Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 45 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-8926 | XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource. | EXPLOITMEDIUM 6.1EPSS 6.31% | 17 May 2019 |
| CVE-2019-8925 | An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via… | EXPLOITMEDIUM 4.3EPSS 11.6% | 17 May 2019 |
| CVE-2019-8924 | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. | EXPLOITMEDIUM 6.1EPSS 5.67% | 17 May 2019 |
| CVE-2019-0881 | An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 2.64% | 16 May 2019 |
| CVE-2019-0863 | Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 5.21% | 16 May 2019 |
| CVE-2019-0708 | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | KEVEXPLOIT ×4 ✓CRITICAL 9.8EPSS 100.0% | 16 May 2019 |
| CVE-2019-12137 | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | EXPLOITHIGH 7.8EPSS 6.45% | 16 May 2019 |
| CVE-2019-1821 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying… | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 98.1% | 16 May 2019 |
| CVE-2013-7285 | Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported… | EXPLOITCRITICAL 9.8EPSS 84.4% | 15 May 2019 |
| CVE-2019-5526 | VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. | EXPLOIT ✓HIGH 7.8EPSS 9.03% | 15 May 2019 |
| CVE-2019-12099 | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during… | EXPLOITHIGH 8.8EPSS 17.2% | 14 May 2019 |
| CVE-2019-11419 | vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted… | EXPLOITMEDIUM 5.5EPSS 4.03% | 14 May 2019 |
| CVE-2019-8923 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. | EXPLOITCRITICAL 9.8EPSS 3.90% | 14 May 2019 |
| CVE-2019-8404 | The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. | EXPLOITMEDIUM 6.5EPSS 7.87% | 14 May 2019 |
| CVE-2019-8391 | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. | EXPLOITMEDIUM 6.1EPSS 3.34% | 14 May 2019 |
| CVE-2019-8390 | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter. | EXPLOITMEDIUM 6.1EPSS 9.84% | 14 May 2019 |
| CVE-2018-18800 | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php. | EXPLOITCRITICAL 9.8EPSS 3.21% | 14 May 2019 |
| CVE-2019-9618 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. | EXPLOITCRITICAL 9.8EPSS 43.8% | 13 May 2019 |
| CVE-2019-11600 | A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 8.1EPSS 80.0% | 13 May 2019 |
| CVE-2019-11429 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen. | EXPLOITMEDIUM 4.8EPSS 5.80% | 13 May 2019 |
| CVE-2019-7652 | TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. | EXPLOIT ✓HIGH 7.7EPSS 5.06% | 9 May 2019 |
| CVE-2019-11563 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 9 May 2019 |
| CVE-2019-7181 | Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program. | EXPLOITHIGH 7.5EPSS 9.80% | 9 May 2019 |
| CVE-2019-7442 | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML… | EXPLOITCRITICAL 9.8EPSS 40.0% | 8 May 2019 |
| CVE-2019-11398 | Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error… | EXPLOIT ×2MEDIUM 6.1EPSS 3.47% | 8 May 2019 |
| CVE-2019-11510 | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 100.0% | 8 May 2019 |
| CVE-2019-11564 | A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request. | EXPLOITMEDIUM 6.1EPSS 2.63% | 8 May 2019 |
| CVE-2019-8387 | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | EXPLOITCRITICAL 9.8EPSS 55.7% | 8 May 2019 |
| CVE-2019-7541 | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. | EXPLOITMEDIUM 6.1EPSS 3.24% | 7 May 2019 |
| CVE-2018-20503 | Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. | EXPLOITMEDIUM 6.1EPSS 3.90% | 7 May 2019 |
| CVE-2018-14485 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | EXPLOITCRITICAL 9.8EPSS 16.3% | 7 May 2019 |
| CVE-2019-11569 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. | EXPLOITHIGH 8.8EPSS 2.28% | 6 May 2019 |
| CVE-2019-5434 | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. | EXPLOITCRITICAL 9.8EPSS 57.0% | 6 May 2019 |
| CVE-2019-3799 | Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. | EXPLOITMEDIUM 6.5EPSS 85.3% | 6 May 2019 |
| CVE-2018-20580 | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | EXPLOITHIGH 8.8EPSS 9.79% | 3 May 2019 |
| CVE-2019-9017 | DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. | EXPLOITHIGH 7.5EPSS 20.6% | 2 May 2019 |
| CVE-2019-0227 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. | EXPLOITHIGH 7.5EPSS 91.9% | 1 May 2019 |
| CVE-2019-11631 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 1 May 2019 |
| CVE-2019-3929 | Crestron Multiple Products Command Injection Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.0% | 30 April 2019 |
| CVE-2019-11193 | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel. | EXPLOITMEDIUM 6.1EPSS 2.09% | 30 April 2019 |
| CVE-2019-9621 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.5EPSS 81.0% | 30 April 2019 |
| CVE-2018-19374 | Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory. | EXPLOITHIGH 7.0EPSS 1.08% | 30 April 2019 |
| CVE-2019-11599 | The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or… | EXPLOIT ✓HIGH 7.0EPSS 0.99% | 29 April 2019 |
| CVE-2019-3844 | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. | EXPLOIT ✓HIGH 7.8EPSS 0.92% | 26 April 2019 |
| CVE-2019-3843 | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. | EXPLOIT ✓HIGH 7.8EPSS 0.94% | 26 April 2019 |
| CVE-2019-2725 | Oracle WebLogic Server, Injection | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 100.0% | 26 April 2019 |
| CVE-2019-9813 | Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. | EXPLOIT ✓HIGH 8.8EPSS 7.39% | 26 April 2019 |
| CVE-2019-9810 | Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. | EXPLOIT ×2HIGH 8.8EPSS 29.7% | 26 April 2019 |
| CVE-2019-9792 | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. | EXPLOIT ✓CRITICAL 9.8EPSS 13.2% | 26 April 2019 |
| CVE-2019-9791 | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack… | EXPLOIT ✓CRITICAL 9.8EPSS 19.9% | 26 April 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.