SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,450 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 123 of 348

CVESummaryPriorityPublished
CVE-2019-11013Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability.MEDIUM 6.5EPSS 27.4%22 August 2019
CVE-2017-18580The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.CRITICAL 9.8EPSS 12.1%22 August 2019
CVE-2016-10924The ebook-download plugin before 1.2 for WordPress has directory traversal.HIGH 7.5EPSS 11.7%22 August 2019
CVE-2019-1937A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session…CRITICAL 9.8EPSS 75.9%21 August 2019
CVE-2019-1936A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands…HIGH 7.2EPSS 39.5%21 August 2019
CVE-2019-1935A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User…CRITICAL 9.8EPSS 83.4%21 August 2019
CVE-2019-12624A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an…HIGH 8.8EPSS 18.2%21 August 2019
CVE-2019-8050Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 40.6%20 August 2019
CVE-2019-10086In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.HIGH 7.3EPSS 29.2%20 August 2019
CVE-2019-8049Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 19.7%20 August 2019
CVE-2019-8048Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability.CRITICAL 9.8EPSS 34.6%20 August 2019
CVE-2019-8046Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 17.9%20 August 2019
CVE-2019-8045Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference…CRITICAL 9.8EPSS 16.0%20 August 2019
CVE-2019-8044Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability.CRITICAL 9.8EPSS 14.5%20 August 2019
CVE-2019-8043Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability.HIGH 7.5EPSS 13.4%20 August 2019
CVE-2019-8042Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 16.8%20 August 2019
CVE-2019-8041Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability.CRITICAL 9.8EPSS 17.9%20 August 2019
CVE-2019-8024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability.CRITICAL 9.8EPSS 15.1%20 August 2019
CVE-2019-8017Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference…CRITICAL 9.8EPSS 13.3%20 August 2019
CVE-2019-8016Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability.CRITICAL 9.8EPSS 22.0%20 August 2019
CVE-2019-3967In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.MEDIUM 6.5EPSS 29.5%20 August 2019
CVE-2019-3964In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter.MEDIUM 6.1EPSS 52.7%20 August 2019
CVE-2019-3963In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter.MEDIUM 6.1EPSS 52.7%20 August 2019
CVE-2015-9323The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.CRITICAL 9.8EPSS 46.1%16 August 2019
CVE-2019-7964Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability.CRITICAL 9.8EPSS 10.2%16 August 2019
CVE-2019-15107Webmin Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.8%16 August 2019
CVE-2019-15106One can bypass the user password requirement and execute commands on the server.CRITICAL 9.8EPSS 25.5%16 August 2019
CVE-2019-9851LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from.CRITICAL 9.8EPSS 78.3%15 August 2019
CVE-2019-10081HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes.HIGH 7.5EPSS 14.6%15 August 2019
CVE-2019-13510Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416.HIGH 7.8EPSS 12.0%15 August 2019
CVE-2019-14422The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code.HIGH 8.8EPSS 16.4%15 August 2019
CVE-2019-12854On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.HIGH 7.5EPSS 11.7%15 August 2019
CVE-2019-1184An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls.MEDIUM 6.7EPSS 70.2%14 August 2019
CVE-2019-1182A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests.CRITICAL 9.8EPSS 16.8%14 August 2019
CVE-2019-1181A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests.CRITICAL 9.8EPSS 75.8%14 August 2019
CVE-2019-1159An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory.HIGH 7.8EPSS 11.3%14 August 2019
CVE-2019-1152A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-1151A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 15.5%14 August 2019
CVE-2019-1150A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 28.9%14 August 2019
CVE-2019-1149A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 13.9%14 August 2019
CVE-2019-1145A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-1144A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts.HIGH 8.8EPSS 13.1%14 August 2019
CVE-2019-14974SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.MEDIUM 6.1EPSS 28.4%14 August 2019
CVE-2019-9518Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service.HIGH 7.5EPSS 25.4%13 August 2019
CVE-2019-9517Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service.HIGH 7.5EPSS 27.9%13 August 2019
CVE-2019-9516Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service.MEDIUM 6.5EPSS 56.3%13 August 2019
CVE-2019-9515Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.HIGH 7.5EPSS 87.4%13 August 2019
CVE-2019-9514Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service.HIGH 7.5EPSS 82.8%13 August 2019
CVE-2019-9513Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service.HIGH 7.5EPSS 81.6%13 August 2019
CVE-2019-9512Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service.HIGH 7.5EPSS 83.4%13 August 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.