Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 41 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-1170 | An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. | EXPLOIT ✓HIGH 7.9EPSS 2.43% | 14 August 2019 |
| CVE-2019-1153 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. | EXPLOIT ✓MEDIUM 5.5EPSS 2.83% | 14 August 2019 |
| CVE-2019-1152 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ✓HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-1151 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ✓HIGH 8.8EPSS 15.5% | 14 August 2019 |
| CVE-2019-1150 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ×2 ✓HIGH 8.8EPSS 28.9% | 14 August 2019 |
| CVE-2019-1149 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ✓HIGH 8.8EPSS 13.9% | 14 August 2019 |
| CVE-2019-1148 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. | EXPLOIT ✓MEDIUM 5.5EPSS 2.83% | 14 August 2019 |
| CVE-2019-1145 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ✓HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-1144 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | EXPLOIT ✓HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-14974 | SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. | EXPLOITMEDIUM 6.1EPSS 28.4% | 14 August 2019 |
| CVE-2019-14530 | An attacker can download any file (that is readable by the user www-data) from server storage. | EXPLOITHIGH 8.8EPSS 65.5% | 13 August 2019 |
| CVE-2019-12255 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). | EXPLOITCRITICAL 9.8EPSS 75.3% | 9 August 2019 |
| CVE-2019-14804 | studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing. | EXPLOITMEDIUM 4.8EPSS 2.67% | 9 August 2019 |
| CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. | EXPLOITMEDIUM 6.5EPSS 20.6% | 9 August 2019 |
| CVE-2019-14221 | 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. | EXPLOITMEDIUM 5.4EPSS 1.71% | 8 August 2019 |
| CVE-2019-13101 | An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the… | EXPLOITCRITICAL 9.8EPSS 67.1% | 8 August 2019 |
| CVE-2019-14750 | Stored XSS exists in setup/install.php. | EXPLOIT ✓MEDIUM 6.1EPSS 10.9% | 7 August 2019 |
| CVE-2019-14749 | CSV (aka Formula) injection exists in the export spreadsheets functionality. | EXPLOIT ✓HIGH 8.8EPSS 9.61% | 7 August 2019 |
| CVE-2019-14748 | The Ticket creation form allows users to upload files along with queries. | EXPLOIT ✓MEDIUM 5.4EPSS 2.73% | 7 August 2019 |
| CVE-2019-1914 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. | EXPLOITHIGH 7.2EPSS 24.9% | 7 August 2019 |
| CVE-2019-1913 | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on… | EXPLOITCRITICAL 9.8EPSS 25.9% | 7 August 2019 |
| CVE-2019-1912 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. | EXPLOITCRITICAL 9.1EPSS 17.0% | 7 August 2019 |
| CVE-2019-14347 | Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script. | EXPLOITHIGH 8.8EPSS 9.31% | 6 August 2019 |
| CVE-2019-14696 | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. | EXPLOITMEDIUM 6.1EPSS 15.7% | 6 August 2019 |
| CVE-2019-14346 | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. | EXPLOITHIGH 8.8EPSS 2.74% | 6 August 2019 |
| CVE-2019-14348 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter. | EXPLOITCRITICAL 9.8EPSS 20.5% | 5 August 2019 |
| CVE-2019-3948 | An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device. | EXPLOIT ✓HIGH 7.5EPSS 25.0% | 29 July 2019 |
| CVE-2019-14267 | PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled. | EXPLOIT ✓HIGH 7.8EPSS 7.05% | 29 July 2019 |
| CVE-2019-14378 | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment. | EXPLOITHIGH 8.8EPSS 16.7% | 29 July 2019 |
| CVE-2019-14328 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | EXPLOITHIGH 8.8EPSS 3.15% | 28 July 2019 |
| CVE-2019-14322 | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. | EXPLOITHIGH 7.5EPSS 55.8% | 28 July 2019 |
| CVE-2019-10267 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. | EXPLOIT ×2 ✓HIGH 8.8EPSS 75.2% | 26 July 2019 |
| CVE-2019-10266 | When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication. | EXPLOITHIGH 7.5EPSS 13.3% | 26 July 2019 |
| CVE-2019-14280 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | EXPLOITMEDIUM 5.3EPSS 9.36% | 26 July 2019 |
| CVE-2019-2861 | Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). | EXPLOIT ✓MEDIUM 4.2EPSS 4.31% | 23 July 2019 |
| CVE-2019-9816 | A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with… | EXPLOIT ✓MEDIUM 5.9EPSS 6.15% | 23 July 2019 |
| CVE-2019-11708 | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 55.9% | 23 July 2019 |
| CVE-2019-11707 | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 37.7% | 23 July 2019 |
| CVE-2019-11706 | A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. | EXPLOITHIGH 7.5EPSS 9.73% | 23 July 2019 |
| CVE-2019-11705 | A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in a potentially exploitable crash. | EXPLOITCRITICAL 9.8EPSS 9.90% | 23 July 2019 |
| CVE-2019-11704 | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash. | EXPLOITCRITICAL 9.8EPSS 10.5% | 23 July 2019 |
| CVE-2019-11703 | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash. | EXPLOITCRITICAL 9.8EPSS 10.5% | 23 July 2019 |
| CVE-2019-1010124 | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). | EXPLOITMEDIUM 5.4EPSS 3.21% | 23 July 2019 |
| CVE-2019-12725 | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 89.8% | 19 July 2019 |
| CVE-2019-13977 | index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=. | EXPLOITMEDIUM 5.4EPSS 1.50% | 19 July 2019 |
| CVE-2019-13961 | A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php. | EXPLOITHIGH 8.8EPSS 2.25% | 18 July 2019 |
| CVE-2019-1943 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. | EXPLOITMEDIUM 6.1EPSS 9.69% | 17 July 2019 |
| CVE-2019-13577 | SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987. | EXPLOIT ×2CRITICAL 9.8EPSS 24.4% | 17 July 2019 |
| CVE-2019-13493 | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. | EXPLOITMEDIUM 5.4EPSS 1.58% | 17 July 2019 |
| CVE-2019-13346 | In MyT 1.5.1, the User[username] parameter has XSS. | EXPLOITMEDIUM 6.1EPSS 2.19% | 17 July 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.