SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

394,905 CVEs1,713 in CISA KEV17,386 with EPSS ≥ 10%Updated 17 September 2026

17,386 results · page 116 of 348

CVESummaryPriorityPublished
CVE-2019-20361There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).CRITICAL 9.8EPSS 85.1%8 January 2020
CVE-2019-17147This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers.HIGH 8.8EPSS 13.7%7 January 2020
CVE-2020-5307PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the…CRITICAL 9.8EPSS 15.7%7 January 2020
CVE-2014-8673Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.CRITICAL 9.8EPSS 11.9%7 January 2020
CVE-2015-4553A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.HIGH 8.8EPSS 56.7%6 January 2020
CVE-2020-5513Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.MEDIUM 6.8EPSS 25.8%6 January 2020
CVE-2020-5512Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.MEDIUM 6.8EPSS 18.9%6 January 2020
CVE-2019-19509A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.HIGH 8.8EPSS 71.6%6 January 2020
CVE-2020-5515Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.HIGH 7.2EPSS 26.5%6 January 2020
CVE-2020-5514Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.CRITICAL 9.1EPSS 44.1%6 January 2020
CVE-2019-15984Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device.HIGH 7.2EPSS 46.9%6 January 2020
CVE-2019-15982Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.HIGH 7.2EPSS 14.3%6 January 2020
CVE-2019-15981Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.HIGH 7.2EPSS 14.3%6 January 2020
CVE-2019-15980Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.HIGH 7.2EPSS 50.0%6 January 2020
CVE-2019-15978Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying…HIGH 7.2EPSS 37.5%6 January 2020
CVE-2019-15977Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…HIGH 7.5EPSS 38.1%6 January 2020
CVE-2019-15976Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…CRITICAL 9.8EPSS 92.8%6 January 2020
CVE-2019-15975Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected…CRITICAL 9.8EPSS 96.5%6 January 2020
CVE-2020-5192PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.HIGH 8.8EPSS 16.8%6 January 2020
CVE-2014-8516Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.CRITICAL 9.8EPSS 81.7%3 January 2020
CVE-2019-5064An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0.HIGH 8.8EPSS 10.7%3 January 2020
CVE-2019-5063An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0.HIGH 8.8EPSS 21.1%3 January 2020
CVE-2016-1000027Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data.CRITICAL 9.8EPSS 32.3%2 January 2020
CVE-2013-3944Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.HIGH 7.8EPSS 27.5%2 January 2020
CVE-2019-20197In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.HIGH 8.8EPSS 22.4%31 December 2019
CVE-2019-7751A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files.HIGH 7.5EPSS 14.2%31 December 2019
CVE-2019-17621D-Link DIR-859 Router Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 89.6%30 December 2019
CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution VulnerabilityKEVHIGH 7.5EPSS 98.6%30 December 2019
CVE-2019-20139In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter.MEDIUM 5.4EPSS 26.1%30 December 2019
CVE-2019-20085TVT NVMS-1000 Directory Traversal VulnerabilityKEVHIGH 7.5EPSS 96.1%30 December 2019
CVE-2014-5289Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.CRITICAL 9.8EPSS 12.0%27 December 2019
CVE-2019-20049A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM.CRITICAL 9.8EPSS 12.8%27 December 2019
CVE-2013-4982AVTECH AVN801 DVR has a security bypass via the administration login captchaCRITICAL 9.8EPSS 13.1%27 December 2019
CVE-2013-4976Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentialsCRITICAL 9.8EPSS 36.1%27 December 2019
CVE-2013-4975Hikvision DS-2CD7153-E IP Camera has Privilege EscalationHIGH 8.8EPSS 12.3%27 December 2019
CVE-2019-19781Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%27 December 2019
CVE-2019-19985The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.MEDIUM 5.3EPSS 71.4%26 December 2019
CVE-2019-10758MongoDB mongo-express Remote Code Execution VulnerabilityKEVCRITICAL 9.9EPSS 84.7%24 December 2019
CVE-2019-5108An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3.MEDIUM 6.5EPSS 10.1%23 December 2019
CVE-2019-17563When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack.HIGH 7.5EPSS 10.7%23 December 2019
CVE-2019-17571Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for…CRITICAL 9.8EPSS 69.1%20 December 2019
CVE-2019-19908phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL.MEDIUM 6.1EPSS 21.2%20 December 2019
CVE-2019-16451Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 34.7%19 December 2019
CVE-2019-19844Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.CRITICAL 9.8EPSS 53.6%18 December 2019
CVE-2019-8689Multiple memory corruption issues were addressed with improved memory handling.HIGH 8.8EPSS 12.9%18 December 2019
CVE-2019-8672Multiple memory corruption issues were addressed with improved memory handling.HIGH 8.8EPSS 11.0%18 December 2019
CVE-2019-8661A use after free issue was addressed with improved memory management.CRITICAL 9.8EPSS 10.3%18 December 2019
CVE-2019-8660A memory corruption issue was addressed with improved input validation.CRITICAL 9.8EPSS 13.8%18 December 2019
CVE-2019-8647A use after free issue was addressed with improved memory management.CRITICAL 9.8EPSS 13.5%18 December 2019
CVE-2019-8646An out-of-bounds read was addressed with improved input validation.HIGH 7.5EPSS 11.0%18 December 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.