SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 41 of 501

CVESummaryPriorityPublished
CVE-2019-1170An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape.EXPLOITHIGH 7.9EPSS 2.43%14 August 2019
CVE-2019-1153An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory.EXPLOITMEDIUM 5.5EPSS 2.83%14 August 2019
CVE-2019-1152A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOITHIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-1151A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOITHIGH 8.8EPSS 15.5%14 August 2019
CVE-2019-1150A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOIT ×2HIGH 8.8EPSS 28.9%14 August 2019
CVE-2019-1149A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOITHIGH 8.8EPSS 13.9%14 August 2019
CVE-2019-1148An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory.EXPLOITMEDIUM 5.5EPSS 2.83%14 August 2019
CVE-2019-1145A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOITHIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-1144A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.EXPLOITHIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-14974SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.EXPLOITMEDIUM 6.1EPSS 28.4%14 August 2019
CVE-2019-14530An attacker can download any file (that is readable by the user www-data) from server storage.EXPLOITHIGH 8.8EPSS 65.5%13 August 2019
CVE-2019-12255Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).EXPLOITCRITICAL 9.8EPSS 75.3%9 August 2019
CVE-2019-14804studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.EXPLOITMEDIUM 4.8EPSS 2.67%9 August 2019
CVE-2019-14312Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer.EXPLOITMEDIUM 6.5EPSS 20.6%9 August 2019
CVE-2019-142211CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.EXPLOITMEDIUM 5.4EPSS 1.71%8 August 2019
CVE-2019-13101An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the…EXPLOITCRITICAL 9.8EPSS 67.1%8 August 2019
CVE-2019-14750Stored XSS exists in setup/install.php.EXPLOITMEDIUM 6.1EPSS 10.9%7 August 2019
CVE-2019-14749CSV (aka Formula) injection exists in the export spreadsheets functionality.EXPLOITHIGH 8.8EPSS 9.61%7 August 2019
CVE-2019-14748The Ticket creation form allows users to upload files along with queries.EXPLOITMEDIUM 5.4EPSS 2.73%7 August 2019
CVE-2019-1914A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack.EXPLOITHIGH 7.2EPSS 24.9%7 August 2019
CVE-2019-1913Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on…EXPLOITCRITICAL 9.8EPSS 25.9%7 August 2019
CVE-2019-1912A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files.EXPLOITCRITICAL 9.1EPSS 17.0%7 August 2019
CVE-2019-14347Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.EXPLOITHIGH 8.8EPSS 9.31%6 August 2019
CVE-2019-14696Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.EXPLOITMEDIUM 6.1EPSS 15.7%6 August 2019
CVE-2019-14346Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.EXPLOITHIGH 8.8EPSS 2.74%6 August 2019
CVE-2019-14348The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.EXPLOITCRITICAL 9.8EPSS 20.5%5 August 2019
CVE-2019-3948An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.EXPLOITHIGH 7.5EPSS 25.0%29 July 2019
CVE-2019-14267PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.EXPLOITHIGH 7.8EPSS 7.05%29 July 2019
CVE-2019-14378ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.EXPLOITHIGH 8.8EPSS 16.7%29 July 2019
CVE-2019-14328The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.EXPLOITHIGH 8.8EPSS 3.15%28 July 2019
CVE-2019-14322In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.EXPLOITHIGH 7.5EPSS 55.8%28 July 2019
CVE-2019-10267An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50.EXPLOIT ×2HIGH 8.8EPSS 75.2%26 July 2019
CVE-2019-10266When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.EXPLOITHIGH 7.5EPSS 13.3%26 July 2019
CVE-2019-14280In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.EXPLOITMEDIUM 5.3EPSS 9.36%26 July 2019
CVE-2019-2861Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security).EXPLOITMEDIUM 4.2EPSS 4.31%23 July 2019
CVE-2019-9816A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with…EXPLOITMEDIUM 5.9EPSS 6.15%23 July 2019
CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 55.9%23 July 2019
CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 37.7%23 July 2019
CVE-2019-11706A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash.EXPLOITHIGH 7.5EPSS 9.73%23 July 2019
CVE-2019-11705A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash.EXPLOITCRITICAL 9.8EPSS 9.90%23 July 2019
CVE-2019-11704A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash.EXPLOITCRITICAL 9.8EPSS 10.5%23 July 2019
CVE-2019-11703A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash.EXPLOITCRITICAL 9.8EPSS 10.5%23 July 2019
CVE-2019-1010124WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS).EXPLOITMEDIUM 5.4EPSS 3.21%23 July 2019
CVE-2019-12725Zeroshell 3.9.0 is prone to a remote command execution vulnerability.EXPLOIT ×2CRITICAL 9.8EPSS 89.8%19 July 2019
CVE-2019-13977index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.EXPLOITMEDIUM 5.4EPSS 1.50%19 July 2019
CVE-2019-13961A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.EXPLOITHIGH 8.8EPSS 2.25%18 July 2019
CVE-2019-1943A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.EXPLOITMEDIUM 6.1EPSS 9.69%17 July 2019
CVE-2019-13577SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.EXPLOIT ×2CRITICAL 9.8EPSS 24.4%17 July 2019
CVE-2019-13493In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager.EXPLOITMEDIUM 5.4EPSS 1.58%17 July 2019
CVE-2019-13346In MyT 1.5.1, the User[username] parameter has XSS.EXPLOITMEDIUM 6.1EPSS 2.19%17 July 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.