Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
394,905 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026
17,386 results · page 115 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-1352 | A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 24.0% | 24 January 2020 |
| CVE-2019-1350 | A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 25.7% | 24 January 2020 |
| CVE-2019-1349 | A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 34.0% | 24 January 2020 |
| CVE-2013-1598 | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code. | HIGH 8.8EPSS 20.5% | 24 January 2020 |
| CVE-2013-1597 | A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials. | MEDIUM 6.5EPSS 14.2% | 24 January 2020 |
| CVE-2013-1596 | An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554. | MEDIUM 5.3EPSS 10.4% | 24 January 2020 |
| CVE-2013-1595 | A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a… | CRITICAL 9.8EPSS 41.6% | 24 January 2020 |
| CVE-2019-17570 | An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. | CRITICAL 9.8EPSS 49.3% | 23 January 2020 |
| CVE-2012-6649 | WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | CRITICAL 9.8EPSS 16.3% | 23 January 2020 |
| CVE-2013-1592 | A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30… | CRITICAL 9.8EPSS 24.4% | 23 January 2020 |
| CVE-2019-16516 | There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username. | MEDIUM 5.3EPSS 19.1% | 23 January 2020 |
| CVE-2012-6083 | Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. | HIGH 7.5EPSS 11.7% | 23 January 2020 |
| CVE-2019-19838 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute. | CRITICAL 9.8EPSS 24.4% | 23 January 2020 |
| CVE-2019-18426 | WhatsApp Cross-Site Scripting Vulnerability | KEVHIGH 8.2EPSS 67.9% | 21 January 2020 |
| CVE-2019-17357 | Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. | MEDIUM 6.5EPSS 34.2% | 21 January 2020 |
| CVE-2020-7246 | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. | HIGH 8.8EPSS 83.2% | 21 January 2020 |
| CVE-2020-7237 | Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. | HIGH 8.8EPSS 37.1% | 20 January 2020 |
| CVE-2014-5007 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files… | CRITICAL 9.8EPSS 37.3% | 17 January 2020 |
| CVE-2019-17361 | In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. | CRITICAL 9.8EPSS 15.2% | 17 January 2020 |
| CVE-2020-5398 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response… | HIGH 7.5EPSS 88.4% | 17 January 2020 |
| CVE-2020-7048 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a… | CRITICAL 9.1EPSS 22.9% | 16 January 2020 |
| CVE-2020-2555 | Oracle Multiple Products Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 97.1% | 15 January 2020 |
| CVE-2020-2551 | Oracle Fusion Middleware Unspecified Vulnerability | KEVCRITICAL 9.8EPSS 93.2% | 15 January 2020 |
| CVE-2019-16469 | Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. | HIGH 7.5EPSS 17.2% | 15 January 2020 |
| CVE-2020-2096 | Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. | MEDIUM 6.1EPSS 92.8% | 15 January 2020 |
| CVE-2015-7874 | Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. | CRITICAL 9.8EPSS 13.9% | 15 January 2020 |
| CVE-2020-0653 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 20.5% | 14 January 2020 |
| CVE-2020-0652 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'. | HIGH 7.8EPSS 17.1% | 14 January 2020 |
| CVE-2020-0651 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 17.3% | 14 January 2020 |
| CVE-2020-0650 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 17.3% | 14 January 2020 |
| CVE-2020-0646 | Microsoft .NET Framework Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.2% | 14 January 2020 |
| CVE-2020-0610 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)… | CRITICAL 9.8EPSS 67.6% | 14 January 2020 |
| CVE-2020-0609 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)… | CRITICAL 9.8EPSS 74.9% | 14 January 2020 |
| CVE-2020-0606 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET… | HIGH 8.8EPSS 17.2% | 14 January 2020 |
| CVE-2020-0605 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET… | HIGH 8.8EPSS 17.8% | 14 January 2020 |
| CVE-2020-0603 | A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET… | HIGH 8.8EPSS 21.0% | 14 January 2020 |
| CVE-2020-0601 | Microsoft Windows CryptoAPI Spoofing Vulnerability | KEVHIGH 8.1EPSS 89.4% | 14 January 2020 |
| CVE-2020-5505 | Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI. | CRITICAL 9.8EPSS 44.3% | 14 January 2020 |
| CVE-2013-6225 | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability | CRITICAL 9.8EPSS 26.6% | 13 January 2020 |
| CVE-2014-6039 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. | HIGH 7.5EPSS 68.8% | 13 January 2020 |
| CVE-2014-6038 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. | HIGH 7.5EPSS 72.8% | 13 January 2020 |
| CVE-2019-13767 | Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | HIGH 8.8EPSS 15.5% | 10 January 2020 |
| CVE-2012-4284 | A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code | CRITICAL 9.8EPSS 69.5% | 10 January 2020 |
| CVE-2014-5081 | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | CRITICAL 9.8EPSS 10.5% | 10 January 2020 |
| CVE-2020-6756 | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter. | CRITICAL 9.8EPSS 10.6% | 9 January 2020 |
| CVE-2020-5504 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. | HIGH 8.8EPSS 38.8% | 9 January 2020 |
| CVE-2012-3807 | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | CRITICAL 9.8EPSS 31.6% | 9 January 2020 |
| CVE-2019-20372 | NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer. | MEDIUM 5.3EPSS 15.0% | 9 January 2020 |
| CVE-2019-20224 | netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. | HIGH 8.8EPSS 49.7% | 9 January 2020 |
| CVE-2019-19494 | Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. | HIGH 8.8EPSS 23.1% | 9 January 2020 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.