SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,450 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 19 September 2026

17,384 results · page 121 of 348

CVESummaryPriorityPublished
CVE-2019-11932A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to…HIGH 8.8EPSS 44.5%3 October 2019
CVE-2019-16328In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.HIGH 7.5EPSS 13.0%3 October 2019
CVE-2019-12630A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.CRITICAL 9.8EPSS 65.8%2 October 2019
CVE-2019-15039It had a possible remote code execution issue.CRITICAL 9.8EPSS 12.9%1 October 2019
CVE-2019-16932A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.CRITICAL 10.0EPSS 39.1%30 September 2019
CVE-2019-16997In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.HIGH 7.2EPSS 49.4%30 September 2019
CVE-2019-16996In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.HIGH 7.2EPSS 12.4%30 September 2019
CVE-2019-16928Exim Out-of-bounds Write VulnerabilityKEVCRITICAL 9.8EPSS 41.6%27 September 2019
CVE-2019-8074ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability.CRITICAL 9.8EPSS 18.9%27 September 2019
CVE-2019-16920D-Link Multiple Routers Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 100.0%27 September 2019
CVE-2019-16667diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.HIGH 8.8EPSS 54.5%26 September 2019
CVE-2019-10097In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference.HIGH 7.2EPSS 52.9%26 September 2019
CVE-2019-10092In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page.MEDIUM 6.1EPSS 81.5%26 September 2019
CVE-2019-10082In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.CRITICAL 9.1EPSS 16.5%26 September 2019
CVE-2019-12650Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.HIGH 8.8EPSS 28.9%25 September 2019
CVE-2019-10098In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.MEDIUM 6.1EPSS 74.0%25 September 2019
CVE-2019-16701pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.HIGH 8.8EPSS 19.6%25 September 2019
CVE-2019-10405Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.MEDIUM 5.4EPSS 65.3%25 September 2019
CVE-2019-16759vBulletin PHP Module Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.7%24 September 2019
CVE-2019-16724File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.CRITICAL 9.8EPSS 72.2%24 September 2019
CVE-2019-16746It does not check the length of variable elements in a beacon head, leading to a buffer overflow.CRITICAL 9.8EPSS 12.7%24 September 2019
CVE-2019-1367Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 52.4%23 September 2019
CVE-2019-13063Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page.HIGH 7.5EPSS 27.2%23 September 2019
CVE-2019-16702Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.CRITICAL 9.8EPSS 10.7%23 September 2019
CVE-2019-16692phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.CRITICAL 9.8EPSS 10.3%22 September 2019
CVE-2015-9406Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a ..HIGH 7.5EPSS 55.0%20 September 2019
CVE-2019-15001The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote…HIGH 7.2EPSS 11.4%19 September 2019
CVE-2019-5482Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.CRITICAL 9.8EPSS 17.9%16 September 2019
CVE-2019-8368OpenEMR v5.0.1-6 allows XSS.MEDIUM 6.1EPSS 45.9%16 September 2019
CVE-2019-0195Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded.CRITICAL 9.8EPSS 13.9%16 September 2019
CVE-2019-16057D-Link DNS-320 Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 87.1%16 September 2019
CVE-2016-10956The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.HIGH 7.5EPSS 10.6%16 September 2019
CVE-2019-14540A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10.CRITICAL 9.8EPSS 10.8%15 September 2019
CVE-2019-16314Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.CRITICAL 9.8EPSS 38.7%14 September 2019
CVE-2019-16313ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.HIGH 7.5EPSS 46.1%14 September 2019
CVE-2019-5485NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability.CRITICAL 10.0EPSS 58.8%13 September 2019
CVE-2010-5333The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution.CRITICAL 9.8EPSS 16.0%13 September 2019
CVE-2019-12922A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.MEDIUM 6.5EPSS 10.1%13 September 2019
CVE-2019-10392Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.HIGH 8.8EPSS 25.8%12 September 2019
CVE-2019-1306A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.CRITICAL 9.8EPSS 17.0%11 September 2019
CVE-2019-1297Microsoft Excel Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 21.8%11 September 2019
CVE-2019-1291A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.5%11 September 2019
CVE-2019-1290A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.5%11 September 2019
CVE-2019-1280A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK…HIGH 7.8EPSS 19.0%11 September 2019
CVE-2019-1257A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.7%11 September 2019
CVE-2019-1253Microsoft Windows AppX Deployment Server Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 11.6%11 September 2019
CVE-2019-1252An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.MEDIUM 6.5EPSS 60.4%11 September 2019
CVE-2019-1250A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 18.5%11 September 2019
CVE-2019-1249A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.9%11 September 2019
CVE-2019-1248A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.9%11 September 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.