SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,450 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 19 September 2026

17,384 results · page 122 of 348

CVESummaryPriorityPublished
CVE-2019-1247A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.9%11 September 2019
CVE-2019-1246A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 12.6%11 September 2019
CVE-2019-1245An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.MEDIUM 6.5EPSS 12.9%11 September 2019
CVE-2019-1244An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.MEDIUM 6.5EPSS 12.1%11 September 2019
CVE-2019-1243A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 18.5%11 September 2019
CVE-2019-1242A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.9%11 September 2019
CVE-2019-1241A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 17.2%11 September 2019
CVE-2019-1240A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 11.9%11 September 2019
CVE-2019-1221A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 19.1%11 September 2019
CVE-2019-1215Microsoft Windows Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 19.3%11 September 2019
CVE-2019-1208A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.HIGH 7.5EPSS 12.6%11 September 2019
CVE-2019-0788A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.5%11 September 2019
CVE-2019-0787A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.5%11 September 2019
CVE-2019-0189This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution.CRITICAL 9.8EPSS 23.7%11 September 2019
CVE-2019-16098The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs.HIGH 7.8EPSS 19.8%11 September 2019
CVE-2019-8451The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist…MEDIUM 6.5EPSS 94.5%11 September 2019
CVE-2019-8449The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.MEDIUM 5.3EPSS 84.8%11 September 2019
CVE-2019-15639main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.HIGH 7.5EPSS 21.9%9 September 2019
CVE-2019-10669There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function.HIGH 7.2EPSS 80.7%9 September 2019
CVE-2019-16124In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.CRITICAL 9.8EPSS 27.6%9 September 2019
CVE-2019-16123In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.HIGH 7.5EPSS 16.6%9 September 2019
CVE-2019-16119SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.CRITICAL 9.8EPSS 24.8%8 September 2019
CVE-2019-16113Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.HIGH 8.8EPSS 78.0%8 September 2019
CVE-2019-16097core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration.MEDIUM 6.5EPSS 22.4%8 September 2019
CVE-2019-10891There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbitrary shell commands with a special HTTP header.CRITICAL 9.8EPSS 19.4%6 September 2019
CVE-2019-14813A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.CRITICAL 9.8EPSS 11.4%6 September 2019
CVE-2019-15846Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.CRITICAL 9.8EPSS 35.7%6 September 2019
CVE-2019-15029FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database).HIGH 8.8EPSS 12.3%5 September 2019
CVE-2019-15954An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side.CRITICAL 9.9EPSS 78.7%5 September 2019
CVE-2019-15949Nagios XI Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 77.0%5 September 2019
CVE-2019-14470cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.MEDIUM 6.1EPSS 83.0%4 September 2019
CVE-2019-15813Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.HIGH 8.8EPSS 33.2%4 September 2019
CVE-2019-10709AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.CRITICAL 9.8EPSS 11.5%4 September 2019
CVE-2019-5475The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.HIGH 8.8EPSS 18.4%3 September 2019
CVE-2019-15889The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.MEDIUM 6.1EPSS 11.4%3 September 2019
CVE-2019-15043In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use.HIGH 7.5EPSS 63.4%3 September 2019
CVE-2019-15858admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.HIGH 8.8EPSS 18.5%3 September 2019
CVE-2019-15821The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.HIGH 7.5EPSS 11.0%30 August 2019
CVE-2019-12402This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.HIGH 7.5EPSS 16.2%30 August 2019
CVE-2019-13608Citrix StoreFront Server XML External Entity (XXE) Processing VulnerabilityKEVHIGH 7.5EPSS 30.0%29 August 2019
CVE-2019-3394There was a local file disclosure vulnerability in Confluence Server and Confluence Data Center via page exporting.HIGH 8.8EPSS 11.0%29 August 2019
CVE-2019-11500This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.CRITICAL 9.8EPSS 62.6%29 August 2019
CVE-2019-11248The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port.HIGH 8.2EPSS 75.1%29 August 2019
CVE-2019-15752Docker Desktop Community Edition Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 31.9%28 August 2019
CVE-2019-14314A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.CRITICAL 9.8EPSS 43.4%27 August 2019
CVE-2019-7989Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability.HIGH 8.8EPSS 14.2%26 August 2019
CVE-2019-15642rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.HIGH 8.8EPSS 34.8%26 August 2019
CVE-2019-15637Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS.HIGH 8.1EPSS 14.3%26 August 2019
CVE-2019-8446The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.MEDIUM 5.3EPSS 17.5%23 August 2019
CVE-2019-11013Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability.MEDIUM 6.5EPSS 27.4%22 August 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.