Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,466 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 127 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2018-20469 | A parameter in the web reports module is vulnerable to h2 SQL injection. | CRITICAL 9.8EPSS 18.5% | 17 June 2019 |
| CVE-2019-12840 | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi. | HIGH 8.8EPSS 77.8% | 15 June 2019 |
| CVE-2019-12828 | Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath… | HIGH 8.8EPSS 13.3% | 14 June 2019 |
| CVE-2019-12799 | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. | HIGH 8.8EPSS 54.7% | 13 June 2019 |
| CVE-2019-7840 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 17.2% | 12 June 2019 |
| CVE-2019-7839 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. | CRITICAL 9.8EPSS 44.1% | 12 June 2019 |
| CVE-2019-7838 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. | CRITICAL 9.8EPSS 17.4% | 12 June 2019 |
| CVE-2019-1040 | A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. | MEDIUM 5.3EPSS 48.0% | 12 June 2019 |
| CVE-2019-1019 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. | HIGH 8.5EPSS 15.1% | 12 June 2019 |
| CVE-2019-1009 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. | MEDIUM 4.7EPSS 48.5% | 12 June 2019 |
| CVE-2019-0948 | An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. | MEDIUM 4.7EPSS 12.7% | 12 June 2019 |
| CVE-2019-0888 | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. | HIGH 8.8EPSS 11.1% | 12 June 2019 |
| CVE-2019-0196 | A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. | MEDIUM 5.3EPSS 20.0% | 11 June 2019 |
| CVE-2019-0220 | A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. | MEDIUM 5.3EPSS 18.0% | 11 June 2019 |
| CVE-2018-20841 | HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. | CRITICAL 9.8EPSS 47.9% | 11 June 2019 |
| CVE-2013-7471 | There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request. | CRITICAL 9.8EPSS 24.0% | 11 June 2019 |
| CVE-2010-5330 | Ubiquiti AirOS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 33.8% | 11 June 2019 |
| CVE-2009-5156 | There is Command Injection via the cgi-bin/script query string. | CRITICAL 9.8EPSS 10.9% | 11 June 2019 |
| CVE-2019-12765 | The CSV export of com_actionslogs is vulnerable to CSV injection. | CRITICAL 9.8EPSS 10.5% | 11 June 2019 |
| CVE-2019-9881 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | MEDIUM 5.3EPSS 18.8% | 10 June 2019 |
| CVE-2019-9880 | By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. | CRITICAL 9.1EPSS 34.8% | 10 June 2019 |
| CVE-2019-9879 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. | CRITICAL 9.8EPSS 46.6% | 10 June 2019 |
| CVE-2019-12780 | The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. | CRITICAL 9.8EPSS 72.6% | 10 June 2019 |
| CVE-2019-3957 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information. | HIGH 7.4EPSS 25.6% | 7 June 2019 |
| CVE-2019-3955 | Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. | HIGH 7.5EPSS 17.9% | 7 June 2019 |
| CVE-2018-10700 | However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. | MEDIUM 6.1EPSS 38.3% | 7 June 2019 |
| CVE-2018-20523 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. | MEDIUM 5.3EPSS 10.0% | 7 June 2019 |
| CVE-2019-12477 | Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI. | MEDIUM 5.5EPSS 13.3% | 7 June 2019 |
| CVE-2019-6989 | TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. | HIGH 8.8EPSS 11.6% | 6 June 2019 |
| CVE-2019-11080 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. | HIGH 8.8EPSS 14.2% | 6 June 2019 |
| CVE-2019-8385 | An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. | CRITICAL 9.8EPSS 19.6% | 5 June 2019 |
| CVE-2019-9189 | The application allows the upload of arbitrary Python scripts when configuring the main central controller. | HIGH 8.8EPSS 11.6% | 5 June 2019 |
| CVE-2019-12276 | A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName=… | HIGH 7.5EPSS 57.1% | 5 June 2019 |
| CVE-2019-12196 | A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter. | CRITICAL 9.8EPSS 69.1% | 5 June 2019 |
| CVE-2019-5356 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | CRITICAL 9.8EPSS 10.9% | 5 June 2019 |
| CVE-2019-5355 | A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | HIGH 7.5EPSS 54.0% | 5 June 2019 |
| CVE-2019-11945 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | CRITICAL 9.8EPSS 78.6% | 5 June 2019 |
| CVE-2019-11944 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | CRITICAL 9.8EPSS 13.3% | 5 June 2019 |
| CVE-2018-7123 | A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | HIGH 7.5EPSS 57.7% | 5 June 2019 |
| CVE-2019-12735 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | HIGH 8.6EPSS 19.0% | 5 June 2019 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | KEVCRITICAL 9.8EPSS 100.0% | 5 June 2019 |
| CVE-2019-12616 | A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. | MEDIUM 6.5EPSS 19.2% | 5 June 2019 |
| CVE-2018-13382 | Fortinet FortiOS and FortiProxy Improper Authorization | KEVHIGH 7.5EPSS 81.7% | 4 June 2019 |
| CVE-2018-13380 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious… | MEDIUM 6.1EPSS 62.5% | 4 June 2019 |
| CVE-2018-13379 | Fortinet FortiOS SSL VPN Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 4 June 2019 |
| CVE-2019-10883 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | CRITICAL 9.8EPSS 65.5% | 3 June 2019 |
| CVE-2019-10009 | A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. | MEDIUM 6.5EPSS 11.5% | 3 June 2019 |
| CVE-2019-12169 | ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or… | HIGH 8.8EPSS 73.3% | 3 June 2019 |
| CVE-2019-6753 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.3.0.10826. | MEDIUM 5.5EPSS 10.7% | 3 June 2019 |
| CVE-2018-5406 | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. | HIGH 8.8EPSS 12.2% | 3 June 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.