SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,450 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 19 September 2026

17,384 results · page 120 of 348

CVESummaryPriorityPublished
CVE-2019-17120A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp.MEDIUM 6.1EPSS 50.0%17 October 2019
CVE-2019-14287In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID.HIGH 8.8EPSS 63.8%17 October 2019
CVE-2019-11253Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU…HIGH 7.5EPSS 25.9%17 October 2019
CVE-2019-15850eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method.HIGH 8.8EPSS 15.6%17 October 2019
CVE-2019-14423A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.HIGH 8.8EPSS 19.9%17 October 2019
CVE-2019-17671In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.MEDIUM 5.3EPSS 36.5%17 October 2019
CVE-2019-3025Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications.CRITICAL 9.0EPSS 14.5%16 October 2019
CVE-2019-3010Oracle Solaris Privilege Escalation VulnerabilityKEVHIGH 8.8EPSS 13.4%16 October 2019
CVE-2019-2904Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces).CRITICAL 9.8EPSS 14.3%16 October 2019
CVE-2019-2890Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services).HIGH 7.2EPSS 37.6%16 October 2019
CVE-2019-17662ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server.CRITICAL 9.8EPSS 96.8%16 October 2019
CVE-2019-17626ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.CRITICAL 9.8EPSS 10.2%16 October 2019
CVE-2019-17602The OPMDeviceDetailsServlet servlet is prone to SQL injection.CRITICAL 9.8EPSS 81.5%15 October 2019
CVE-2019-17195Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.CRITICAL 9.8EPSS 11.0%15 October 2019
CVE-2019-16279A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.HIGH 7.5EPSS 19.8%14 October 2019
CVE-2019-16278Nostromo nhttpd Directory Traversal VulnerabilityKEVCRITICAL 9.8EPSS 99.0%14 October 2019
CVE-2019-17538Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.HIGH 7.5EPSS 11.3%13 October 2019
CVE-2017-18638send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.HIGH 7.5EPSS 15.3%11 October 2019
CVE-2019-17508On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.CRITICAL 9.8EPSS 15.8%11 October 2019
CVE-2019-17506An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php.CRITICAL 9.8EPSS 56.4%11 October 2019
CVE-2019-2215Android Kernel Use-After-Free VulnerabilityKEVHIGH 7.8EPSS 72.1%11 October 2019
CVE-2019-17503This file exposes SQL database information such as database version, table name, column name, etc.MEDIUM 5.3EPSS 48.3%11 October 2019
CVE-2015-9480The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.HIGH 7.5EPSS 12.7%10 October 2019
CVE-2019-1372An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged…CRITICAL 10.0EPSS 18.5%10 October 2019
CVE-2019-1359A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 19.3%10 October 2019
CVE-2019-1358A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 76.5%10 October 2019
CVE-2019-1347A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.MEDIUM 6.5EPSS 14.9%10 October 2019
CVE-2019-1346A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.MEDIUM 6.5EPSS 10.9%10 October 2019
CVE-2019-1343A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.MEDIUM 6.5EPSS 10.9%10 October 2019
CVE-2019-1333A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 15.9%10 October 2019
CVE-2019-1331A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 19.7%10 October 2019
CVE-2019-1327A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 8.8EPSS 14.0%10 October 2019
CVE-2019-1322Microsoft Windows Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 19.2%10 October 2019
CVE-2019-1311A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.HIGH 7.8EPSS 36.2%10 October 2019
CVE-2019-1308A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%10 October 2019
CVE-2019-1307A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%10 October 2019
CVE-2019-1166A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.MEDIUM 5.9EPSS 68.1%10 October 2019
CVE-2019-1060A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.8%10 October 2019
CVE-2019-17418There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.HIGH 7.2EPSS 49.3%10 October 2019
CVE-2019-15715MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.HIGH 7.2EPSS 30.0%9 October 2019
CVE-2019-17124Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.CRITICAL 9.8EPSS 22.5%9 October 2019
CVE-2019-15859Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.CRITICAL 9.8EPSS 31.5%9 October 2019
CVE-2019-15226A remote attacker may craft a request that stays below the maximum request header size but consists of many thousands of small headers to consume CPU and result in a denial-of-service attack.HIGH 7.5EPSS 65.4%9 October 2019
CVE-2019-17382An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously).CRITICAL 9.1EPSS 54.1%9 October 2019
CVE-2019-13051Pi-Hole 4.3 allows Command Injection.HIGH 8.8EPSS 12.5%9 October 2019
CVE-2019-10969Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.HIGH 7.2EPSS 10.6%8 October 2019
CVE-2019-17187/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.HIGH 7.5EPSS 10.8%8 October 2019
CVE-2019-17240bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.CRITICAL 9.8EPSS 39.6%6 October 2019
CVE-2019-16891Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.CRITICAL 9.8EPSS 44.7%4 October 2019
CVE-2019-17132vBulletin through 5.5.4 mishandles custom avatars.CRITICAL 9.8EPSS 11.7%4 October 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.