SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,466 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 126 of 348

CVESummaryPriorityPublished
CVE-2017-8416This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications to discover D-Link devices on the local network.HIGH 8.8EPSS 11.6%2 July 2019
CVE-2017-8413This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications to discover D-Link devices on the local network.HIGH 8.8EPSS 10.2%2 July 2019
CVE-2019-7258Linear eMerge E3-Series devices allow Privilege Escalation.HIGH 8.8EPSS 19.6%2 July 2019
CVE-2019-7257Linear eMerge E3-Series devices allow Unrestricted File Upload.CRITICAL 10.0EPSS 70.0%2 July 2019
CVE-2019-7256Nice Linear eMerge E3-Series OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 97.1%2 July 2019
CVE-2019-7255Linear eMerge E3-Series devices allow XSS.MEDIUM 6.1EPSS 55.8%2 July 2019
CVE-2019-7254Linear eMerge E3-Series devices allow File Inclusion.HIGH 7.5EPSS 82.3%2 July 2019
CVE-2019-7262Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).HIGH 8.8EPSS 16.3%2 July 2019
CVE-2019-7259Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.HIGH 8.8EPSS 13.2%2 July 2019
CVE-2019-7269Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.CRITICAL 9.8EPSS 40.0%2 July 2019
CVE-2019-7267Linear eMerge 50P/5000P devices allow Cookie Path Traversal.CRITICAL 9.8EPSS 21.5%2 July 2019
CVE-2019-7265Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).CRITICAL 9.8EPSS 23.1%2 July 2019
CVE-2019-7274Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.CRITICAL 9.8EPSS 29.0%1 July 2019
CVE-2019-7272Optergy Proton/Enterprise devices allow Username Disclosure.MEDIUM 5.3EPSS 10.5%1 July 2019
CVE-2019-7276Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.CRITICAL 9.8EPSS 93.4%1 July 2019
CVE-2019-7670The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.HIGH 7.2EPSS 18.3%1 July 2019
CVE-2019-7669Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.HIGH 8.8EPSS 31.4%1 July 2019
CVE-2019-7666The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.HIGH 8.8EPSS 14.8%1 July 2019
CVE-2019-13024Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the…HIGH 8.8EPSS 32.2%1 July 2019
CVE-2019-13086core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.CRITICAL 9.8EPSS 32.0%30 June 2019
CVE-2019-13068public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).MEDIUM 5.4EPSS 51.9%30 June 2019
CVE-2019-10993In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code.CRITICAL 9.8EPSS 10.7%28 June 2019
CVE-2018-14918LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.HIGH 7.5EPSS 18.6%28 June 2019
CVE-2018-14916LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.CRITICAL 9.1EPSS 17.2%28 June 2019
CVE-2019-5786Google Chrome Blink Use-After-Free VulnerabilityKEVMEDIUM 6.5EPSS 61.5%27 June 2019
CVE-2019-12583Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator.CRITICAL 9.1EPSS 43.9%27 June 2019
CVE-2019-1622A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device.MEDIUM 5.3EPSS 78.9%27 June 2019
CVE-2019-1621A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device.HIGH 7.5EPSS 29.8%27 June 2019
CVE-2019-1620A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device.CRITICAL 9.8EPSS 83.8%27 June 2019
CVE-2019-1619A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device.CRITICAL 9.8EPSS 82.8%27 June 2019
CVE-2019-7232The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.HIGH 8.8EPSS 52.1%24 June 2019
CVE-2019-12384FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization.MEDIUM 5.9EPSS 45.2%24 June 2019
CVE-2019-12928The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening…CRITICAL 9.8EPSS 23.0%24 June 2019
CVE-2019-10072The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 .HIGH 7.5EPSS 73.0%21 June 2019
CVE-2019-12744SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.HIGH 7.5EPSS 11.7%20 June 2019
CVE-2018-16117A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.HIGH 8.8EPSS 44.3%20 June 2019
CVE-2018-16119Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.HIGH 7.2EPSS 34.1%20 June 2019
CVE-2019-1898A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device.MEDIUM 5.3EPSS 41.7%20 June 2019
CVE-2019-2729Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).CRITICAL 9.8EPSS 88.8%19 June 2019
CVE-2018-18472Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.CRITICAL 9.8EPSS 30.3%19 June 2019
CVE-2019-6971An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.CRITICAL 9.8EPSS 13.7%19 June 2019
CVE-2019-12814When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to…MEDIUM 5.9EPSS 10.9%19 June 2019
CVE-2019-11479Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes.HIGH 7.5EPSS 91.7%19 June 2019
CVE-2019-11478A remote attacker could use this to cause a denial of service.HIGH 7.5EPSS 94.7%19 June 2019
CVE-2019-11477Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs).HIGH 7.5EPSS 98.7%19 June 2019
CVE-2018-18852Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.HIGH 8.8EPSS 63.8%18 June 2019
CVE-2019-7315Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow.HIGH 7.5EPSS 11.2%17 June 2019
CVE-2019-11409app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host.HIGH 8.8EPSS 87.5%17 June 2019
CVE-2019-12181A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.HIGH 8.8EPSS 66.0%17 June 2019
CVE-2018-20470A directory traversal (arbitrary file access) vulnerability exists in the web reports module.HIGH 7.5EPSS 46.1%17 June 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.