SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 46 of 501

CVESummaryPriorityPublished
CVE-2019-0186The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks.EXPLOITMEDIUM 6.1EPSS 20.6%26 April 2019
CVE-2019-11539Ivanti Pulse Connect Secure and Policy Secure Command Injection VulnerabilityKEVEXPLOIT ×2HIGH 7.2EPSS 98.5%26 April 2019
CVE-2019-11537In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an…EXPLOITMEDIUM 6.1EPSS 4.62%25 April 2019
CVE-2019-11504Zotonic before version 0.47 has mod_admin XSS.EXPLOITMEDIUM 4.8EPSS 2.49%24 April 2019
CVE-2018-20434LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a…EXPLOIT ×2CRITICAL 9.8EPSS 71.5%24 April 2019
CVE-2019-10008Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an…EXPLOITHIGH 8.8EPSS 19.4%24 April 2019
CVE-2019-7214SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.EXPLOITCRITICAL 9.8EPSS 84.8%24 April 2019
CVE-2019-2721Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).EXPLOITHIGH 8.8EPSS 2.15%23 April 2019
CVE-2019-2698Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D).EXPLOITHIGH 8.1EPSS 12.0%23 April 2019
CVE-2019-2697Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D).EXPLOITHIGH 8.1EPSS 11.5%23 April 2019
CVE-2019-2616Oracle BI Publisher Unauthorized Access VulnerabilityKEVEXPLOITHIGH 7.2EPSS 92.2%23 April 2019
CVE-2019-2588Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).EXPLOITMEDIUM 4.9EPSS 36.8%23 April 2019
CVE-2019-7304Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root.EXPLOIT ×2CRITICAL 9.8EPSS 60.8%23 April 2019
CVE-2019-7303A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host.EXPLOITHIGH 7.5EPSS 3.70%23 April 2019
CVE-2019-11469Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection.EXPLOITCRITICAL 9.8EPSS 17.0%23 April 2019
CVE-2019-8452Doing this on files with limited access gains the local attacker higher privileges to the file.EXPLOITHIGH 7.8EPSS 1.04%22 April 2019
CVE-2019-9955On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via…EXPLOITMEDIUM 6.1EPSS 21.2%22 April 2019
CVE-2019-11448An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability.EXPLOITCRITICAL 9.8EPSS 12.4%22 April 2019
CVE-2019-11447An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal.EXPLOIT ×2HIGH 8.8EPSS 52.3%22 April 2019
CVE-2019-11446It allows the user to run commands on the server with the teacher user privilege.EXPLOITHIGH 8.8EPSS 7.80%22 April 2019
CVE-2019-11445OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileUpload and admin/repository_export.jsp.EXPLOITHIGH 7.2EPSS 14.2%22 April 2019
CVE-2019-11444An attacker can use Liferay's Groovy script console to execute OS commands.EXPLOITHIGH 7.2EPSS 12.6%22 April 2019
CVE-2019-11416A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.EXPLOITHIGH 8.8EPSS 3.89%22 April 2019
CVE-2019-11415A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.EXPLOITHIGH 7.5EPSS 13.7%22 April 2019
CVE-2019-11375Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.EXPLOITMEDIUM 6.5EPSS 2.62%20 April 2019
CVE-2019-1137474CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.EXPLOITHIGH 8.8EPSS 9.85%20 April 2019
CVE-2019-11358jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution.EXPLOITMEDIUM 6.1EPSS 87.2%20 April 2019
CVE-2019-11354The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.EXPLOITHIGH 7.8EPSS 23.1%19 April 2019
CVE-2019-10893CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen.EXPLOITMEDIUM 4.8EPSS 2.83%18 April 2019
CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal VulnerabilityKEVEXPLOITHIGH 8.8EPSS 96.8%18 April 2019
CVE-2019-11017On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.EXPLOITMEDIUM 4.8EPSS 1.49%18 April 2019
CVE-2019-0232When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to…EXPLOITHIGH 8.1EPSS 99.7%15 April 2019
CVE-2019-11229models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.EXPLOITHIGH 8.8EPSS 55.0%15 April 2019
CVE-2019-0285The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker.EXPLOITCRITICAL 9.8EPSS 6.61%10 April 2019
CVE-2019-10945The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.EXPLOITCRITICAL 9.8EPSS 38.0%10 April 2019
CVE-2019-4013IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges.EXPLOITCRITICAL 9.9EPSS 13.9%10 April 2019
CVE-2019-10843Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.EXPLOITUnscoredEPSS —10 April 2019
CVE-2019-3842It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".EXPLOITHIGH 7.0EPSS 1.21%9 April 2019
CVE-2019-0841Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityKEVEXPLOIT ×4HIGH 7.8EPSS 41.4%9 April 2019
CVE-2019-0836An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 4.30%9 April 2019
CVE-2019-0805An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 2.79%9 April 2019
CVE-2019-0803Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 45.0%9 April 2019
CVE-2019-0796An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITMEDIUM 5.5EPSS 4.24%9 April 2019
CVE-2019-0752Microsoft Internet Explorer Type Confusion VulnerabilityKEVEXPLOITHIGH 7.5EPSS 81.6%9 April 2019
CVE-2019-0735An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 3.66%9 April 2019
CVE-2019-0732A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.EXPLOITHIGH 7.8EPSS 3.78%9 April 2019
CVE-2019-0731An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 4.35%9 April 2019
CVE-2019-0730An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.EXPLOITHIGH 7.8EPSS 4.35%9 April 2019
CVE-2019-5512Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation of privilege.EXPLOITHIGH 8.8EPSS 1.23%9 April 2019
CVE-2018-14894CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications.EXPLOITHIGH 7.8EPSS 1.93%9 April 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.