Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 47 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0808 | Microsoft Win32k Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 53.0% | 9 April 2019 |
| CVE-2019-0768 | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security… | EXPLOIT ✓MEDIUM 4.3EPSS 48.5% | 9 April 2019 |
| CVE-2019-0667 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | EXPLOIT ✓HIGH 7.5EPSS 31.3% | 8 April 2019 |
| CVE-2019-0612 | A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. | EXPLOIT ✓MEDIUM 5.3EPSS 10.5% | 8 April 2019 |
| CVE-2019-0211 | Apache HTTP Server Privilege Escalation Vulnerability | KEVEXPLOITHIGH 7.8EPSS 65.0% | 8 April 2019 |
| CVE-2019-10887 | A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmLog.csv?log= or /waitlog.cgi?name=… | EXPLOITMEDIUM 6.1EPSS 5.82% | 5 April 2019 |
| CVE-2019-10874 | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration… | EXPLOITHIGH 8.8EPSS 4.52% | 5 April 2019 |
| CVE-2019-10867 | An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to… | EXPLOIT ✓HIGH 8.8EPSS 68.9% | 4 April 2019 |
| CVE-2019-10863 | A command injection vulnerability exists in TeemIp versions before 2.4.0. | EXPLOITHIGH 7.2EPSS 13.4% | 4 April 2019 |
| CVE-2019-10273 | Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. | EXPLOITMEDIUM 4.3EPSS 7.64% | 4 April 2019 |
| CVE-2018-4443 | A memory corruption issue was addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 5.85% | 3 April 2019 |
| CVE-2018-4442 | A memory corruption issue was addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 5.83% | 3 April 2019 |
| CVE-2018-4441 | A memory corruption issue was addressed with improved memory handling. | EXPLOIT ×2 ✓HIGH 8.8EPSS 12.7% | 3 April 2019 |
| CVE-2018-4438 | A logic issue existed resulting in memory corruption. | EXPLOIT ✓HIGH 8.8EPSS 5.83% | 3 April 2019 |
| CVE-2018-4435 | A logic issue was addressed with improved restrictions. | EXPLOIT ✓HIGH 7.8EPSS 3.09% | 3 April 2019 |
| CVE-2018-4416 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 34.2% | 3 April 2019 |
| CVE-2018-4386 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ×2 ✓HIGH 8.8EPSS 6.49% | 3 April 2019 |
| CVE-2018-4384 | A memory corruption issue was addressed with improved input validation. | EXPLOIT ✓HIGH 7.8EPSS 2.76% | 3 April 2019 |
| CVE-2018-4382 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 5.83% | 3 April 2019 |
| CVE-2018-4367 | A memory corruption issue was addressed with improved input validation. | EXPLOIT ✓CRITICAL 9.8EPSS 6.50% | 3 April 2019 |
| CVE-2018-4366 | A memory corruption issue was addressed with improved input validation. | EXPLOIT ✓HIGH 7.5EPSS 6.45% | 3 April 2019 |
| CVE-2018-4328 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 9.65% | 3 April 2019 |
| CVE-2018-4323 | Multiple memory corruption issues were addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 9.61% | 3 April 2019 |
| CVE-2018-4318 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.35% | 3 April 2019 |
| CVE-2018-4317 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.35% | 3 April 2019 |
| CVE-2018-4315 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.39% | 3 April 2019 |
| CVE-2018-4314 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 10.3% | 3 April 2019 |
| CVE-2018-4312 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.35% | 3 April 2019 |
| CVE-2018-4306 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.35% | 3 April 2019 |
| CVE-2018-4197 | A use after free issue was addressed with improved memory management. | EXPLOIT ✓HIGH 8.8EPSS 9.39% | 3 April 2019 |
| CVE-2019-10261 | CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action. | EXPLOITMEDIUM 4.8EPSS 2.34% | 3 April 2019 |
| CVE-2019-9193 | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. | EXPLOIT ✓HIGH 7.2EPSS 91.7% | 1 April 2019 |
| CVE-2018-19113 | The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows… | EXPLOITHIGH 7.3EPSS 0.85% | 1 April 2019 |
| CVE-2019-10678 | Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. | EXPLOIT ✓HIGH 7.5EPSS 17.3% | 31 March 2019 |
| CVE-2019-10664 | Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. | EXPLOIT ✓CRITICAL 9.8EPSS 8.19% | 31 March 2019 |
| CVE-2019-10652 | An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature. | EXPLOITHIGH 7.2EPSS 6.96% | 30 March 2019 |
| CVE-2019-5420 | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. | EXPLOIT ✓CRITICAL 9.8EPSS 92.1% | 27 March 2019 |
| CVE-2019-5418 | Rails Ruby on Rails Path Traversal Vulnerability | KEVEXPLOITHIGH 7.5EPSS 98.5% | 27 March 2019 |
| CVE-2019-9053 | It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter. | EXPLOITHIGH 8.1EPSS 68.6% | 26 March 2019 |
| CVE-2019-7646 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter. | EXPLOITMEDIUM 4.8EPSS 7.12% | 26 March 2019 |
| CVE-2019-3396 | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | KEVEXPLOIT ×2 ✓CRITICAL 9.8EPSS 99.9% | 25 March 2019 |
| CVE-2018-12653 | A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. | EXPLOITMEDIUM 6.1EPSS 2.61% | 25 March 2019 |
| CVE-2019-3810 | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. | EXPLOITMEDIUM 6.1EPSS 13.9% | 25 March 2019 |
| CVE-2018-16858 | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. | EXPLOIT ✓CRITICAL 9.8EPSS 67.3% | 25 March 2019 |
| CVE-2019-9978 | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | KEVEXPLOIT ×2MEDIUM 6.1EPSS 72.9% | 24 March 2019 |
| CVE-2019-9649 | Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date. | EXPLOITMEDIUM 5.3EPSS 14.5% | 22 March 2019 |
| CVE-2019-9648 | A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information. | EXPLOITMEDIUM 5.3EPSS 14.3% | 22 March 2019 |
| CVE-2019-9083 | SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. | EXPLOITCRITICAL 9.8EPSS 17.6% | 21 March 2019 |
| CVE-2019-7441 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. | EXPLOITMEDIUM 6.5EPSS 5.94% | 21 March 2019 |
| CVE-2019-7440 | JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi). | EXPLOITMEDIUM 6.5EPSS 1.96% | 21 March 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.