SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,450 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 124 of 348

CVESummaryPriorityPublished
CVE-2019-9511Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service.HIGH 7.5EPSS 59.5%13 August 2019
CVE-2019-14530An attacker can download any file (that is readable by the user www-data) from server storage.HIGH 8.8EPSS 65.5%13 August 2019
CVE-2019-13462Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.CRITICAL 9.1EPSS 11.3%12 August 2019
CVE-2019-12260Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4).CRITICAL 9.8EPSS 22.8%9 August 2019
CVE-2019-12258This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.HIGH 7.5EPSS 23.4%9 August 2019
CVE-2019-12255Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).CRITICAL 9.8EPSS 75.3%9 August 2019
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection VulnerabilityKEVCRITICAL 9.8EPSS 84.6%9 August 2019
CVE-2019-12265Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.MEDIUM 5.3EPSS 59.8%9 August 2019
CVE-2019-12259There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.HIGH 7.5EPSS 15.9%9 August 2019
CVE-2019-12257Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component.HIGH 8.8EPSS 84.2%9 August 2019
CVE-2019-12256Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component.CRITICAL 9.8EPSS 26.6%9 August 2019
CVE-2019-14312Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer.MEDIUM 6.5EPSS 20.6%9 August 2019
CVE-2019-14234Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection.CRITICAL 9.8EPSS 47.7%9 August 2019
CVE-2019-13101An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the…CRITICAL 9.8EPSS 67.1%8 August 2019
CVE-2019-14750Stored XSS exists in setup/install.php.MEDIUM 6.1EPSS 10.9%7 August 2019
CVE-2019-1914A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack.HIGH 7.2EPSS 24.9%7 August 2019
CVE-2019-1913Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on…CRITICAL 9.8EPSS 25.9%7 August 2019
CVE-2019-1912A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files.CRITICAL 9.1EPSS 17.0%7 August 2019
CVE-2019-14696Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.MEDIUM 6.1EPSS 15.7%6 August 2019
CVE-2019-14348The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.CRITICAL 9.8EPSS 20.5%5 August 2019
CVE-2019-14529OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.CRITICAL 9.8EPSS 28.1%2 August 2019
CVE-2019-0193Apache Solr DataImportHandler Code Injection VulnerabilityKEVHIGH 7.2EPSS 83.5%1 August 2019
CVE-2019-13635The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.CRITICAL 9.1EPSS 44.4%30 July 2019
CVE-2019-14439This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.HIGH 7.5EPSS 10.8%30 July 2019
CVE-2019-3948An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.HIGH 7.5EPSS 25.0%29 July 2019
CVE-2019-14271In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.CRITICAL 9.8EPSS 18.8%29 July 2019
CVE-2019-14378ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.HIGH 8.8EPSS 16.7%29 July 2019
CVE-2019-14322In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.HIGH 7.5EPSS 55.8%28 July 2019
CVE-2019-10267An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50.HIGH 8.8EPSS 75.2%26 July 2019
CVE-2019-10266When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.HIGH 7.5EPSS 13.3%26 July 2019
CVE-2019-13990initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.CRITICAL 9.8EPSS 16.2%26 July 2019
CVE-2019-11730A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed.MEDIUM 6.5EPSS 20.3%23 July 2019
CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape VulnerabilityKEVCRITICAL 10.0EPSS 55.9%23 July 2019
CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion VulnerabilityKEVHIGH 8.8EPSS 37.7%23 July 2019
CVE-2019-11704A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting in a potentially exploitable crash.CRITICAL 9.8EPSS 10.5%23 July 2019
CVE-2019-11703A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash.CRITICAL 9.8EPSS 10.5%23 July 2019
CVE-2019-14241HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.HIGH 7.5EPSS 70.2%23 July 2019
CVE-2019-10173It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.CRITICAL 9.8EPSS 95.0%23 July 2019
CVE-2019-14205A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.HIGH 7.5EPSS 63.4%21 July 2019
CVE-2019-12815An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.CRITICAL 9.8EPSS 57.6%19 July 2019
CVE-2019-12725Zeroshell 3.9.0 is prone to a remote command execution vulnerability.CRITICAL 9.8EPSS 89.8%19 July 2019
CVE-2019-1579Palo Alto Networks PAN-OS Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 46.2%19 July 2019
CVE-2019-13577SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.CRITICAL 9.8EPSS 24.4%17 July 2019
CVE-2019-13585The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.CRITICAL 9.8EPSS 14.7%17 July 2019
CVE-2019-10352A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the…MEDIUM 6.5EPSS 10.2%17 July 2019
CVE-2019-13272Linux Kernel Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 52.2%17 July 2019
CVE-2019-9848LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc.CRITICAL 9.8EPSS 31.4%17 July 2019
CVE-2019-13359In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.HIGH 7.5EPSS 25.8%16 July 2019
CVE-2019-13115In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server.HIGH 8.1EPSS 11.7%16 July 2019
CVE-2019-12992Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).HIGH 8.8EPSS 48.9%16 July 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.