Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 25 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-2215 | Android Kernel Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 72.1% | 11 October 2019 |
| CVE-2019-1322 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 19.2% | 10 October 2019 |
| CVE-2019-1315 | Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.48% | 10 October 2019 |
| CVE-2019-16928 | Exim Out-of-bounds Write Vulnerability | KEVCRITICAL 9.8EPSS 41.6% | 27 September 2019 |
| CVE-2019-16920 | D-Link Multiple Routers Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 27 September 2019 |
| CVE-2019-16759 | vBulletin PHP Module Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 24 September 2019 |
| CVE-2019-1367 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | KEVHIGH 7.5EPSS 52.4% | 23 September 2019 |
| CVE-2019-16057 | D-Link DNS-320 Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 87.1% | 16 September 2019 |
| CVE-2019-16256 | SIMalliance Toolbox Browser Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 4.95% | 12 September 2019 |
| CVE-2019-1297 | Microsoft Excel Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 21.8% | 11 September 2019 |
| CVE-2019-1253 | Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 11.6% | 11 September 2019 |
| CVE-2019-1215 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 19.3% | 11 September 2019 |
| CVE-2019-1214 | Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability | KEVHIGH 7.8EPSS 1.42% | 11 September 2019 |
| CVE-2019-15949 | Nagios XI Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 77.0% | 5 September 2019 |
| CVE-2019-13608 | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | KEVHIGH 7.5EPSS 30.0% | 29 August 2019 |
| CVE-2019-15752 | Docker Desktop Community Edition Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 31.9% | 28 August 2019 |
| CVE-2019-15107 | Webmin Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 16 August 2019 |
| CVE-2019-0344 | SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 7.08% | 14 August 2019 |
| CVE-2019-11581 | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 84.6% | 9 August 2019 |
| CVE-2019-0193 | Apache Solr DataImportHandler Code Injection Vulnerability | KEVHIGH 7.2EPSS 83.5% | 1 August 2019 |
| CVE-2019-11708 | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | KEVCRITICAL 10.0EPSS 55.9% | 23 July 2019 |
| CVE-2019-11707 | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | KEVHIGH 8.8EPSS 37.7% | 23 July 2019 |
| CVE-2019-1579 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 46.2% | 19 July 2019 |
| CVE-2019-13272 | Linux Kernel Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 52.2% | 17 July 2019 |
| CVE-2019-12991 | Citrix SD-WAN and NetScaler Command Injection Vulnerability | KEVHIGH 8.8EPSS 74.1% | 16 July 2019 |
| CVE-2019-12989 | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.1% | 16 July 2019 |
| CVE-2019-1132 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 9.79% | 15 July 2019 |
| CVE-2019-1130 | Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.28% | 15 July 2019 |
| CVE-2019-1129 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 1.78% | 15 July 2019 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 52.8% | 15 July 2019 |
| CVE-2019-0880 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 2.29% | 15 July 2019 |
| CVE-2018-18325 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | KEVHIGH 7.5EPSS 74.0% | 3 July 2019 |
| CVE-2018-15811 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | KEVHIGH 7.5EPSS 74.0% | 3 July 2019 |
| CVE-2019-7256 | Nice Linear eMerge E3-Series OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 97.1% | 2 July 2019 |
| CVE-2019-5786 | Google Chrome Blink Use-After-Free Vulnerability | KEVMEDIUM 6.5EPSS 61.5% | 27 June 2019 |
| CVE-2019-1069 | Microsoft Task Scheduler Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 6.12% | 12 June 2019 |
| CVE-2019-1064 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 6.89% | 12 June 2019 |
| CVE-2010-5330 | Ubiquiti AirOS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 33.8% | 11 June 2019 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | KEVCRITICAL 9.8EPSS 100.0% | 5 June 2019 |
| CVE-2018-13382 | Fortinet FortiOS and FortiProxy Improper Authorization | KEVHIGH 7.5EPSS 81.7% | 4 June 2019 |
| CVE-2018-13379 | Fortinet FortiOS SSL VPN Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 June 2019 |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 95.4% | 3 June 2019 |
| CVE-2019-9875 | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | KEVHIGH 8.8EPSS 14.0% | 31 May 2019 |
| CVE-2019-9874 | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 83.7% | 31 May 2019 |
| CVE-2019-9670 | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | KEVCRITICAL 9.8EPSS 100.0% | 29 May 2019 |
| CVE-2018-13383 | Fortinet FortiOS and FortiProxy Out-of-bounds Write | KEVMEDIUM 6.5EPSS 33.6% | 29 May 2019 |
| CVE-2018-7841 | Schneider Electric U.motion Builder SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 72.7% | 22 May 2019 |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 8.03% | 22 May 2019 |
| CVE-2019-0903 | Microsoft GDI Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 21.7% | 16 May 2019 |
| CVE-2019-0863 | Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 5.21% | 16 May 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.