SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 48 of 501

CVESummaryPriorityPublished
CVE-2019-7439cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.EXPLOITMEDIUM 6.5EPSS 4.77%21 March 2019
CVE-2019-7438cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.EXPLOITMEDIUM 6.1EPSS 3.99%21 March 2019
CVE-2019-7391ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.EXPLOITHIGH 8.8EPSS 13.6%21 March 2019
CVE-2019-7385An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and…EXPLOITHIGH 7.8EPSS 12.2%21 March 2019
CVE-2019-6973Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.EXPLOITHIGH 7.5EPSS 13.8%21 March 2019
CVE-2019-6967AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.EXPLOITHIGH 8.8EPSS 13.5%21 March 2019
CVE-2019-6716An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs…EXPLOITCRITICAL 9.4EPSS 9.64%21 March 2019
CVE-2019-6714A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem.EXPLOITCRITICAL 9.8EPSS 31.7%21 March 2019
CVE-2019-6441By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.EXPLOITCRITICAL 9.8EPSS 53.6%21 March 2019
CVE-2019-6282ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.EXPLOITHIGH 8.8EPSS 3.04%21 March 2019
CVE-2019-6279ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security…EXPLOITHIGH 8.8EPSS 7.53%21 March 2019
CVE-2019-6275Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.EXPLOITHIGH 8.8EPSS 12.5%21 March 2019
CVE-2019-6274Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.EXPLOITHIGH 8.8EPSS 11.2%21 March 2019
CVE-2019-6273download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.EXPLOITMEDIUM 6.5EPSS 11.5%21 March 2019
CVE-2019-6272Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.EXPLOITHIGH 8.8EPSS 12.5%21 March 2019
CVE-2019-6116In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.EXPLOITHIGH 7.8EPSS 41.6%21 March 2019
CVE-2019-5722Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.EXPLOITCRITICAL 9.8EPSS 3.90%21 March 2019
CVE-2018-20556SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.EXPLOITHIGH 8.8EPSS 18.9%21 March 2019
CVE-2018-20526Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.EXPLOITCRITICAL 9.8EPSS 73.1%21 March 2019
CVE-2018-20525Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.EXPLOITCRITICAL 9.1EPSS 21.6%21 March 2019
CVE-2018-20221Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user.EXPLOITHIGH 8.8EPSS 10.3%21 March 2019
CVE-2018-20220While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication.EXPLOITHIGH 7.5EPSS 15.4%21 March 2019
CVE-2018-20219This token is hard-coded to a string in the source code (/usr/share/www/check.lp file).EXPLOITHIGH 8.1EPSS 14.6%21 March 2019
CVE-2018-20218An attacker is able to perform command injection using the "password" parameter in the login form.EXPLOITCRITICAL 9.8EPSS 10.7%21 March 2019
CVE-2018-19524A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.EXPLOITCRITICAL 9.8EPSS 50.5%21 March 2019
CVE-2018-19276OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.EXPLOIT ×2CRITICAL 9.8EPSS 98.7%21 March 2019
CVE-2018-18798Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.EXPLOITCRITICAL 9.8EPSS 3.21%21 March 2019
CVE-2018-18762SaltOS 3.1 r8126 contains a database download vulnerability.EXPLOITMEDIUM 6.5EPSS 6.19%21 March 2019
CVE-2018-18435KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders.EXPLOITHIGH 7.8EPSS 1.38%21 March 2019
CVE-2018-17997LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).EXPLOITMEDIUM 6.1EPSS 3.58%21 March 2019
CVE-2018-17996LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.EXPLOITMEDIUM 6.5EPSS 3.01%21 March 2019
CVE-2018-14575Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.EXPLOITHIGH 8.8EPSS 2.38%21 March 2019
CVE-2018-10093AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.EXPLOITHIGH 8.8EPSS 68.2%21 March 2019
CVE-2019-9834The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection.EXPLOITMEDIUM 6.1EPSS 5.10%15 March 2019
CVE-2019-9833The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous /start-stop requests.EXPLOITHIGH 7.5EPSS 8.82%15 March 2019
CVE-2019-9832The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections through a configured port.EXPLOITHIGH 7.5EPSS 8.30%15 March 2019
CVE-2019-9831The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via many simultaneous /?Key=PhoneRequestAuthorization requests.EXPLOITHIGH 7.5EPSS 9.01%15 March 2019
CVE-2019-9769PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.EXPLOITHIGH 8.8EPSS 2.28%14 March 2019
CVE-2019-9768Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.EXPLOITHIGH 7.5EPSS 11.7%14 March 2019
CVE-2019-9767Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wma file.EXPLOITHIGH 7.8EPSS 7.99%14 March 2019
CVE-2019-9766Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .mp3 file.EXPLOITHIGH 7.8EPSS 7.96%14 March 2019
CVE-2019-9760FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses.EXPLOITCRITICAL 9.8EPSS 53.1%14 March 2019
CVE-2019-9692class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).EXPLOIT ×2MEDIUM 6.5EPSS 45.9%11 March 2019
CVE-2019-9650An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.EXPLOITMEDIUM 6.1EPSS 3.39%11 March 2019
CVE-2019-1003030Jenkins Matrix Project Plugin Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.9EPSS 96.9%8 March 2019
CVE-2019-6710Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.EXPLOITHIGH 8.8EPSS 2.97%7 March 2019
CVE-2019-3778Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code.EXPLOITMEDIUM 6.5EPSS 15.5%7 March 2019
CVE-2019-9625JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.EXPLOITHIGH 8.8EPSS 2.44%7 March 2019
CVE-2019-9624Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.EXPLOITHIGH 7.8EPSS 23.7%7 March 2019
CVE-2019-9623Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.EXPLOITCRITICAL 9.8EPSS 8.12%7 March 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.