Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,450 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 19 September 2026
17,384 results · page 119 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-12419 | There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. | CRITICAL 9.8EPSS 13.8% | 6 November 2019 |
| CVE-2014-9014 | Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. | MEDIUM 4.3EPSS 11.6% | 6 November 2019 |
| CVE-2014-9013 | The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of… | HIGH 8.8EPSS 46.9% | 6 November 2019 |
| CVE-2013-2261 | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | HIGH 7.5EPSS 11.6% | 4 November 2019 |
| CVE-2019-18665 | The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. | HIGH 7.5EPSS 14.9% | 2 November 2019 |
| CVE-2013-2227 | GLPI 0.83.7 has Local File Inclusion in common.tabs.php. | HIGH 7.5EPSS 13.0% | 1 November 2019 |
| CVE-2011-3923 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | CRITICAL 9.8EPSS 89.5% | 1 November 2019 |
| CVE-2019-5010 | An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. | HIGH 7.5EPSS 20.7% | 31 October 2019 |
| CVE-2018-4064 | An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. | HIGH 7.1EPSS 14.5% | 31 October 2019 |
| CVE-2019-18396 | A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. | HIGH 7.2EPSS 16.2% | 31 October 2019 |
| CVE-2013-1391 | Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration. | HIGH 7.5EPSS 76.1% | 30 October 2019 |
| CVE-2012-0694 | SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. | CRITICAL 9.8EPSS 67.3% | 29 October 2019 |
| CVE-2019-9757 | Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read. | HIGH 7.5EPSS 37.3% | 29 October 2019 |
| CVE-2019-8287 | TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. | CRITICAL 9.8EPSS 19.5% | 29 October 2019 |
| CVE-2019-6851 | A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol. | HIGH 7.5EPSS 29.9% | 29 October 2019 |
| CVE-2019-6848 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on… | HIGH 8.6EPSS 33.0% | 29 October 2019 |
| CVE-2019-6841 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a… | MEDIUM 4.9EPSS 24.4% | 29 October 2019 |
| CVE-2019-5533 | In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. | MEDIUM 4.3EPSS 17.9% | 29 October 2019 |
| CVE-2019-3978 | RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. | HIGH 7.5EPSS 10.3% | 29 October 2019 |
| CVE-2019-15683 | TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. | CRITICAL 9.8EPSS 19.4% | 29 October 2019 |
| CVE-2019-15679 | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. | CRITICAL 9.8EPSS 11.8% | 29 October 2019 |
| CVE-2019-15678 | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. | CRITICAL 9.8EPSS 12.2% | 29 October 2019 |
| CVE-2019-18187 | Trend Micro OfficeScan Directory Traversal Vulnerability | KEVHIGH 7.5EPSS 25.1% | 28 October 2019 |
| CVE-2019-17181 | A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). | CRITICAL 9.8EPSS 48.7% | 28 October 2019 |
| CVE-2019-14450 | A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. | CRITICAL 9.8EPSS 10.4% | 28 October 2019 |
| CVE-2019-11043 | PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 28 October 2019 |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | CRITICAL 9.8EPSS 13.4% | 28 October 2019 |
| CVE-2019-14931 | An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. | CRITICAL 9.8EPSS 58.1% | 28 October 2019 |
| CVE-2019-14928 | A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. | MEDIUM 5.4EPSS 44.1% | 28 October 2019 |
| CVE-2019-14927 | An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data). | HIGH 7.5EPSS 41.8% | 28 October 2019 |
| CVE-2019-16663 | An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution. | HIGH 8.8EPSS 84.7% | 28 October 2019 |
| CVE-2019-16662 | An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution. | CRITICAL 9.8EPSS 97.7% | 28 October 2019 |
| CVE-2019-5129 | A command injection have been found in YouPHPTube Encoder. | CRITICAL 9.8EPSS 38.5% | 25 October 2019 |
| CVE-2019-5128 | A command injection have been found in YouPHPTube Encoder. | CRITICAL 9.8EPSS 30.2% | 25 October 2019 |
| CVE-2019-5127 | A command injection have been found in YouPHPTube Encoder. | CRITICAL 9.8EPSS 45.3% | 25 October 2019 |
| CVE-2019-8086 | Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. | HIGH 7.5EPSS 22.5% | 25 October 2019 |
| CVE-2019-18394 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. | CRITICAL 9.8EPSS 32.3% | 24 October 2019 |
| CVE-2019-18393 | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability. | MEDIUM 5.3EPSS 13.9% | 24 October 2019 |
| CVE-2019-18371 | There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. | HIGH 7.5EPSS 55.9% | 23 October 2019 |
| CVE-2019-18370 | In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed. | CRITICAL 9.8EPSS 40.3% | 23 October 2019 |
| CVE-2019-18277 | In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. | HIGH 7.5EPSS 10.0% | 23 October 2019 |
| CVE-2019-10475 | A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin. | MEDIUM 6.1EPSS 57.7% | 23 October 2019 |
| CVE-2015-9499 | The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. | CRITICAL 9.8EPSS 16.3% | 22 October 2019 |
| CVE-2019-17424 | A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file. | HIGH 7.8EPSS 13.4% | 22 October 2019 |
| CVE-2019-9491 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. | HIGH 7.8EPSS 12.9% | 21 October 2019 |
| CVE-2019-18217 | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop. | HIGH 7.5EPSS 19.5% | 21 October 2019 |
| CVE-2019-8197 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 16.8% | 17 October 2019 |
| CVE-2019-8196 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. | CRITICAL 9.8EPSS 22.9% | 17 October 2019 |
| CVE-2019-8195 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. | CRITICAL 9.8EPSS 22.9% | 17 October 2019 |
| CVE-2019-8183 | Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. | HIGH 8.8EPSS 13.1% | 17 October 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.