Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 128 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-12593 | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. | HIGH 7.5EPSS 41.0% | 3 June 2019 |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 95.4% | 3 June 2019 |
| CVE-2019-12569 | A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. | HIGH 7.8EPSS 15.0% | 3 June 2019 |
| CVE-2019-9653 | NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php. | CRITICAL 9.8EPSS 11.5% | 31 May 2019 |
| CVE-2019-10123 | SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. | CRITICAL 9.8EPSS 65.8% | 31 May 2019 |
| CVE-2019-9875 | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | KEVHIGH 8.8EPSS 14.0% | 31 May 2019 |
| CVE-2019-9874 | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | KEVCRITICAL 9.8EPSS 83.7% | 31 May 2019 |
| CVE-2019-12480 | BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. | HIGH 7.5EPSS 33.7% | 30 May 2019 |
| CVE-2019-8457 | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables. | CRITICAL 9.8EPSS 45.4% | 30 May 2019 |
| CVE-2019-9670 | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | KEVCRITICAL 9.8EPSS 100.0% | 29 May 2019 |
| CVE-2019-12347 | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. | MEDIUM 6.1EPSS 58.6% | 29 May 2019 |
| CVE-2018-13383 | Fortinet FortiOS and FortiProxy Out-of-bounds Write | KEVMEDIUM 6.5EPSS 33.6% | 29 May 2019 |
| CVE-2019-9858 | Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. | HIGH 8.8EPSS 19.2% | 29 May 2019 |
| CVE-2019-0221 | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. | MEDIUM 6.1EPSS 45.6% | 28 May 2019 |
| CVE-2019-5436 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | HIGH 7.8EPSS 49.7% | 28 May 2019 |
| CVE-2019-7091 | ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier have a deserialization of untrusted data vulnerability. | CRITICAL 9.8EPSS 25.7% | 24 May 2019 |
| CVE-2019-7089 | Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a data leakage (sensitive) vulnerability. | HIGH 7.5EPSS 44.8% | 24 May 2019 |
| CVE-2019-7816 | ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. | CRITICAL 9.8EPSS 67.6% | 24 May 2019 |
| CVE-2019-12314 | Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI. | CRITICAL 9.8EPSS 84.2% | 24 May 2019 |
| CVE-2019-7127 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 15.1% | 23 May 2019 |
| CVE-2019-7111 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. | HIGH 8.8EPSS 55.9% | 23 May 2019 |
| CVE-2019-7110 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 15.1% | 23 May 2019 |
| CVE-2019-7109 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. | MEDIUM 6.5EPSS 15.1% | 23 May 2019 |
| CVE-2019-7125 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. | HIGH 8.8EPSS 14.0% | 23 May 2019 |
| CVE-2019-7107 | Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. | CRITICAL 9.8EPSS 27.8% | 23 May 2019 |
| CVE-2019-6814 | A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the… | CRITICAL 9.8EPSS 36.6% | 22 May 2019 |
| CVE-2018-7846 | A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on… | CRITICAL 9.8EPSS 29.6% | 22 May 2019 |
| CVE-2018-7842 | A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters… | CRITICAL 9.8EPSS 35.0% | 22 May 2019 |
| CVE-2018-7841 | Schneider Electric U.motion Builder SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 72.7% | 22 May 2019 |
| CVE-2019-8442 | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory… | HIGH 7.5EPSS 59.8% | 22 May 2019 |
| CVE-2019-7828 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability. | HIGH 8.8EPSS 13.6% | 22 May 2019 |
| CVE-2019-7827 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability. | HIGH 8.8EPSS 13.6% | 22 May 2019 |
| CVE-2019-7824 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a buffer error vulnerability. | HIGH 8.8EPSS 10.8% | 22 May 2019 |
| CVE-2019-3403 | The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | MEDIUM 5.3EPSS 52.6% | 22 May 2019 |
| CVE-2019-3401 | The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | MEDIUM 5.3EPSS 12.7% | 22 May 2019 |
| CVE-2019-11231 | An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). | CRITICAL 9.8EPSS 71.6% | 22 May 2019 |
| CVE-2018-14729 | 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code. | HIGH 8.8EPSS 10.4% | 22 May 2019 |
| CVE-2019-7820 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a type confusion vulnerability. | HIGH 8.8EPSS 10.9% | 22 May 2019 |
| CVE-2019-7761 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. | HIGH 8.8EPSS 10.2% | 22 May 2019 |
| CVE-2019-12185 | eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. | HIGH 8.8EPSS 17.8% | 20 May 2019 |
| CVE-2019-12086 | When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server… | HIGH 7.5EPSS 21.9% | 17 May 2019 |
| CVE-2019-4279 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. | CRITICAL 9.8EPSS 79.9% | 17 May 2019 |
| CVE-2018-19585 | GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol. | HIGH 7.5EPSS 14.5% | 17 May 2019 |
| CVE-2018-17179 | There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php. | CRITICAL 9.8EPSS 12.8% | 17 May 2019 |
| CVE-2019-8937 | HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php. | MEDIUM 6.1EPSS 10.6% | 17 May 2019 |
| CVE-2019-8929 | XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype. | MEDIUM 6.1EPSS 11.2% | 17 May 2019 |
| CVE-2019-8925 | An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via… | MEDIUM 4.3EPSS 11.6% | 17 May 2019 |
| CVE-2019-0953 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 12.9% | 16 May 2019 |
| CVE-2019-0947 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 13.7% | 16 May 2019 |
| CVE-2019-0946 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 13.7% | 16 May 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.