SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

25,049 results · page 49 of 501

CVESummaryPriorityPublished
CVE-2019-9622eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file.EXPLOITMEDIUM 4.3EPSS 4.80%7 March 2019
CVE-2019-9601The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestAuthorization requests.EXPLOITHIGH 7.5EPSS 8.30%6 March 2019
CVE-2019-9600The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets.EXPLOITHIGH 7.5EPSS 8.30%6 March 2019
CVE-2019-9599The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.EXPLOITHIGH 7.5EPSS 13.3%6 March 2019
CVE-2019-9593A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.EXPLOITMEDIUM 6.1EPSS 4.42%6 March 2019
CVE-2019-9592A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.EXPLOITMEDIUM 6.1EPSS 5.30%6 March 2019
CVE-2019-9591A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.EXPLOITMEDIUM 6.1EPSS 5.33%6 March 2019
CVE-2019-9581phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.EXPLOIT ×2HIGH 8.8EPSS 13.5%6 March 2019
CVE-2019-0604Microsoft SharePoint Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 99.9%5 March 2019
CVE-2019-9213In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms.EXPLOIT ×2MEDIUM 5.5EPSS 5.67%5 March 2019
CVE-2019-3921The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/.EXPLOITHIGH 8.8EPSS 17.9%5 March 2019
CVE-2019-6225A memory corruption issue was addressed with improved validation.EXPLOITHIGH 7.8EPSS 28.8%5 March 2019
CVE-2019-6224A buffer overflow issue was addressed with improved memory handling.EXPLOITHIGH 8.8EPSS 8.97%5 March 2019
CVE-2019-6218A memory corruption issue was addressed with improved input validation.EXPLOITHIGH 7.8EPSS 5.50%5 March 2019
CVE-2019-6215Processing maliciously crafted web content may lead to arbitrary code execution.EXPLOITHIGH 8.8EPSS 9.75%5 March 2019
CVE-2019-6214A malicious application may be able to break out of its sandbox.EXPLOITHIGH 8.6EPSS 3.64%5 March 2019
CVE-2019-6213A buffer overflow was addressed with improved bounds checking.EXPLOITHIGH 7.8EPSS 5.42%5 March 2019
CVE-2019-6209An out-of-bounds read issue existed that led to the disclosure of kernel memory.EXPLOITMEDIUM 5.5EPSS 3.69%5 March 2019
CVE-2019-6208A malicious application may cause unexpected changes in memory shared between processes.EXPLOITMEDIUM 5.5EPSS 3.42%5 March 2019
CVE-2019-6205A memory corruption issue was addressed with improved lock state checking.EXPLOITHIGH 7.8EPSS 4.06%5 March 2019
CVE-2019-1674A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user.EXPLOITHIGH 8.8EPSS 10.8%28 February 2019
CVE-2019-1663A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute…EXPLOIT ×3CRITICAL 9.8EPSS 95.7%28 February 2019
CVE-2019-2000In several functions of binder.c, there is possible memory corruption due to a use after free.EXPLOITHIGH 7.8EPSS 0.68%28 February 2019
CVE-2019-1999In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking.EXPLOITHIGH 7.8EPSS 0.81%28 February 2019
CVE-2019-9194elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.EXPLOIT ×2CRITICAL 9.8EPSS 96.7%26 February 2019
CVE-2019-9184SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.EXPLOITCRITICAL 9.8EPSS 8.98%26 February 2019
CVE-2019-9162In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local…EXPLOITHIGH 7.8EPSS 1.09%25 February 2019
CVE-2019-9082ThinkPHP Remote Code Execution VulnerabilityKEVEXPLOIT ×2HIGH 8.8EPSS 97.4%24 February 2019
CVE-2019-8375The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of…EXPLOITCRITICAL 9.8EPSS 16.1%24 February 2019
CVE-2019-9041In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.EXPLOITHIGH 7.2EPSS 31.4%23 February 2019
CVE-2014-10079In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.EXPLOITMEDIUM 5.3EPSS 8.75%23 February 2019
CVE-2014-10078Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.EXPLOITMEDIUM 6.1EPSS 3.25%23 February 2019
CVE-2019-6340Drupal Core Remote Code Execution VulnerabilityKEVEXPLOIT ×3HIGH 8.1EPSS 92.0%21 February 2019
CVE-2019-8982com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.EXPLOITCRITICAL 9.6EPSS 28.0%21 February 2019
CVE-2019-3475A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root.EXPLOITHIGH 7.8EPSS 0.99%20 February 2019
CVE-2019-3474A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server.EXPLOITMEDIUM 6.5EPSS 8.95%20 February 2019
CVE-2019-3924MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.EXPLOITHIGH 7.5EPSS 15.7%20 February 2019
CVE-2019-8953The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.EXPLOITMEDIUM 6.1EPSS 52.2%20 February 2019
CVE-2019-8943WordPress through 5.0.3 allows Path Traversal in wp_crop_image().EXPLOIT ×2MEDIUM 6.5EPSS 92.6%20 February 2019
CVE-2019-8942WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring.EXPLOIT ×2HIGH 8.8EPSS 82.7%20 February 2019
CVE-2019-6453mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.EXPLOITHIGH 8.1EPSS 54.3%18 February 2019
CVE-2018-20782The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.EXPLOITHIGH 7.5EPSS 10.0%17 February 2019
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) File Upload VulnerabilityKEVEXPLOITMEDIUM 6.5EPSS 63.3%17 February 2019
CVE-2019-6974In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.EXPLOITHIGH 8.1EPSS 16.5%15 February 2019
CVE-2019-8341The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it.EXPLOITCRITICAL 9.8EPSS 44.8%15 February 2019
CVE-2019-6545An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.EXPLOITHIGH 7.5EPSS 13.9%13 February 2019
CVE-2019-6543Code is executed under the program runtime privileges, which could lead to the compromise of the machine.EXPLOITCRITICAL 9.8EPSS 17.3%13 February 2019
CVE-2019-5596In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released…EXPLOIT ×2HIGH 8.8EPSS 1.23%12 February 2019
CVE-2019-5736runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of…EXPLOIT ×2HIGH 8.6EPSS 98.5%11 February 2019
CVE-2018-20250WinRAR Absolute Path Traversal VulnerabilityKEVEXPLOIT ×2HIGH 7.8EPSS 96.3%5 February 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.