Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,450 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 123 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-11013 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. | MEDIUM 6.5EPSS 27.4% | 22 August 2019 |
| CVE-2017-18580 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode. | CRITICAL 9.8EPSS 12.1% | 22 August 2019 |
| CVE-2016-10924 | The ebook-download plugin before 1.2 for WordPress has directory traversal. | HIGH 7.5EPSS 11.7% | 22 August 2019 |
| CVE-2019-1937 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session… | CRITICAL 9.8EPSS 75.9% | 21 August 2019 |
| CVE-2019-1936 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands… | HIGH 7.2EPSS 39.5% | 21 August 2019 |
| CVE-2019-1935 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User… | CRITICAL 9.8EPSS 83.4% | 21 August 2019 |
| CVE-2019-12624 | A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an… | HIGH 8.8EPSS 18.2% | 21 August 2019 |
| CVE-2019-8050 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 40.6% | 20 August 2019 |
| CVE-2019-10086 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. | HIGH 7.3EPSS 29.2% | 20 August 2019 |
| CVE-2019-8049 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 19.7% | 20 August 2019 |
| CVE-2019-8048 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a buffer error vulnerability. | CRITICAL 9.8EPSS 34.6% | 20 August 2019 |
| CVE-2019-8046 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 17.9% | 20 August 2019 |
| CVE-2019-8045 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference… | CRITICAL 9.8EPSS 16.0% | 20 August 2019 |
| CVE-2019-8044 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. | CRITICAL 9.8EPSS 14.5% | 20 August 2019 |
| CVE-2019-8043 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. | HIGH 7.5EPSS 13.4% | 20 August 2019 |
| CVE-2019-8042 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 16.8% | 20 August 2019 |
| CVE-2019-8041 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. | CRITICAL 9.8EPSS 17.9% | 20 August 2019 |
| CVE-2019-8024 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. | CRITICAL 9.8EPSS 15.1% | 20 August 2019 |
| CVE-2019-8017 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference… | CRITICAL 9.8EPSS 13.3% | 20 August 2019 |
| CVE-2019-8016 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. | CRITICAL 9.8EPSS 22.0% | 20 August 2019 |
| CVE-2019-3967 | In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system. | MEDIUM 6.5EPSS 29.5% | 20 August 2019 |
| CVE-2019-3964 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. | MEDIUM 6.1EPSS 52.7% | 20 August 2019 |
| CVE-2019-3963 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. | MEDIUM 6.1EPSS 52.7% | 20 August 2019 |
| CVE-2015-9323 | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. | CRITICAL 9.8EPSS 46.1% | 16 August 2019 |
| CVE-2019-7964 | Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. | CRITICAL 9.8EPSS 10.2% | 16 August 2019 |
| CVE-2019-15107 | Webmin Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.8% | 16 August 2019 |
| CVE-2019-15106 | One can bypass the user password requirement and execute commands on the server. | CRITICAL 9.8EPSS 25.5% | 16 August 2019 |
| CVE-2019-9851 | LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. | CRITICAL 9.8EPSS 78.3% | 15 August 2019 |
| CVE-2019-10081 | HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. | HIGH 7.5EPSS 14.6% | 15 August 2019 |
| CVE-2019-13510 | Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. | HIGH 7.8EPSS 12.0% | 15 August 2019 |
| CVE-2019-14422 | The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code. | HIGH 8.8EPSS 16.4% | 15 August 2019 |
| CVE-2019-12854 | On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it. | HIGH 7.5EPSS 11.7% | 15 August 2019 |
| CVE-2019-1184 | An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. | MEDIUM 6.7EPSS 70.2% | 14 August 2019 |
| CVE-2019-1182 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. | CRITICAL 9.8EPSS 16.8% | 14 August 2019 |
| CVE-2019-1181 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. | CRITICAL 9.8EPSS 75.8% | 14 August 2019 |
| CVE-2019-1159 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. | HIGH 7.8EPSS 11.3% | 14 August 2019 |
| CVE-2019-1152 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-1151 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 15.5% | 14 August 2019 |
| CVE-2019-1150 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 28.9% | 14 August 2019 |
| CVE-2019-1149 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 13.9% | 14 August 2019 |
| CVE-2019-1145 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-1144 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. | HIGH 8.8EPSS 13.1% | 14 August 2019 |
| CVE-2019-14974 | SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. | MEDIUM 6.1EPSS 28.4% | 14 August 2019 |
| CVE-2019-9518 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. | HIGH 7.5EPSS 25.4% | 13 August 2019 |
| CVE-2019-9517 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. | HIGH 7.5EPSS 27.9% | 13 August 2019 |
| CVE-2019-9516 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. | MEDIUM 6.5EPSS 56.3% | 13 August 2019 |
| CVE-2019-9515 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. | HIGH 7.5EPSS 87.4% | 13 August 2019 |
| CVE-2019-9514 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. | HIGH 7.5EPSS 82.8% | 13 August 2019 |
| CVE-2019-9513 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. | HIGH 7.5EPSS 81.6% | 13 August 2019 |
| CVE-2019-9512 | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. | HIGH 7.5EPSS 83.4% | 13 August 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.