SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 47 of 501

CVESummaryPriorityPublished
CVE-2019-0808Microsoft Win32k Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 53.0%9 April 2019
CVE-2019-0768A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security…EXPLOITMEDIUM 4.3EPSS 48.5%9 April 2019
CVE-2019-0667A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.EXPLOITHIGH 7.5EPSS 31.3%8 April 2019
CVE-2019-0612A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects.EXPLOITMEDIUM 5.3EPSS 10.5%8 April 2019
CVE-2019-0211Apache HTTP Server Privilege Escalation VulnerabilityKEVEXPLOITHIGH 7.8EPSS 65.0%8 April 2019
CVE-2019-10887A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmLog.csv?log= or /waitlog.cgi?name=…EXPLOITMEDIUM 6.1EPSS 5.82%5 April 2019
CVE-2019-10874Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration…EXPLOITHIGH 8.8EPSS 4.52%5 April 2019
CVE-2019-10867An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…EXPLOITHIGH 8.8EPSS 68.9%4 April 2019
CVE-2019-10863A command injection vulnerability exists in TeemIp versions before 2.4.0.EXPLOITHIGH 7.2EPSS 13.4%4 April 2019
CVE-2019-10273Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users.EXPLOITMEDIUM 4.3EPSS 7.64%4 April 2019
CVE-2018-4443A memory corruption issue was addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 5.85%3 April 2019
CVE-2018-4442A memory corruption issue was addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 5.83%3 April 2019
CVE-2018-4441A memory corruption issue was addressed with improved memory handling.EXPLOIT ×2HIGH 8.8EPSS 12.7%3 April 2019
CVE-2018-4438A logic issue existed resulting in memory corruption.EXPLOITHIGH 8.8EPSS 5.83%3 April 2019
CVE-2018-4435A logic issue was addressed with improved restrictions.EXPLOITHIGH 7.8EPSS 3.09%3 April 2019
CVE-2018-4416Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 34.2%3 April 2019
CVE-2018-4386Multiple memory corruption issues were addressed with improved memory handling.EXPLOIT ×2HIGH 8.8EPSS 6.49%3 April 2019
CVE-2018-4384A memory corruption issue was addressed with improved input validation.EXPLOITHIGH 7.8EPSS 2.76%3 April 2019
CVE-2018-4382Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 5.83%3 April 2019
CVE-2018-4367A memory corruption issue was addressed with improved input validation.EXPLOITCRITICAL 9.8EPSS 6.50%3 April 2019
CVE-2018-4366A memory corruption issue was addressed with improved input validation.EXPLOITHIGH 7.5EPSS 6.45%3 April 2019
CVE-2018-4328Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 9.65%3 April 2019
CVE-2018-4323Multiple memory corruption issues were addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 9.61%3 April 2019
CVE-2018-4318A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.35%3 April 2019
CVE-2018-4317A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.35%3 April 2019
CVE-2018-4315A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.39%3 April 2019
CVE-2018-4314A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 10.3%3 April 2019
CVE-2018-4312A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.35%3 April 2019
CVE-2018-4306A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.35%3 April 2019
CVE-2018-4197A use after free issue was addressed with improved memory management.EXPLOITHIGH 8.8EPSS 9.39%3 April 2019
CVE-2019-10261CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.EXPLOITMEDIUM 4.8EPSS 2.34%3 April 2019
CVE-2019-9193In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user.EXPLOITHIGH 7.2EPSS 91.7%1 April 2019
CVE-2018-19113The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows…EXPLOITHIGH 7.3EPSS 0.85%1 April 2019
CVE-2019-10678Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.EXPLOITHIGH 7.5EPSS 17.3%31 March 2019
CVE-2019-10664Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.EXPLOITCRITICAL 9.8EPSS 8.19%31 March 2019
CVE-2019-10652An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.EXPLOITHIGH 7.2EPSS 6.96%30 March 2019
CVE-2019-5420A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token.EXPLOITCRITICAL 9.8EPSS 92.1%27 March 2019
CVE-2019-5418Rails Ruby on Rails Path Traversal VulnerabilityKEVEXPLOITHIGH 7.5EPSS 98.5%27 March 2019
CVE-2019-9053It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.EXPLOITHIGH 8.1EPSS 68.6%26 March 2019
CVE-2019-7646CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.EXPLOITMEDIUM 4.8EPSS 7.12%26 March 2019
CVE-2019-3396Atlassian Confluence Server and Data Center Server-Side Template Injection VulnerabilityKEVEXPLOIT ×2CRITICAL 9.8EPSS 99.9%25 March 2019
CVE-2018-12653A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0.EXPLOITMEDIUM 6.1EPSS 2.61%25 March 2019
CVE-2019-3810A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions.EXPLOITMEDIUM 6.1EPSS 13.9%25 March 2019
CVE-2018-16858It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document.EXPLOITCRITICAL 9.8EPSS 67.3%25 March 2019
CVE-2019-9978WordPress Social Warfare Plugin Cross-Site Scripting (XSS) VulnerabilityKEVEXPLOIT ×2MEDIUM 6.1EPSS 72.9%24 March 2019
CVE-2019-9649Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.EXPLOITMEDIUM 5.3EPSS 14.5%22 March 2019
CVE-2019-9648A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.EXPLOITMEDIUM 5.3EPSS 14.3%22 March 2019
CVE-2019-9083SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter.EXPLOITCRITICAL 9.8EPSS 17.6%21 March 2019
CVE-2019-7441cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price.EXPLOITMEDIUM 6.5EPSS 5.94%21 March 2019
CVE-2019-7440JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).EXPLOITMEDIUM 6.5EPSS 1.96%21 March 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.