SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,446 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 18 September 2026

17,384 results · page 117 of 348

CVESummaryPriorityPublished
CVE-2019-8641An out-of-bounds read was addressed with improved input validation.CRITICAL 9.8EPSS 17.0%18 December 2019
CVE-2019-8613A use after free issue was addressed with improved memory management.CRITICAL 9.8EPSS 13.3%18 December 2019
CVE-2019-8605Apple Multiple Products Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 17.5%18 December 2019
CVE-2019-8602A memory corruption issue was addressed by removing the vulnerable code.HIGH 7.8EPSS 10.3%18 December 2019
CVE-2019-8600A memory corruption issue was addressed with improved input validation.CRITICAL 9.8EPSS 20.0%18 December 2019
CVE-2019-8598A malicious application may be able to read restricted memory.MEDIUM 5.5EPSS 10.3%18 December 2019
CVE-2019-8577An input validation issue was addressed with improved memory handling.HIGH 7.8EPSS 10.3%18 December 2019
CVE-2019-8565A race condition was addressed with additional validation.HIGH 7.0EPSS 13.5%18 December 2019
CVE-2019-8518Multiple memory corruption issues were addressed with improved memory handling.HIGH 8.8EPSS 10.5%18 December 2019
CVE-2019-8506Apple Multiple Products Type Confusion VulnerabilityKEVHIGH 8.8EPSS 18.1%18 December 2019
CVE-2019-7286Apple Multiple Products Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 15.6%18 December 2019
CVE-2019-19833In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server.MEDIUM 6.5EPSS 14.7%18 December 2019
CVE-2019-4716IBM Planning Analytics Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 86.4%18 December 2019
CVE-2019-11400A buffer overflow occurs through the get_set.ccp ccp_act parameter.CRITICAL 9.8EPSS 16.6%18 December 2019
CVE-2019-19742On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.MEDIUM 4.8EPSS 19.8%18 December 2019
CVE-2019-7481SonicWall SMA100 SQL Injection VulnerabilityKEVHIGH 7.5EPSS 99.9%17 December 2019
CVE-2019-3995ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference.HIGH 7.5EPSS 28.5%17 December 2019
CVE-2019-3993ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability.HIGH 7.5EPSS 45.7%17 December 2019
CVE-2019-19731Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal.HIGH 7.5EPSS 11.6%16 December 2019
CVE-2019-19368A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1.MEDIUM 6.1EPSS 25.9%16 December 2019
CVE-2019-19774By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5…HIGH 8.8EPSS 12.5%13 December 2019
CVE-2017-18640The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.HIGH 7.5EPSS 26.7%12 December 2019
CVE-2013-5743Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.CRITICAL 9.8EPSS 80.0%11 December 2019
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 99.7%11 December 2019
CVE-2019-19719Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.MEDIUM 6.1EPSS 22.0%11 December 2019
CVE-2019-1481An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'.MEDIUM 4.3EPSS 13.7%10 December 2019
CVE-2019-1468A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.HIGH 8.8EPSS 16.6%10 December 2019
CVE-2019-1462A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.HIGH 7.8EPSS 18.0%10 December 2019
CVE-2019-1458Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 74.3%10 December 2019
CVE-2019-17270Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the…CRITICAL 9.8EPSS 58.9%10 December 2019
CVE-2019-19642On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address.HIGH 8.8EPSS 19.0%8 December 2019
CVE-2019-1551There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli.MEDIUM 5.3EPSS 14.3%6 December 2019
CVE-2018-7282The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.CRITICAL 9.8EPSS 10.1%6 December 2019
CVE-2019-5544VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 97.3%6 December 2019
CVE-2012-1592A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.HIGH 8.8EPSS 28.5%5 December 2019
CVE-2019-19609The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be…HIGH 7.2EPSS 54.1%5 December 2019
CVE-2019-7195QNAP Photo Station Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 89.7%5 December 2019
CVE-2019-7194QNAP Photo Station Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 83.1%5 December 2019
CVE-2019-7193QNAP QTS Improper Input Validation VulnerabilityKEVCRITICAL 9.8EPSS 14.4%5 December 2019
CVE-2019-7192QNAP Photo Station Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 88.2%5 December 2019
CVE-2019-19597D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.HIGH 8.8EPSS 20.8%5 December 2019
CVE-2019-19576class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.CRITICAL 9.8EPSS 26.4%4 December 2019
CVE-2019-17554The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities.MEDIUM 5.5EPSS 12.2%4 December 2019
CVE-2019-5097A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5.HIGH 7.5EPSS 45.1%3 December 2019
CVE-2019-5096An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5.CRITICAL 9.8EPSS 67.0%3 December 2019
CVE-2019-12518Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.CRITICAL 9.8EPSS 50.7%2 December 2019
CVE-2019-19492FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.CRITICAL 9.8EPSS 29.4%2 December 2019
CVE-2019-18922A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request.HIGH 7.5EPSS 23.9%29 November 2019
CVE-2019-14901A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver.CRITICAL 9.8EPSS 16.9%29 November 2019
CVE-2011-2523vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.CRITICAL 9.8EPSS 96.2%27 November 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.