Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 43 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-13068 | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). | EXPLOIT ✓MEDIUM 5.4EPSS 51.9% | 30 June 2019 |
| CVE-2019-5786 | Google Chrome Blink Use-After-Free Vulnerability | KEVEXPLOIT ✓MEDIUM 6.5EPSS 61.5% | 27 June 2019 |
| CVE-2018-6130 | Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | EXPLOIT ✓MEDIUM 6.5EPSS 2.95% | 27 June 2019 |
| CVE-2018-6129 | Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | EXPLOIT ✓MEDIUM 6.5EPSS 2.75% | 27 June 2019 |
| CVE-2019-1622 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. | EXPLOIT ✓MEDIUM 5.3EPSS 78.9% | 27 June 2019 |
| CVE-2019-1620 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. | EXPLOIT ✓CRITICAL 9.8EPSS 83.8% | 27 June 2019 |
| CVE-2019-1619 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. | EXPLOIT ✓CRITICAL 9.8EPSS 82.8% | 27 June 2019 |
| CVE-2019-12962 | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. | EXPLOITMEDIUM 6.1EPSS 9.05% | 25 June 2019 |
| CVE-2019-12323 | The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. | EXPLOITHIGH 7.5EPSS 8.79% | 24 June 2019 |
| CVE-2019-12745 | out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. | EXPLOITMEDIUM 5.4EPSS 2.57% | 20 June 2019 |
| CVE-2019-12744 | SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940. | EXPLOIT ×2HIGH 7.5EPSS 11.7% | 20 June 2019 |
| CVE-2019-12905 | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. | EXPLOITMEDIUM 6.1EPSS 3.60% | 20 June 2019 |
| CVE-2019-2729 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | EXPLOITCRITICAL 9.8EPSS 88.8% | 19 June 2019 |
| CVE-2019-2025 | In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. | EXPLOIT ✓HIGH 7.8EPSS 0.52% | 19 June 2019 |
| CVE-2019-2023 | In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. | EXPLOIT ✓HIGH 7.8EPSS 0.49% | 19 June 2019 |
| CVE-2019-9701 | DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. | EXPLOITMEDIUM 4.8EPSS 1.76% | 19 June 2019 |
| CVE-2019-6971 | An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials. | EXPLOITCRITICAL 9.8EPSS 13.7% | 19 June 2019 |
| CVE-2019-6965 | An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. | EXPLOITMEDIUM 6.1EPSS 2.52% | 18 June 2019 |
| CVE-2019-11409 | app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. | EXPLOIT ✓HIGH 8.8EPSS 87.5% | 17 June 2019 |
| CVE-2019-12801 | out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name. | EXPLOITMEDIUM 6.1EPSS 1.92% | 17 June 2019 |
| CVE-2019-12181 | A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | EXPLOIT ×3 ✓HIGH 8.8EPSS 66.0% | 17 June 2019 |
| CVE-2018-20472 | The logs web interface is vulnerable to stored XSS. | EXPLOITMEDIUM 5.4EPSS 2.08% | 17 June 2019 |
| CVE-2018-20470 | A directory traversal (arbitrary file access) vulnerability exists in the web reports module. | EXPLOITHIGH 7.5EPSS 46.1% | 17 June 2019 |
| CVE-2018-20469 | A parameter in the web reports module is vulnerable to h2 SQL injection. | EXPLOITCRITICAL 9.8EPSS 18.5% | 17 June 2019 |
| CVE-2019-12840 | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi. | EXPLOIT ✓HIGH 8.8EPSS 77.8% | 15 June 2019 |
| CVE-2019-12828 | Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath… | EXPLOITHIGH 8.8EPSS 13.3% | 14 June 2019 |
| CVE-2019-11269 | Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. | EXPLOITMEDIUM 5.4EPSS 8.91% | 12 June 2019 |
| CVE-2019-1019 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. | EXPLOIT ✓HIGH 8.5EPSS 15.1% | 12 June 2019 |
| CVE-2019-0959 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. | EXPLOIT ✓HIGH 7.0EPSS 3.54% | 12 June 2019 |
| CVE-2019-0948 | An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. | EXPLOIT ✓MEDIUM 4.7EPSS 12.7% | 12 June 2019 |
| CVE-2019-0943 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | EXPLOIT ✓HIGH 7.8EPSS 2.37% | 12 June 2019 |
| CVE-2019-12765 | The CSV export of com_actionslogs is vulnerable to CSV injection. | EXPLOITCRITICAL 9.8EPSS 10.5% | 11 June 2019 |
| CVE-2019-10226 | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. | EXPLOITMEDIUM 5.4EPSS 4.70% | 10 June 2019 |
| CVE-2019-12788 | It is possible to perform a buffer overflow via a crafted file. | EXPLOITHIGH 7.8EPSS 4.45% | 10 June 2019 |
| CVE-2019-9881 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | EXPLOITMEDIUM 5.3EPSS 18.8% | 10 June 2019 |
| CVE-2019-9880 | By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. | EXPLOITCRITICAL 9.1EPSS 34.8% | 10 June 2019 |
| CVE-2019-9879 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. | EXPLOITCRITICAL 9.8EPSS 46.6% | 10 June 2019 |
| CVE-2018-20523 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. | EXPLOITMEDIUM 5.3EPSS 10.0% | 7 June 2019 |
| CVE-2019-12477 | Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI. | EXPLOITMEDIUM 5.5EPSS 13.3% | 7 June 2019 |
| CVE-2019-6989 | TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. | EXPLOITHIGH 8.8EPSS 11.6% | 6 June 2019 |
| CVE-2019-11080 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. | EXPLOITHIGH 8.8EPSS 14.2% | 6 June 2019 |
| CVE-2019-8385 | An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. | EXPLOITCRITICAL 9.8EPSS 19.6% | 5 June 2019 |
| CVE-2019-7671 | Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site. | EXPLOITCRITICAL 9.0EPSS 8.26% | 5 June 2019 |
| CVE-2019-9189 | The application allows the upload of arbitrary Python scripts when configuring the main central controller. | EXPLOITHIGH 8.8EPSS 11.6% | 5 June 2019 |
| CVE-2019-12276 | A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName=… | EXPLOITHIGH 7.5EPSS 57.1% | 5 June 2019 |
| CVE-2019-9647 | Gila CMS 1.9.1 has XSS. | EXPLOITMEDIUM 6.1EPSS 2.26% | 5 June 2019 |
| CVE-2019-5392 | A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | EXPLOITMEDIUM 5.3EPSS 7.16% | 5 June 2019 |
| CVE-2019-12543 | There is XSS via the PurchaseRequest.do serviceRequestId parameter. | EXPLOITMEDIUM 6.1EPSS 6.06% | 5 June 2019 |
| CVE-2019-12542 | There is XSS via the SearchN.do userConfigID parameter. | EXPLOITMEDIUM 6.1EPSS 6.03% | 5 June 2019 |
| CVE-2019-12541 | There is XSS via the SolutionSearch.do searchText parameter. | EXPLOITMEDIUM 6.1EPSS 6.03% | 5 June 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.