Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 24 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2020-0683 | Microsoft Windows Installer Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 7.67% | 11 February 2020 |
| CVE-2020-0674 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 86.9% | 11 February 2020 |
| CVE-2020-0618 | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 99.0% | 11 February 2020 |
| CVE-2019-19356 | Netis WF2419 Devices Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 28.2% | 7 February 2020 |
| CVE-2019-18988 | TeamViewer Desktop Bypass Remote Login Vulnerability | KEVHIGH 7.0EPSS 4.71% | 7 February 2020 |
| CVE-2020-8655 | EyesOfNetwork Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 60.1% | 7 February 2020 |
| CVE-2020-8657 | EyesOfNetwork Use of Hard-Coded Credentials Vulnerability | KEVCRITICAL 9.8EPSS 91.9% | 6 February 2020 |
| CVE-2020-8644 | PlaySMS Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.7% | 5 February 2020 |
| CVE-2020-3118 | Cisco IOS XR Software Discovery Protocol Format String Vulnerability | KEVHIGH 8.8EPSS 11.7% | 5 February 2020 |
| CVE-2020-8515 | Multiple DrayTek Vigor Routers Web Management Page Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 1 February 2020 |
| CVE-2020-7247 | OpenSMTPD Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 29 January 2020 |
| CVE-2019-18426 | WhatsApp Cross-Site Scripting Vulnerability | KEVHIGH 8.2EPSS 67.9% | 21 January 2020 |
| CVE-2020-2555 | Oracle Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.1% | 15 January 2020 |
| CVE-2020-2551 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 93.2% | 15 January 2020 |
| CVE-2020-0646 | Microsoft .NET Framework Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 14 January 2020 |
| CVE-2020-0638 | Microsoft Update Notification Manager Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.04% | 14 January 2020 |
| CVE-2020-0601 | Microsoft Windows CryptoAPI Spoofing Vulnerability | KEVHIGH 8.1EPSS 89.4% | 14 January 2020 |
| CVE-2019-17621 | D-Link DIR-859 Router Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 89.6% | 30 December 2019 |
| CVE-2019-17558 | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability | KEVHIGH 7.5EPSS 98.6% | 30 December 2019 |
| CVE-2019-20085 | TVT NVMS-1000 Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 96.1% | 30 December 2019 |
| CVE-2019-19781 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 27 December 2019 |
| CVE-2019-10758 | MongoDB mongo-express Remote Code Execution Vulnerability | KEVCRITICAL 9.9EPSS 84.7% | 24 December 2019 |
| CVE-2019-7483 | SonicWall SMA100 Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 4.01% | 19 December 2019 |
| CVE-2019-8605 | Apple Multiple Products Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 17.5% | 18 December 2019 |
| CVE-2019-8526 | Apple macOS Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 0.70% | 18 December 2019 |
| CVE-2019-8506 | Apple Multiple Products Type Confusion Vulnerability | KEVHIGH 8.8EPSS 18.1% | 18 December 2019 |
| CVE-2019-7287 | Apple iOS Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 4.55% | 18 December 2019 |
| CVE-2019-7286 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 15.6% | 18 December 2019 |
| CVE-2019-4716 | IBM Planning Analytics Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 86.4% | 18 December 2019 |
| CVE-2019-7481 | SonicWall SMA100 SQL Injection Vulnerability | KEVHIGH 7.5EPSS 99.9% | 17 December 2019 |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 11 December 2019 |
| CVE-2019-1458 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 74.3% | 10 December 2019 |
| CVE-2019-5544 | VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 6 December 2019 |
| CVE-2019-7195 | QNAP Photo Station Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 89.7% | 5 December 2019 |
| CVE-2019-7194 | QNAP Photo Station Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 83.1% | 5 December 2019 |
| CVE-2019-7193 | QNAP QTS Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 14.4% | 5 December 2019 |
| CVE-2019-7192 | QNAP Photo Station Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 88.2% | 5 December 2019 |
| CVE-2019-15271 | Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 5.98% | 26 November 2019 |
| CVE-2019-5825 | Google Chromium V8 Out-of-Bounds Write Vulnerability | KEVMEDIUM 6.5EPSS 55.9% | 25 November 2019 |
| CVE-2019-13720 | Google Chrome WebAudio Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 73.0% | 25 November 2019 |
| CVE-2019-19006 | Sangoma FreePBX Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 36.6% | 21 November 2019 |
| CVE-2019-6693 | Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | KEVMEDIUM 6.5EPSS 5.66% | 21 November 2019 |
| CVE-2019-1429 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 77.3% | 12 November 2019 |
| CVE-2019-1405 | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 29.9% | 12 November 2019 |
| CVE-2019-1388 | Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 8.59% | 12 November 2019 |
| CVE-2019-1385 | Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.60% | 12 November 2019 |
| CVE-2019-18187 | Trend Micro OfficeScan Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 25.1% | 28 October 2019 |
| CVE-2019-11043 | PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 28 October 2019 |
| CVE-2019-3010 | Oracle Solaris Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 13.4% | 16 October 2019 |
| CVE-2019-16278 | Nostromo nhttpd Directory Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 14 October 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.