Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,466 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 125 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-12991 | Citrix SD-WAN and NetScaler Command Injection Vulnerability | KEVHIGH 8.8EPSS 74.1% | 16 July 2019 |
| CVE-2019-12990 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | CRITICAL 9.8EPSS 39.3% | 16 July 2019 |
| CVE-2019-12989 | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.1% | 16 July 2019 |
| CVE-2019-12988 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). | CRITICAL 9.8EPSS 42.6% | 16 July 2019 |
| CVE-2019-12987 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). | CRITICAL 9.8EPSS 42.6% | 16 July 2019 |
| CVE-2019-12986 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | CRITICAL 9.8EPSS 39.5% | 16 July 2019 |
| CVE-2019-12985 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | CRITICAL 9.8EPSS 39.5% | 16 July 2019 |
| CVE-2019-13605 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. | HIGH 8.8EPSS 15.3% | 16 July 2019 |
| CVE-2019-13383 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response. | MEDIUM 5.3EPSS 14.2% | 16 July 2019 |
| CVE-2019-13360 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username. | CRITICAL 9.8EPSS 24.4% | 16 July 2019 |
| CVE-2019-1128 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.9% | 15 July 2019 |
| CVE-2019-1127 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 20.6% | 15 July 2019 |
| CVE-2019-1124 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 18.4% | 15 July 2019 |
| CVE-2019-1123 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.9% | 15 July 2019 |
| CVE-2019-1122 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.9% | 15 July 2019 |
| CVE-2019-1121 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.9% | 15 July 2019 |
| CVE-2019-1120 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.9% | 15 July 2019 |
| CVE-2019-1119 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 19.4% | 15 July 2019 |
| CVE-2019-1118 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 23.6% | 15 July 2019 |
| CVE-2019-1117 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 23.6% | 15 July 2019 |
| CVE-2019-1111 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.2% | 15 July 2019 |
| CVE-2019-1110 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.2% | 15 July 2019 |
| CVE-2019-1108 | An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'. | MEDIUM 6.5EPSS 10.7% | 15 July 2019 |
| CVE-2019-1102 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.3% | 15 July 2019 |
| CVE-2019-1072 | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 12.4% | 15 July 2019 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 52.8% | 15 July 2019 |
| CVE-2019-0887 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | HIGH 8.0EPSS 71.0% | 15 July 2019 |
| CVE-2019-0785 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 49.6% | 15 July 2019 |
| CVE-2019-13597 | _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. | CRITICAL 9.8EPSS 14.3% | 14 July 2019 |
| CVE-2019-12527 | Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data. | HIGH 8.8EPSS 49.0% | 11 July 2019 |
| CVE-2019-12525 | An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. | CRITICAL 9.8EPSS 24.4% | 11 July 2019 |
| CVE-2019-10193 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. | HIGH 7.2EPSS 23.7% | 11 July 2019 |
| CVE-2019-10192 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. | HIGH 7.2EPSS 26.0% | 11 July 2019 |
| CVE-2019-13132 | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and… | CRITICAL 9.8EPSS 41.6% | 10 July 2019 |
| CVE-2018-19571 | GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks. | HIGH 7.7EPSS 28.2% | 10 July 2019 |
| CVE-2019-13396 | FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in… | MEDIUM 5.3EPSS 62.6% | 10 July 2019 |
| CVE-2019-13375 | A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. | CRITICAL 9.8EPSS 28.2% | 6 July 2019 |
| CVE-2019-13373 | Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL. | CRITICAL 9.8EPSS 68.0% | 6 July 2019 |
| CVE-2019-13372 | /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password… | CRITICAL 9.8EPSS 82.5% | 6 July 2019 |
| CVE-2019-13358 | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. | HIGH 7.5EPSS 23.8% | 5 July 2019 |
| CVE-2019-13345 | The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter. | MEDIUM 6.1EPSS 74.5% | 5 July 2019 |
| CVE-2019-13344 | An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. | MEDIUM 5.3EPSS 45.1% | 5 July 2019 |
| CVE-2019-13294 | AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. | CRITICAL 9.8EPSS 18.8% | 4 July 2019 |
| CVE-2019-9827 | Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI. | CRITICAL 9.8EPSS 26.8% | 3 July 2019 |
| CVE-2017-8229 | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. | CRITICAL 9.8EPSS 74.2% | 3 July 2019 |
| CVE-2018-18326 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. | HIGH 7.5EPSS 54.5% | 3 July 2019 |
| CVE-2018-18325 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | KEVHIGH 7.5EPSS 74.0% | 3 July 2019 |
| CVE-2018-15812 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | HIGH 7.5EPSS 47.5% | 3 July 2019 |
| CVE-2018-15811 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | KEVHIGH 7.5EPSS 74.0% | 3 July 2019 |
| CVE-2018-11686 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | CRITICAL 9.8EPSS 52.5% | 3 July 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.