Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,446 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 18 September 2026
17,384 results · page 117 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-8641 | An out-of-bounds read was addressed with improved input validation. | CRITICAL 9.8EPSS 17.0% | 18 December 2019 |
| CVE-2019-8613 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 13.3% | 18 December 2019 |
| CVE-2019-8605 | Apple Multiple Products Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 17.5% | 18 December 2019 |
| CVE-2019-8602 | A memory corruption issue was addressed by removing the vulnerable code. | HIGH 7.8EPSS 10.3% | 18 December 2019 |
| CVE-2019-8600 | A memory corruption issue was addressed with improved input validation. | CRITICAL 9.8EPSS 20.0% | 18 December 2019 |
| CVE-2019-8598 | A malicious application may be able to read restricted memory. | MEDIUM 5.5EPSS 10.3% | 18 December 2019 |
| CVE-2019-8577 | An input validation issue was addressed with improved memory handling. | HIGH 7.8EPSS 10.3% | 18 December 2019 |
| CVE-2019-8565 | A race condition was addressed with additional validation. | HIGH 7.0EPSS 13.5% | 18 December 2019 |
| CVE-2019-8518 | Multiple memory corruption issues were addressed with improved memory handling. | HIGH 8.8EPSS 10.5% | 18 December 2019 |
| CVE-2019-8506 | Apple Multiple Products Type Confusion Vulnerability | KEVHIGH 8.8EPSS 18.1% | 18 December 2019 |
| CVE-2019-7286 | Apple Multiple Products Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 15.6% | 18 December 2019 |
| CVE-2019-19833 | In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. | MEDIUM 6.5EPSS 14.7% | 18 December 2019 |
| CVE-2019-4716 | IBM Planning Analytics Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 86.4% | 18 December 2019 |
| CVE-2019-11400 | A buffer overflow occurs through the get_set.ccp ccp_act parameter. | CRITICAL 9.8EPSS 16.6% | 18 December 2019 |
| CVE-2019-19742 | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. | MEDIUM 4.8EPSS 19.8% | 18 December 2019 |
| CVE-2019-7481 | SonicWall SMA100 SQL Injection Vulnerability | KEVHIGH 7.5EPSS 99.9% | 17 December 2019 |
| CVE-2019-3995 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. | HIGH 7.5EPSS 28.5% | 17 December 2019 |
| CVE-2019-3993 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. | HIGH 7.5EPSS 45.7% | 17 December 2019 |
| CVE-2019-19731 | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. | HIGH 7.5EPSS 11.6% | 16 December 2019 |
| CVE-2019-19368 | A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. | MEDIUM 6.1EPSS 25.9% | 16 December 2019 |
| CVE-2019-19774 | By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5… | HIGH 8.8EPSS 12.5% | 13 December 2019 |
| CVE-2017-18640 | The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. | HIGH 7.5EPSS 26.7% | 12 December 2019 |
| CVE-2013-5743 | Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | CRITICAL 9.8EPSS 80.0% | 11 December 2019 |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 99.7% | 11 December 2019 |
| CVE-2019-19719 | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. | MEDIUM 6.1EPSS 22.0% | 11 December 2019 |
| CVE-2019-1481 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. | MEDIUM 4.3EPSS 13.7% | 10 December 2019 |
| CVE-2019-1468 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.6% | 10 December 2019 |
| CVE-2019-1462 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 18.0% | 10 December 2019 |
| CVE-2019-1458 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 74.3% | 10 December 2019 |
| CVE-2019-17270 | Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the… | CRITICAL 9.8EPSS 58.9% | 10 December 2019 |
| CVE-2019-19642 | On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. | HIGH 8.8EPSS 19.0% | 8 December 2019 |
| CVE-2019-1551 | There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. | MEDIUM 5.3EPSS 14.3% | 6 December 2019 |
| CVE-2018-7282 | The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi. | CRITICAL 9.8EPSS 10.1% | 6 December 2019 |
| CVE-2019-5544 | VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 6 December 2019 |
| CVE-2012-1592 | A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. | HIGH 8.8EPSS 28.5% | 5 December 2019 |
| CVE-2019-19609 | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be… | HIGH 7.2EPSS 54.1% | 5 December 2019 |
| CVE-2019-7195 | QNAP Photo Station Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 89.7% | 5 December 2019 |
| CVE-2019-7194 | QNAP Photo Station Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 83.1% | 5 December 2019 |
| CVE-2019-7193 | QNAP QTS Improper Input Validation Vulnerability | KEVCRITICAL 9.8EPSS 14.4% | 5 December 2019 |
| CVE-2019-7192 | QNAP Photo Station Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 88.2% | 5 December 2019 |
| CVE-2019-19597 | D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header. | HIGH 8.8EPSS 20.8% | 5 December 2019 |
| CVE-2019-19576 | class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions. | CRITICAL 9.8EPSS 26.4% | 4 December 2019 |
| CVE-2019-17554 | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. | MEDIUM 5.5EPSS 12.2% | 4 December 2019 |
| CVE-2019-5097 | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. | HIGH 7.5EPSS 45.1% | 3 December 2019 |
| CVE-2019-5096 | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. | CRITICAL 9.8EPSS 67.0% | 3 December 2019 |
| CVE-2019-12518 | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. | CRITICAL 9.8EPSS 50.7% | 2 December 2019 |
| CVE-2019-19492 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. | CRITICAL 9.8EPSS 29.4% | 2 December 2019 |
| CVE-2019-18922 | A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. | HIGH 7.5EPSS 23.9% | 29 November 2019 |
| CVE-2019-14901 | A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. | CRITICAL 9.8EPSS 16.9% | 29 November 2019 |
| CVE-2011-2523 | vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. | CRITICAL 9.8EPSS 96.2% | 27 November 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.