SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,466 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 127 of 348

CVESummaryPriorityPublished
CVE-2018-20469A parameter in the web reports module is vulnerable to h2 SQL injection.CRITICAL 9.8EPSS 18.5%17 June 2019
CVE-2019-12840In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.HIGH 8.8EPSS 77.8%15 June 2019
CVE-2019-12828Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath…HIGH 8.8EPSS 13.3%14 June 2019
CVE-2019-12799In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated.HIGH 8.8EPSS 54.7%13 June 2019
CVE-2019-7840ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability.CRITICAL 9.8EPSS 17.2%12 June 2019
CVE-2019-7839ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability.CRITICAL 9.8EPSS 44.1%12 June 2019
CVE-2019-7838ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability.CRITICAL 9.8EPSS 17.4%12 June 2019
CVE-2019-1040A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection.MEDIUM 5.3EPSS 48.0%12 June 2019
CVE-2019-1019A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.HIGH 8.5EPSS 15.1%12 June 2019
CVE-2019-1009An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory.MEDIUM 4.7EPSS 48.5%12 June 2019
CVE-2019-0948An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity.MEDIUM 4.7EPSS 12.7%12 June 2019
CVE-2019-0888A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory.HIGH 8.8EPSS 11.1%12 June 2019
CVE-2019-0196A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38.MEDIUM 5.3EPSS 20.0%11 June 2019
CVE-2019-0220A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38.MEDIUM 5.3EPSS 18.0%11 June 2019
CVE-2018-20841HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.CRITICAL 9.8EPSS 47.9%11 June 2019
CVE-2013-7471There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.CRITICAL 9.8EPSS 24.0%11 June 2019
CVE-2010-5330Ubiquiti AirOS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 33.8%11 June 2019
CVE-2009-5156There is Command Injection via the cgi-bin/script query string.CRITICAL 9.8EPSS 10.9%11 June 2019
CVE-2019-12765The CSV export of com_actionslogs is vulnerable to CSV injection.CRITICAL 9.8EPSS 10.5%11 June 2019
CVE-2019-9881The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.MEDIUM 5.3EPSS 18.8%10 June 2019
CVE-2019-9880By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.CRITICAL 9.1EPSS 34.8%10 June 2019
CVE-2019-9879The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed.CRITICAL 9.8EPSS 46.6%10 June 2019
CVE-2019-12780The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action.CRITICAL 9.8EPSS 72.6%10 June 2019
CVE-2019-3957Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.HIGH 7.4EPSS 25.6%7 June 2019
CVE-2019-3955Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation.HIGH 7.5EPSS 17.9%7 June 2019
CVE-2018-10700However, the same functionality allows an attacker to execute XSS by injecting an XSS payload.MEDIUM 6.1EPSS 38.3%7 June 2019
CVE-2018-20523Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection.MEDIUM 5.3EPSS 10.0%7 June 2019
CVE-2019-12477Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.MEDIUM 5.5EPSS 13.3%7 June 2019
CVE-2019-6989TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function.HIGH 8.8EPSS 11.6%6 June 2019
CVE-2019-11080Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.HIGH 8.8EPSS 14.2%6 June 2019
CVE-2019-8385An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677.CRITICAL 9.8EPSS 19.6%5 June 2019
CVE-2019-9189The application allows the upload of arbitrary Python scripts when configuring the main central controller.HIGH 8.8EPSS 11.6%5 June 2019
CVE-2019-12276A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName=…HIGH 7.5EPSS 57.1%5 June 2019
CVE-2019-12196A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.CRITICAL 9.8EPSS 69.1%5 June 2019
CVE-2019-5356A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.CRITICAL 9.8EPSS 10.9%5 June 2019
CVE-2019-5355A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.HIGH 7.5EPSS 54.0%5 June 2019
CVE-2019-11945A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.CRITICAL 9.8EPSS 78.6%5 June 2019
CVE-2019-11944A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.CRITICAL 9.8EPSS 13.3%5 June 2019
CVE-2018-7123A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.HIGH 7.5EPSS 57.7%5 June 2019
CVE-2019-12735getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.HIGH 8.6EPSS 19.0%5 June 2019
CVE-2019-10149Exim Mail Transfer Agent (MTA) Improper Input ValidationKEVCRITICAL 9.8EPSS 100.0%5 June 2019
CVE-2019-12616A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user.MEDIUM 6.5EPSS 19.2%5 June 2019
CVE-2018-13382Fortinet FortiOS and FortiProxy Improper AuthorizationKEVHIGH 7.5EPSS 81.7%4 June 2019
CVE-2018-13380A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious…MEDIUM 6.1EPSS 62.5%4 June 2019
CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%4 June 2019
CVE-2019-10883Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.CRITICAL 9.8EPSS 65.5%3 June 2019
CVE-2019-10009A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505.MEDIUM 6.5EPSS 11.5%3 June 2019
CVE-2019-12169ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or…HIGH 8.8EPSS 73.3%3 June 2019
CVE-2019-6753This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.3.0.10826.MEDIUM 5.5EPSS 10.7%3 June 2019
CVE-2018-5406The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism.HIGH 8.8EPSS 12.2%3 June 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.