SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,905 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 115 of 348

CVESummaryPriorityPublished
CVE-2019-1352A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.HIGH 8.8EPSS 24.0%24 January 2020
CVE-2019-1350A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.HIGH 8.8EPSS 25.7%24 January 2020
CVE-2019-1349A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.HIGH 8.8EPSS 34.0%24 January 2020
CVE-2013-1598A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.HIGH 8.8EPSS 20.5%24 January 2020
CVE-2013-1597A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.MEDIUM 6.5EPSS 14.2%24 January 2020
CVE-2013-1596An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.MEDIUM 5.3EPSS 10.4%24 January 2020
CVE-2013-1595A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a…CRITICAL 9.8EPSS 41.6%24 January 2020
CVE-2019-17570An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library.CRITICAL 9.8EPSS 49.3%23 January 2020
CVE-2012-6649WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.CRITICAL 9.8EPSS 16.3%23 January 2020
CVE-2013-1592A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30…CRITICAL 9.8EPSS 24.4%23 January 2020
CVE-2019-16516There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.MEDIUM 5.3EPSS 19.1%23 January 2020
CVE-2012-6083Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.HIGH 7.5EPSS 11.7%23 January 2020
CVE-2019-19838emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.CRITICAL 9.8EPSS 24.4%23 January 2020
CVE-2019-18426WhatsApp Cross-Site Scripting VulnerabilityKEVHIGH 8.2EPSS 67.9%21 January 2020
CVE-2019-17357Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id.MEDIUM 6.5EPSS 34.2%21 January 2020
CVE-2020-7246A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.HIGH 8.8EPSS 83.2%21 January 2020
CVE-2020-7237Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php.HIGH 8.8EPSS 37.1%20 January 2020
CVE-2014-5007Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files…CRITICAL 9.8EPSS 37.3%17 January 2020
CVE-2019-17361In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.CRITICAL 9.8EPSS 15.2%17 January 2020
CVE-2020-5398In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response…HIGH 7.5EPSS 88.4%17 January 2020
CVE-2020-7048The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a…CRITICAL 9.1EPSS 22.9%16 January 2020
CVE-2020-2555Oracle Multiple Products Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 97.1%15 January 2020
CVE-2020-2551Oracle Fusion Middleware Unspecified VulnerabilityKEVCRITICAL 9.8EPSS 93.2%15 January 2020
CVE-2019-16469Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability.HIGH 7.5EPSS 17.2%15 January 2020
CVE-2020-2096Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.MEDIUM 6.1EPSS 92.8%15 January 2020
CVE-2015-7874Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.CRITICAL 9.8EPSS 13.9%15 January 2020
CVE-2020-0653A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.5%14 January 2020
CVE-2020-0652A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.HIGH 7.8EPSS 17.1%14 January 2020
CVE-2020-0651A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 7.8EPSS 17.3%14 January 2020
CVE-2020-0650A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 7.8EPSS 17.3%14 January 2020
CVE-2020-0646Microsoft .NET Framework Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.2%14 January 2020
CVE-2020-0610A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)…CRITICAL 9.8EPSS 67.6%14 January 2020
CVE-2020-0609A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway)…CRITICAL 9.8EPSS 74.9%14 January 2020
CVE-2020-0606A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET…HIGH 8.8EPSS 17.2%14 January 2020
CVE-2020-0605A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET…HIGH 8.8EPSS 17.8%14 January 2020
CVE-2020-0603A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET…HIGH 8.8EPSS 21.0%14 January 2020
CVE-2020-0601Microsoft Windows CryptoAPI Spoofing VulnerabilityKEVHIGH 8.1EPSS 89.4%14 January 2020
CVE-2020-5505Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.CRITICAL 9.8EPSS 44.3%14 January 2020
CVE-2013-6225LiveZilla 5.0.1.4 has a Remote Code Execution vulnerabilityCRITICAL 9.8EPSS 26.6%13 January 2020
CVE-2014-6039ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.HIGH 7.5EPSS 68.8%13 January 2020
CVE-2014-6038Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability.HIGH 7.5EPSS 72.8%13 January 2020
CVE-2019-13767Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.HIGH 8.8EPSS 15.5%10 January 2020
CVE-2012-4284A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary codeCRITICAL 9.8EPSS 69.5%10 January 2020
CVE-2014-5081sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypassCRITICAL 9.8EPSS 10.5%10 January 2020
CVE-2020-6756languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.CRITICAL 9.8EPSS 10.6%9 January 2020
CVE-2020-5504In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page.HIGH 8.8EPSS 38.8%9 January 2020
CVE-2012-3807Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.CRITICAL 9.8EPSS 31.6%9 January 2020
CVE-2019-20372NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.MEDIUM 5.3EPSS 15.0%9 January 2020
CVE-2019-20224netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.HIGH 8.8EPSS 49.7%9 January 2020
CVE-2019-19494Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser.HIGH 8.8EPSS 23.1%9 January 2020

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.