Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
393,080 CVEs1,710 in CISA KEV17,380 with EPSS ≥ 10%Updated 16 September 2026
1,710 results · page 26 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0708 | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 16 May 2019 |
| CVE-2018-14839 | LG N1A1 NAS Remote Command Execution Vulnerability | KEVCRITICAL 9.8EPSS 89.4% | 14 May 2019 |
| CVE-2019-3568 | WhatsApp VOIP Stack Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 30.1% | 14 May 2019 |
| CVE-2019-11510 | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | KEVCRITICAL 10.0EPSS 100.0% | 8 May 2019 |
| CVE-2018-4063 | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | KEVHIGH 8.8EPSS 27.1% | 6 May 2019 |
| CVE-2017-18368 | Zyxel P660HN-T1A Routers Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.4% | 2 May 2019 |
| CVE-2019-3929 | Crestron Multiple Products Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 30 April 2019 |
| CVE-2019-9621 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 7.5EPSS 81.0% | 30 April 2019 |
| CVE-2019-2725 | Oracle WebLogic Server, Injection | KEVCRITICAL 9.8EPSS 100.0% | 26 April 2019 |
| CVE-2019-11539 | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | KEVHIGH 7.2EPSS 98.5% | 26 April 2019 |
| CVE-2019-2616 | Oracle BI Publisher Unauthorized Access Vulnerability | KEVHIGH 7.2EPSS 92.2% | 23 April 2019 |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | KEVHIGH 8.8EPSS 96.8% | 18 April 2019 |
| CVE-2019-0859 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.15% | 9 April 2019 |
| CVE-2019-0841 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 41.4% | 9 April 2019 |
| CVE-2019-0803 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 45.2% | 9 April 2019 |
| CVE-2019-0752 | Microsoft Internet Explorer Type Confusion Vulnerability | KEVHIGH 7.5EPSS 81.6% | 9 April 2019 |
| CVE-2019-0808 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 53.0% | 9 April 2019 |
| CVE-2019-0797 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 1.89% | 9 April 2019 |
| CVE-2019-0703 | Microsoft Windows SMB Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 9.64% | 9 April 2019 |
| CVE-2019-0211 | Apache HTTP Server Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 65.0% | 8 April 2019 |
| CVE-2019-11001 | Reolink Multiple IP Cameras OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 37.5% | 8 April 2019 |
| CVE-2018-4344 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 2.91% | 3 April 2019 |
| CVE-2019-5418 | Rails Ruby on Rails Path Traversal Vulnerability | KEVHIGH 7.5EPSS 98.5% | 27 March 2019 |
| CVE-2019-10068 | Kentico Xperience Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 95.1% | 26 March 2019 |
| CVE-2019-7609 | Kibana Arbitrary Code Execution | KEVCRITICAL 10.0EPSS 95.3% | 25 March 2019 |
| CVE-2019-3396 | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 25 March 2019 |
| CVE-2019-9978 | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | KEVMEDIUM 6.1EPSS 72.9% | 24 March 2019 |
| CVE-2019-7238 | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | KEVCRITICAL 9.8EPSS 77.1% | 21 March 2019 |
| CVE-2019-1003030 | Jenkins Matrix Project Plugin Remote Code Execution Vulnerability | KEVCRITICAL 9.9EPSS 96.9% | 8 March 2019 |
| CVE-2019-1003029 | Jenkins Script Security Plugin Sandbox Bypass Vulnerability | KEVCRITICAL 9.9EPSS 73.9% | 8 March 2019 |
| CVE-2018-18809 | TIBCO JasperReports Library Directory Traversal Vulnerability | KEVMEDIUM 6.5EPSS 79.1% | 7 March 2019 |
| CVE-2019-0676 | Microsoft Internet Explorer Information Disclosure Vulnerability | KEVMEDIUM 6.5EPSS 7.51% | 5 March 2019 |
| CVE-2019-0604 | Microsoft SharePoint Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 5 March 2019 |
| CVE-2019-6223 | Apple iOS and macOS Group Facetime Vulnerability | KEVHIGH 7.5EPSS 2.63% | 5 March 2019 |
| CVE-2019-9082 | ThinkPHP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 97.4% | 24 February 2019 |
| CVE-2019-6340 | Drupal Core Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 92.0% | 21 February 2019 |
| CVE-2019-8394 | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | KEVMEDIUM 6.5EPSS 63.3% | 17 February 2019 |
| CVE-2018-20250 | WinRAR Absolute Path Traversal Vulnerability | KEVHIGH 7.8EPSS 96.3% | 5 February 2019 |
| CVE-2018-20753 | Kaseya VSA Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 29.3% | 5 February 2019 |
| CVE-2017-18362 | Kaseya VSA SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.8% | 5 February 2019 |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 99.9% | 24 January 2019 |
| CVE-2019-1652 | Cisco Small Business Routers Improper Input Validation Vulnerability | KEVHIGH 7.2EPSS 95.9% | 24 January 2019 |
| CVE-2018-13374 | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | KEVMEDIUM 4.3EPSS 37.8% | 22 January 2019 |
| CVE-2018-15982 | Adobe Flash Player Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 89.1% | 18 January 2019 |
| CVE-2019-0543 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 4.72% | 8 January 2019 |
| CVE-2019-0541 | Microsoft MSHTML Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 53.2% | 8 January 2019 |
| CVE-2018-19323 | GIGABYTE Multiple Products Privilege Escalation Vulnerability | KEVCRITICAL 9.8EPSS 7.83% | 21 December 2018 |
| CVE-2018-19322 | GIGABYTE Multiple Products Code Execution Vulnerability | KEVHIGH 7.8EPSS 1.80% | 21 December 2018 |
| CVE-2018-19321 | GIGABYTE Multiple Products Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 3.67% | 21 December 2018 |
| CVE-2018-19320 | GIGABYTE Multiple Products Unspecified Vulnerability | KEVHIGH 7.8EPSS 3.60% | 21 December 2018 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.