Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,450 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 19 September 2026
17,384 results · page 120 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-17120 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. | MEDIUM 6.1EPSS 50.0% | 17 October 2019 |
| CVE-2019-14287 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. | HIGH 8.8EPSS 63.8% | 17 October 2019 |
| CVE-2019-11253 | Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU… | HIGH 7.5EPSS 25.9% | 17 October 2019 |
| CVE-2019-15850 | eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. | HIGH 8.8EPSS 15.6% | 17 October 2019 |
| CVE-2019-14423 | A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request. | HIGH 8.8EPSS 19.9% | 17 October 2019 |
| CVE-2019-17671 | In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. | MEDIUM 5.3EPSS 36.5% | 17 October 2019 |
| CVE-2019-3025 | Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. | CRITICAL 9.0EPSS 14.5% | 16 October 2019 |
| CVE-2019-3010 | Oracle Solaris Privilege Escalation Vulnerability | KEVHIGH 8.8EPSS 13.4% | 16 October 2019 |
| CVE-2019-2904 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). | CRITICAL 9.8EPSS 14.3% | 16 October 2019 |
| CVE-2019-2890 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). | HIGH 7.2EPSS 37.6% | 16 October 2019 |
| CVE-2019-17662 | ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. | CRITICAL 9.8EPSS 96.8% | 16 October 2019 |
| CVE-2019-17626 | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code. | CRITICAL 9.8EPSS 10.2% | 16 October 2019 |
| CVE-2019-17602 | The OPMDeviceDetailsServlet servlet is prone to SQL injection. | CRITICAL 9.8EPSS 81.5% | 15 October 2019 |
| CVE-2019-17195 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass. | CRITICAL 9.8EPSS 11.0% | 15 October 2019 |
| CVE-2019-16279 | A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | HIGH 7.5EPSS 19.8% | 14 October 2019 |
| CVE-2019-16278 | Nostromo nhttpd Directory Traversal Vulnerability | KEVCRITICAL 9.8EPSS 99.0% | 14 October 2019 |
| CVE-2019-17538 | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring. | HIGH 7.5EPSS 11.3% | 13 October 2019 |
| CVE-2017-18638 | send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. | HIGH 7.5EPSS 15.3% | 11 October 2019 |
| CVE-2019-17508 | On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable. | CRITICAL 9.8EPSS 15.8% | 11 October 2019 |
| CVE-2019-17506 | An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. | CRITICAL 9.8EPSS 56.4% | 11 October 2019 |
| CVE-2019-2215 | Android Kernel Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 72.1% | 11 October 2019 |
| CVE-2019-17503 | This file exposes SQL database information such as database version, table name, column name, etc. | MEDIUM 5.3EPSS 48.3% | 11 October 2019 |
| CVE-2015-9480 | The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter. | HIGH 7.5EPSS 12.7% | 10 October 2019 |
| CVE-2019-1372 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged… | CRITICAL 10.0EPSS 18.5% | 10 October 2019 |
| CVE-2019-1359 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 19.3% | 10 October 2019 |
| CVE-2019-1358 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 76.5% | 10 October 2019 |
| CVE-2019-1347 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. | MEDIUM 6.5EPSS 14.9% | 10 October 2019 |
| CVE-2019-1346 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. | MEDIUM 6.5EPSS 10.9% | 10 October 2019 |
| CVE-2019-1343 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. | MEDIUM 6.5EPSS 10.9% | 10 October 2019 |
| CVE-2019-1333 | A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 15.9% | 10 October 2019 |
| CVE-2019-1331 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 19.7% | 10 October 2019 |
| CVE-2019-1327 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 14.0% | 10 October 2019 |
| CVE-2019-1322 | Microsoft Windows Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 19.2% | 10 October 2019 |
| CVE-2019-1311 | A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 36.2% | 10 October 2019 |
| CVE-2019-1308 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.1% | 10 October 2019 |
| CVE-2019-1307 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.1% | 10 October 2019 |
| CVE-2019-1166 | A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'. | MEDIUM 5.9EPSS 68.1% | 10 October 2019 |
| CVE-2019-1060 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.8% | 10 October 2019 |
| CVE-2019-17418 | There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997. | HIGH 7.2EPSS 49.3% | 10 October 2019 |
| CVE-2019-15715 | MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. | HIGH 7.2EPSS 30.0% | 9 October 2019 |
| CVE-2019-17124 | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. | CRITICAL 9.8EPSS 22.5% | 9 October 2019 |
| CVE-2019-15859 | Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI. | CRITICAL 9.8EPSS 31.5% | 9 October 2019 |
| CVE-2019-15226 | A remote attacker may craft a request that stays below the maximum request header size but consists of many thousands of small headers to consume CPU and result in a denial-of-service attack. | HIGH 7.5EPSS 65.4% | 9 October 2019 |
| CVE-2019-17382 | An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). | CRITICAL 9.1EPSS 54.1% | 9 October 2019 |
| CVE-2019-13051 | Pi-Hole 4.3 allows Command Injection. | HIGH 8.8EPSS 12.5% | 9 October 2019 |
| CVE-2019-10969 | Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution. | HIGH 7.2EPSS 10.6% | 8 October 2019 |
| CVE-2019-17187 | /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files. | HIGH 7.5EPSS 10.8% | 8 October 2019 |
| CVE-2019-17240 | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers. | CRITICAL 9.8EPSS 39.6% | 6 October 2019 |
| CVE-2019-16891 | Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. | CRITICAL 9.8EPSS 44.7% | 4 October 2019 |
| CVE-2019-17132 | vBulletin through 5.5.4 mishandles custom avatars. | CRITICAL 9.8EPSS 11.7% | 4 October 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.