Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 46 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0186 | The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. | EXPLOITMEDIUM 6.1EPSS 20.6% | 26 April 2019 |
| CVE-2019-11539 | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.2EPSS 98.5% | 26 April 2019 |
| CVE-2019-11537 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an… | EXPLOIT ✓MEDIUM 6.1EPSS 4.62% | 25 April 2019 |
| CVE-2019-11504 | Zotonic before version 0.47 has mod_admin XSS. | EXPLOITMEDIUM 4.8EPSS 2.49% | 24 April 2019 |
| CVE-2018-20434 | LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a… | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 71.5% | 24 April 2019 |
| CVE-2019-10008 | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an… | EXPLOITHIGH 8.8EPSS 19.4% | 24 April 2019 |
| CVE-2019-7214 | SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. | EXPLOITCRITICAL 9.8EPSS 84.8% | 24 April 2019 |
| CVE-2019-2721 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). | EXPLOIT ✓HIGH 8.8EPSS 2.15% | 23 April 2019 |
| CVE-2019-2698 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). | EXPLOIT ✓HIGH 8.1EPSS 12.0% | 23 April 2019 |
| CVE-2019-2697 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). | EXPLOIT ✓HIGH 8.1EPSS 11.5% | 23 April 2019 |
| CVE-2019-2616 | Oracle BI Publisher Unauthorized Access Vulnerability | KEVEXPLOIT ✓HIGH 7.2EPSS 92.2% | 23 April 2019 |
| CVE-2019-2588 | Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). | EXPLOIT ✓MEDIUM 4.9EPSS 36.8% | 23 April 2019 |
| CVE-2019-7304 | Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. | EXPLOIT ×2CRITICAL 9.8EPSS 60.8% | 23 April 2019 |
| CVE-2019-7303 | A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. | EXPLOIT ✓HIGH 7.5EPSS 3.70% | 23 April 2019 |
| CVE-2019-11469 | Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. | EXPLOITCRITICAL 9.8EPSS 17.0% | 23 April 2019 |
| CVE-2019-8452 | Doing this on files with limited access gains the local attacker higher privileges to the file. | EXPLOITHIGH 7.8EPSS 1.04% | 22 April 2019 |
| CVE-2019-9955 | On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via… | EXPLOITMEDIUM 6.1EPSS 21.2% | 22 April 2019 |
| CVE-2019-11448 | An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. | EXPLOITCRITICAL 9.8EPSS 12.4% | 22 April 2019 |
| CVE-2019-11447 | An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. | EXPLOIT ×2 ✓HIGH 8.8EPSS 52.3% | 22 April 2019 |
| CVE-2019-11446 | It allows the user to run commands on the server with the teacher user privilege. | EXPLOITHIGH 8.8EPSS 7.80% | 22 April 2019 |
| CVE-2019-11445 | OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileUpload and admin/repository_export.jsp. | EXPLOITHIGH 7.2EPSS 14.2% | 22 April 2019 |
| CVE-2019-11444 | An attacker can use Liferay's Groovy script console to execute OS commands. | EXPLOITHIGH 7.2EPSS 12.6% | 22 April 2019 |
| CVE-2019-11416 | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. | EXPLOITHIGH 8.8EPSS 3.89% | 22 April 2019 |
| CVE-2019-11415 | A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login. | EXPLOITHIGH 7.5EPSS 13.7% | 22 April 2019 |
| CVE-2019-11375 | Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI. | EXPLOITMEDIUM 6.5EPSS 2.62% | 20 April 2019 |
| CVE-2019-11374 | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | EXPLOITHIGH 8.8EPSS 9.85% | 20 April 2019 |
| CVE-2019-11358 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. | EXPLOITMEDIUM 6.1EPSS 87.2% | 20 April 2019 |
| CVE-2019-11354 | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. | EXPLOITHIGH 7.8EPSS 23.1% | 19 April 2019 |
| CVE-2019-10893 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. | EXPLOITMEDIUM 4.8EPSS 2.83% | 18 April 2019 |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | KEVEXPLOITHIGH 8.8EPSS 96.8% | 18 April 2019 |
| CVE-2019-11017 | On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter. | EXPLOITMEDIUM 4.8EPSS 1.49% | 18 April 2019 |
| CVE-2019-0232 | When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to… | EXPLOIT ✓HIGH 8.1EPSS 99.7% | 15 April 2019 |
| CVE-2019-11229 | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | EXPLOIT ✓HIGH 8.8EPSS 55.0% | 15 April 2019 |
| CVE-2019-0285 | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker. | EXPLOITCRITICAL 9.8EPSS 6.61% | 10 April 2019 |
| CVE-2019-10945 | The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory. | EXPLOITCRITICAL 9.8EPSS 38.0% | 10 April 2019 |
| CVE-2019-4013 | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. | EXPLOITCRITICAL 9.9EPSS 13.9% | 10 April 2019 |
| CVE-2019-10843 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. | EXPLOITUnscoredEPSS — | 10 April 2019 |
| CVE-2019-3842 | It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any". | EXPLOIT ✓HIGH 7.0EPSS 1.21% | 9 April 2019 |
| CVE-2019-0841 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | KEVEXPLOIT ×4 ✓HIGH 7.8EPSS 41.4% | 9 April 2019 |
| CVE-2019-0836 | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 4.30% | 9 April 2019 |
| CVE-2019-0805 | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 2.79% | 9 April 2019 |
| CVE-2019-0803 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 45.0% | 9 April 2019 |
| CVE-2019-0796 | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. | EXPLOIT ✓MEDIUM 5.5EPSS 4.24% | 9 April 2019 |
| CVE-2019-0752 | Microsoft Internet Explorer Type Confusion Vulnerability | KEVEXPLOITHIGH 7.5EPSS 81.6% | 9 April 2019 |
| CVE-2019-0735 | An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 3.66% | 9 April 2019 |
| CVE-2019-0732 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 3.78% | 9 April 2019 |
| CVE-2019-0731 | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 4.35% | 9 April 2019 |
| CVE-2019-0730 | An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. | EXPLOIT ✓HIGH 7.8EPSS 4.35% | 9 April 2019 |
| CVE-2019-5512 | Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation of privilege. | EXPLOIT ✓HIGH 8.8EPSS 1.23% | 9 April 2019 |
| CVE-2018-14894 | CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications. | EXPLOITHIGH 7.8EPSS 1.93% | 9 April 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.