SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026

1,710 results · page 24 of 35

CVESummaryPriorityPublished
CVE-2020-0683Microsoft Windows Installer Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 7.67%11 February 2020
CVE-2020-0674Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 86.9%11 February 2020
CVE-2020-0618Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 99.0%11 February 2020
CVE-2019-19356Netis WF2419 Devices Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 28.2%7 February 2020
CVE-2019-18988TeamViewer Desktop Bypass Remote Login VulnerabilityKEVHIGH 7.0EPSS 4.71%7 February 2020
CVE-2020-8655EyesOfNetwork Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 60.1%7 February 2020
CVE-2020-8657EyesOfNetwork Use of Hard-Coded Credentials VulnerabilityKEVCRITICAL 9.8EPSS 91.9%6 February 2020
CVE-2020-8644PlaySMS Server-Side Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 86.7%5 February 2020
CVE-2020-3118Cisco IOS XR Software Discovery Protocol Format String VulnerabilityKEVHIGH 8.8EPSS 11.7%5 February 2020
CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page VulnerabilityKEVCRITICAL 9.8EPSS 100.0%1 February 2020
CVE-2020-7247OpenSMTPD Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.0%29 January 2020
CVE-2019-18426WhatsApp Cross-Site Scripting VulnerabilityKEVHIGH 8.2EPSS 67.9%21 January 2020
CVE-2020-2555Oracle Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.1%15 January 2020
CVE-2020-2551Oracle Fusion Middleware Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 93.2%15 January 2020
CVE-2020-0646Microsoft .NET Framework Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.2%14 January 2020
CVE-2020-0638Microsoft Update Notification Manager Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 3.04%14 January 2020
CVE-2020-0601Microsoft Windows CryptoAPI Spoofing VulnerabilityKEVHIGH 8.1EPSS 89.4%14 January 2020
CVE-2019-17621D-Link DIR-859 Router Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 89.6%30 December 2019
CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 98.6%30 December 2019
CVE-2019-20085TVT NVMS-1000 Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 96.1%30 December 2019
CVE-2019-19781Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%27 December 2019
CVE-2019-10758MongoDB mongo-express Remote Code Execution VulnerabilityKEVCRITICAL 9.9EPSS 84.7%24 December 2019
CVE-2019-7483SonicWall SMA100 Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 4.01%19 December 2019
CVE-2019-8605Apple Multiple Products Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 17.5%18 December 2019
CVE-2019-8526Apple macOS Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 0.70%18 December 2019
CVE-2019-8506Apple Multiple Products Type Confusion VulnerabilityKEVHIGH 8.8EPSS 18.1%18 December 2019
CVE-2019-7287Apple iOS Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 4.55%18 December 2019
CVE-2019-7286Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 15.6%18 December 2019
CVE-2019-4716IBM Planning Analytics Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 86.4%18 December 2019
CVE-2019-7481SonicWall SMA100 SQL Injection VulnerabilityKEVHIGH 7.5EPSS 99.9%17 December 2019
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 99.7%11 December 2019
CVE-2019-1458Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 74.3%10 December 2019
CVE-2019-5544VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 97.3%6 December 2019
CVE-2019-7195QNAP Photo Station Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 89.7%5 December 2019
CVE-2019-7194QNAP Photo Station Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 83.1%5 December 2019
CVE-2019-7193QNAP QTS Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 14.4%5 December 2019
CVE-2019-7192QNAP Photo Station Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 88.2%5 December 2019
CVE-2019-15271Cisco RV Series Routers Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 5.98%26 November 2019
CVE-2019-5825Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVMEDIUM 6.5EPSS 55.9%25 November 2019
CVE-2019-13720Google Chrome WebAudio Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 73.0%25 November 2019
CVE-2019-19006 Sangoma FreePBX Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 36.6%21 November 2019
CVE-2019-6693Fortinet FortiOS Use of Hard-Coded Credentials VulnerabilityKEVMEDIUM 6.5EPSS 5.66%21 November 2019
CVE-2019-1429Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 77.3%12 November 2019
CVE-2019-1405Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 29.9%12 November 2019
CVE-2019-1388Microsoft Windows Certificate Dialog Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 8.59%12 November 2019
CVE-2019-1385Microsoft Windows AppX Deployment Extensions Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 3.60%12 November 2019
CVE-2019-18187Trend Micro OfficeScan Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 25.1%28 October 2019
CVE-2019-11043PHP FastCGI Process Manager (FPM) Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 99.8%28 October 2019
CVE-2019-3010Oracle Solaris Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 13.4%16 October 2019
CVE-2019-16278Nostromo nhttpd Directory Traversal VulnerabilityKEVCRITICAL 9.8EPSS 99.0%14 October 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.