SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 44 of 501

CVESummaryPriorityPublished
CVE-2019-12538There is XSS via the SiteLookup.do search field.EXPLOITMEDIUM 6.1EPSS 6.03%5 June 2019
CVE-2019-12735getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.EXPLOITHIGH 8.6EPSS 19.0%5 June 2019
CVE-2019-10149Exim Mail Transfer Agent (MTA) Improper Input ValidationKEVEXPLOIT ×3CRITICAL 9.8EPSS 100.0%5 June 2019
CVE-2019-12616A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user.EXPLOITMEDIUM 6.5EPSS 19.2%5 June 2019
CVE-2018-13382Fortinet FortiOS and FortiProxy Improper AuthorizationKEVEXPLOITHIGH 7.5EPSS 81.7%4 June 2019
CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 100.0%4 June 2019
CVE-2019-11368Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.EXPLOITMEDIUM 5.4EPSS 1.58%3 June 2019
CVE-2019-10009A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505.EXPLOITMEDIUM 6.5EPSS 11.5%3 June 2019
CVE-2019-6588In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha…EXPLOITMEDIUM 4.7EPSS 2.28%3 June 2019
CVE-2019-11370Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.EXPLOITMEDIUM 5.4EPSS 5.03%3 June 2019
CVE-2019-11369In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.EXPLOITHIGH 8.8EPSS 8.29%3 June 2019
CVE-2018-5406The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism.EXPLOITHIGH 8.8EPSS 12.2%3 June 2019
CVE-2018-5405The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Console Only' rights to potentially inject arbitrary JavaScript code on the tickets page.EXPLOITMEDIUM 5.4EPSS 3.68%3 June 2019
CVE-2018-5404The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) to potentially exploit multiple Blind SQL Injection vulnerabilities to retrieve sensitive information…EXPLOITMEDIUM 6.5EPSS 3.84%3 June 2019
CVE-2019-12593IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.EXPLOITHIGH 7.5EPSS 41.0%3 June 2019
CVE-2019-10123SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database.EXPLOITCRITICAL 9.8EPSS 65.8%31 May 2019
CVE-2019-10038Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file.EXPLOITHIGH 7.8EPSS 1.31%31 May 2019
CVE-2019-12480BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services.EXPLOITHIGH 7.5EPSS 33.7%30 May 2019
CVE-2019-12461Web Port 1.19.1 allows XSS via the /log type parameter.EXPLOITMEDIUM 6.1EPSS 9.92%30 May 2019
CVE-2019-12460Web Port 1.19.1 allows XSS via the /access/setup type parameter.EXPLOITMEDIUM 6.1EPSS 3.83%30 May 2019
CVE-2019-9670Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity ReferenceKEVEXPLOITCRITICAL 9.8EPSS 100.0%29 May 2019
CVE-2019-12347In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action.EXPLOITMEDIUM 6.1EPSS 58.6%29 May 2019
CVE-2019-0221The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS.EXPLOITMEDIUM 6.1EPSS 45.6%28 May 2019
CVE-2019-12372Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.EXPLOITHIGH 7.8EPSS 0.94%28 May 2019
CVE-2019-10685A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.EXPLOITMEDIUM 6.1EPSS 2.26%24 May 2019
CVE-2019-10848Computrols CBAS 18.0.0 allows Username Enumeration.EXPLOITMEDIUM 5.3EPSS 8.49%24 May 2019
CVE-2019-10847Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.EXPLOITHIGH 8.8EPSS 2.42%24 May 2019
CVE-2019-12195TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name.EXPLOITMEDIUM 4.8EPSS 1.76%24 May 2019
CVE-2019-12314Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.EXPLOITCRITICAL 9.8EPSS 84.2%24 May 2019
CVE-2019-5796Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.EXPLOITHIGH 7.5EPSS 4.61%23 May 2019
CVE-2019-5789An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.EXPLOITHIGH 8.8EPSS 9.26%23 May 2019
CVE-2019-5788An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.EXPLOITHIGH 8.8EPSS 9.09%23 May 2019
CVE-2019-10849Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.EXPLOITHIGH 7.5EPSS 9.01%23 May 2019
CVE-2019-10846Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.EXPLOITMEDIUM 6.1EPSS 4.66%23 May 2019
CVE-2019-10866In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.EXPLOITCRITICAL 9.8EPSS 6.21%23 May 2019
CVE-2019-6814A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the…EXPLOITCRITICAL 9.8EPSS 36.6%22 May 2019
CVE-2018-7841Schneider Electric U.motion Builder SQL Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 72.7%22 May 2019
CVE-2019-11231An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example).EXPLOITCRITICAL 9.8EPSS 71.6%22 May 2019
CVE-2019-12279Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form).EXPLOITCRITICAL 9.8EPSS 4.22%22 May 2019
CVE-2019-12252In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.EXPLOITMEDIUM 6.5EPSS 8.21%21 May 2019
CVE-2019-12189There is XSS via the SearchN.do search field.EXPLOITMEDIUM 6.1EPSS 5.92%21 May 2019
CVE-2019-8352If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.EXPLOITCRITICAL 9.8EPSS 6.28%20 May 2019
CVE-2019-12185eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component.EXPLOITHIGH 8.8EPSS 17.8%20 May 2019
CVE-2018-16156One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString.EXPLOITHIGH 7.8EPSS 2.56%17 May 2019
CVE-2019-4279IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources.EXPLOITCRITICAL 9.8EPSS 79.9%17 May 2019
CVE-2018-19585GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.EXPLOIT ×2HIGH 7.5EPSS 14.5%17 May 2019
CVE-2019-8937HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.EXPLOITMEDIUM 6.1EPSS 10.6%17 May 2019
CVE-2019-8929XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.EXPLOITMEDIUM 6.1EPSS 11.2%17 May 2019
CVE-2019-8928XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.EXPLOITMEDIUM 6.1EPSS 6.31%17 May 2019
CVE-2019-8927XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource, selectDeviceDone,…EXPLOITMEDIUM 6.1EPSS 6.35%17 May 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.