Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 49 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-9622 | eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file. | EXPLOITMEDIUM 4.3EPSS 4.80% | 7 March 2019 |
| CVE-2019-9601 | The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestAuthorization requests. | EXPLOIT ✓HIGH 7.5EPSS 8.30% | 6 March 2019 |
| CVE-2019-9600 | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets. | EXPLOITHIGH 7.5EPSS 8.30% | 6 March 2019 |
| CVE-2019-9599 | The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests. | EXPLOITHIGH 7.5EPSS 13.3% | 6 March 2019 |
| CVE-2019-9593 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | EXPLOITMEDIUM 6.1EPSS 4.42% | 6 March 2019 |
| CVE-2019-9592 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | EXPLOITMEDIUM 6.1EPSS 5.30% | 6 March 2019 |
| CVE-2019-9591 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter. | EXPLOITMEDIUM 6.1EPSS 5.33% | 6 March 2019 |
| CVE-2019-9581 | phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension. | EXPLOIT ×2HIGH 8.8EPSS 13.5% | 6 March 2019 |
| CVE-2019-0604 | Microsoft SharePoint Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 99.9% | 5 March 2019 |
| CVE-2019-9213 | In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. | EXPLOIT ×2 ✓MEDIUM 5.5EPSS 5.67% | 5 March 2019 |
| CVE-2019-3921 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. | EXPLOITHIGH 8.8EPSS 17.9% | 5 March 2019 |
| CVE-2019-6225 | A memory corruption issue was addressed with improved validation. | EXPLOIT ✓HIGH 7.8EPSS 28.8% | 5 March 2019 |
| CVE-2019-6224 | A buffer overflow issue was addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 8.97% | 5 March 2019 |
| CVE-2019-6218 | A memory corruption issue was addressed with improved input validation. | EXPLOIT ✓HIGH 7.8EPSS 5.50% | 5 March 2019 |
| CVE-2019-6215 | Processing maliciously crafted web content may lead to arbitrary code execution. | EXPLOITHIGH 8.8EPSS 9.75% | 5 March 2019 |
| CVE-2019-6214 | A malicious application may be able to break out of its sandbox. | EXPLOIT ✓HIGH 8.6EPSS 3.64% | 5 March 2019 |
| CVE-2019-6213 | A buffer overflow was addressed with improved bounds checking. | EXPLOIT ✓HIGH 7.8EPSS 5.42% | 5 March 2019 |
| CVE-2019-6209 | An out-of-bounds read issue existed that led to the disclosure of kernel memory. | EXPLOIT ✓MEDIUM 5.5EPSS 3.69% | 5 March 2019 |
| CVE-2019-6208 | A malicious application may cause unexpected changes in memory shared between processes. | EXPLOIT ✓MEDIUM 5.5EPSS 3.42% | 5 March 2019 |
| CVE-2019-6205 | A memory corruption issue was addressed with improved lock state checking. | EXPLOIT ✓HIGH 7.8EPSS 4.06% | 5 March 2019 |
| CVE-2019-1674 | A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. | EXPLOITHIGH 8.8EPSS 10.8% | 28 February 2019 |
| CVE-2019-1663 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute… | EXPLOIT ×3 ✓CRITICAL 9.8EPSS 95.7% | 28 February 2019 |
| CVE-2019-2000 | In several functions of binder.c, there is possible memory corruption due to a use after free. | EXPLOIT ✓HIGH 7.8EPSS 0.68% | 28 February 2019 |
| CVE-2019-1999 | In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. | EXPLOIT ✓HIGH 7.8EPSS 0.81% | 28 February 2019 |
| CVE-2019-9194 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 96.7% | 26 February 2019 |
| CVE-2019-9184 | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter. | EXPLOIT ✓CRITICAL 9.8EPSS 8.98% | 26 February 2019 |
| CVE-2019-9162 | In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local… | EXPLOIT ✓HIGH 7.8EPSS 1.09% | 25 February 2019 |
| CVE-2019-9082 | ThinkPHP Remote Code Execution Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.8EPSS 97.4% | 24 February 2019 |
| CVE-2019-8375 | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of… | EXPLOITCRITICAL 9.8EPSS 16.1% | 24 February 2019 |
| CVE-2019-9041 | In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring. | EXPLOITHIGH 7.2EPSS 31.4% | 23 February 2019 |
| CVE-2014-10079 | In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash. | EXPLOITMEDIUM 5.3EPSS 8.75% | 23 February 2019 |
| CVE-2014-10078 | Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php. | EXPLOITMEDIUM 6.1EPSS 3.25% | 23 February 2019 |
| CVE-2019-6340 | Drupal Core Remote Code Execution Vulnerability | KEVEXPLOIT ×3 ✓HIGH 8.1EPSS 92.0% | 21 February 2019 |
| CVE-2019-8982 | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF. | EXPLOITCRITICAL 9.6EPSS 28.0% | 21 February 2019 |
| CVE-2019-3475 | A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. | EXPLOIT ✓HIGH 7.8EPSS 0.99% | 20 February 2019 |
| CVE-2019-3474 | A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. | EXPLOIT ✓MEDIUM 6.5EPSS 8.95% | 20 February 2019 |
| CVE-2019-3924 | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. | EXPLOIT ✓HIGH 7.5EPSS 15.7% | 20 February 2019 |
| CVE-2019-8953 | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php. | EXPLOITMEDIUM 6.1EPSS 52.2% | 20 February 2019 |
| CVE-2019-8943 | WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 92.6% | 20 February 2019 |
| CVE-2019-8942 | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. | EXPLOIT ×2 ✓HIGH 8.8EPSS 82.7% | 20 February 2019 |
| CVE-2019-6453 | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. | EXPLOITHIGH 8.1EPSS 54.3% | 18 February 2019 |
| CVE-2018-20782 | The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. | EXPLOITHIGH 7.5EPSS 10.0% | 17 February 2019 |
| CVE-2019-8394 | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | KEVEXPLOITMEDIUM 6.5EPSS 63.3% | 17 February 2019 |
| CVE-2019-6974 | In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. | EXPLOIT ✓HIGH 8.1EPSS 16.5% | 15 February 2019 |
| CVE-2019-8341 | The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. | EXPLOITCRITICAL 9.8EPSS 44.8% | 15 February 2019 |
| CVE-2019-6545 | An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine. | EXPLOITHIGH 7.5EPSS 13.9% | 13 February 2019 |
| CVE-2019-6543 | Code is executed under the program runtime privileges, which could lead to the compromise of the machine. | EXPLOITCRITICAL 9.8EPSS 17.3% | 13 February 2019 |
| CVE-2019-5596 | In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released… | EXPLOIT ×2 ✓HIGH 8.8EPSS 1.23% | 12 February 2019 |
| CVE-2019-5736 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of… | EXPLOIT ×2HIGH 8.6EPSS 98.5% | 11 February 2019 |
| CVE-2018-20250 | WinRAR Absolute Path Traversal Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.8EPSS 96.3% | 5 February 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.