Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
25,049 results · page 50 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-7400 | Rukovoditel before 2.4.1 allows XSS. | EXPLOITMEDIUM 6.1EPSS 5.56% | 5 February 2019 |
| CVE-2018-15657 | An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. | EXPLOITHIGH 7.3EPSS 1.56% | 5 February 2019 |
| CVE-2018-19043 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI. | EXPLOITMEDIUM 5.3EPSS 10.0% | 31 January 2019 |
| CVE-2018-19042 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI. | EXPLOITMEDIUM 5.3EPSS 10.0% | 31 January 2019 |
| CVE-2018-19041 | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | EXPLOITMEDIUM 6.1EPSS 2.63% | 31 January 2019 |
| CVE-2018-19040 | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | EXPLOITMEDIUM 5.3EPSS 12.1% | 31 January 2019 |
| CVE-2019-6111 | However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). | EXPLOIT ×2MEDIUM 5.9EPSS 58.2% | 31 January 2019 |
| CVE-2019-6110 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred. | EXPLOIT ×2MEDIUM 6.8EPSS 20.9% | 31 January 2019 |
| CVE-2018-19782 | Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter. | EXPLOITMEDIUM 6.1EPSS 4.43% | 30 January 2019 |
| CVE-2018-17431 | Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL. | EXPLOITCRITICAL 9.8EPSS 83.9% | 30 January 2019 |
| CVE-2019-6979 | There is XSS via the admin/modules/tools/ip_history_logs.php useragent field. | EXPLOITMEDIUM 6.1EPSS 2.08% | 28 January 2019 |
| CVE-2019-6977 | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. | EXPLOITHIGH 8.8EPSS 71.5% | 27 January 2019 |
| CVE-2019-6804 | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp. | EXPLOITMEDIUM 6.1EPSS 5.32% | 25 January 2019 |
| CVE-2019-6780 | The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer. | EXPLOITMEDIUM 6.1EPSS 4.92% | 24 January 2019 |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.5EPSS 99.9% | 24 January 2019 |
| CVE-2019-1652 | Cisco Small Business Routers Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 7.2EPSS 95.9% | 24 January 2019 |
| CVE-2019-1642 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface… | EXPLOIT ✓MEDIUM 6.1EPSS 3.91% | 23 January 2019 |
| CVE-2019-6706 | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. | EXPLOITHIGH 7.5EPSS 17.2% | 23 January 2019 |
| CVE-2018-6443 | A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE… | EXPLOIT ✓HIGH 8.1EPSS 7.40% | 22 January 2019 |
| CVE-2019-1003002 | A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read… | EXPLOIT ×2 ✓HIGH 8.8EPSS 81.4% | 22 January 2019 |
| CVE-2019-1003001 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows… | EXPLOIT ×2 ✓HIGH 8.8EPSS 86.1% | 22 January 2019 |
| CVE-2019-1003000 | A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute… | EXPLOIT ×3 ✓HIGH 8.8EPSS 98.4% | 22 January 2019 |
| CVE-2018-13374 | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | KEVEXPLOIT ✓MEDIUM 4.3EPSS 37.8% | 22 January 2019 |
| CVE-2019-6498 | GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused. | EXPLOITHIGH 8.8EPSS 4.96% | 21 January 2019 |
| CVE-2018-15982 | Adobe Flash Player Use-After-Free Vulnerability | KEVEXPLOITHIGH 7.8EPSS 89.1% | 18 January 2019 |
| CVE-2018-20735 | It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. | EXPLOIT ✓HIGH 7.8EPSS 7.49% | 17 January 2019 |
| CVE-2017-3141 | The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. | EXPLOITHIGH 7.8EPSS 1.43% | 16 January 2019 |
| CVE-2019-2413 | Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). | EXPLOIT ✓MEDIUM 6.1EPSS 6.47% | 16 January 2019 |
| CVE-2019-6447 | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. | EXPLOITHIGH 8.1EPSS 63.8% | 16 January 2019 |
| CVE-2019-6263 | Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | EXPLOITMEDIUM 4.8EPSS 3.50% | 16 January 2019 |
| CVE-2019-6445 | An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem. | EXPLOIT ✓MEDIUM 6.5EPSS 14.1% | 16 January 2019 |
| CVE-2019-6444 | An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd. | EXPLOIT ✓CRITICAL 9.1EPSS 45.7% | 16 January 2019 |
| CVE-2019-6443 | An issue was discovered in NTPsec before 1.1.3. | EXPLOIT ✓CRITICAL 9.1EPSS 66.9% | 16 January 2019 |
| CVE-2019-6442 | An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y. | EXPLOIT ✓MEDIUM 6.5EPSS 13.7% | 16 January 2019 |
| CVE-2017-18357 | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object. | EXPLOIT ✓MEDIUM 6.5EPSS 27.1% | 15 January 2019 |
| CVE-2019-6249 | There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add. | EXPLOITHIGH 8.8EPSS 2.98% | 13 January 2019 |
| CVE-2018-4404 | In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling. | EXPLOIT ✓HIGH 8.8EPSS 13.9% | 11 January 2019 |
| CVE-2019-5893 | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. | EXPLOITCRITICAL 9.8EPSS 24.7% | 10 January 2019 |
| CVE-2018-16167 | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | EXPLOITCRITICAL 9.8EPSS 74.9% | 9 January 2019 |
| CVE-2018-6126 | A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | EXPLOIT ✓HIGH 8.8EPSS 7.67% | 9 January 2019 |
| CVE-2018-6084 | Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file. | EXPLOIT ✓HIGH 7.8EPSS 1.10% | 9 January 2019 |
| CVE-2018-16083 | An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | EXPLOIT ✓HIGH 8.8EPSS 5.26% | 9 January 2019 |
| CVE-2018-16071 | A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. | EXPLOIT ✓HIGH 8.8EPSS 4.80% | 9 January 2019 |
| CVE-2016-9651 | A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | EXPLOITHIGH 8.8EPSS 11.2% | 9 January 2019 |
| CVE-2019-0574 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | EXPLOIT ✓HIGH 7.8EPSS 19.4% | 8 January 2019 |
| CVE-2019-0573 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | EXPLOIT ✓HIGH 7.8EPSS 20.1% | 8 January 2019 |
| CVE-2019-0572 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | EXPLOIT ✓HIGH 7.8EPSS 25.1% | 8 January 2019 |
| CVE-2019-0571 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | EXPLOIT ✓HIGH 7.8EPSS 15.8% | 8 January 2019 |
| CVE-2019-0570 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows… | EXPLOIT ✓HIGH 7.8EPSS 3.00% | 8 January 2019 |
| CVE-2019-0568 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. | EXPLOIT ✓HIGH 7.5EPSS 69.5% | 8 January 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.