EPSS 16.4% | 15 August 2019 |
| CVE-2019-15081 | OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages. | EXPLOITMEDIUM 4.8EPSS 1.95% | 15 August 2019 |
| CVE-2019-1184 | An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. | EXPLOITMEDIUM 6.7EPSS 70.2% | 14 August 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.