SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 129 of 348

CVESummaryPriorityPublished
CVE-2019-0945A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0940A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.HIGH 7.5EPSS 23.1%16 May 2019
CVE-2019-0903Microsoft GDI Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 21.7%16 May 2019
CVE-2019-0902A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 8.8EPSS 19.2%16 May 2019
CVE-2019-0901A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0900A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0899A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.2%16 May 2019
CVE-2019-0898A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0897A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0896A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0895A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0894A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0893A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0891A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.2%16 May 2019
CVE-2019-0890A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%16 May 2019
CVE-2019-0889A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.2%16 May 2019
CVE-2019-0885A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.HIGH 7.8EPSS 14.4%16 May 2019
CVE-2019-0758An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.MEDIUM 6.5EPSS 12.3%16 May 2019
CVE-2019-0725A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.CRITICAL 9.8EPSS 28.2%16 May 2019
CVE-2019-0708Microsoft Remote Desktop Services Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 100.0%16 May 2019
CVE-2019-1821A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying…CRITICAL 9.8EPSS 98.1%16 May 2019
CVE-2019-1820A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should…MEDIUM 6.5EPSS 13.6%16 May 2019
CVE-2019-1819A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should…MEDIUM 6.5EPSS 13.6%16 May 2019
CVE-2019-1818A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should…MEDIUM 6.5EPSS 13.6%16 May 2019
CVE-2019-1717A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information.HIGH 7.5EPSS 10.1%15 May 2019
CVE-2013-7285Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported…CRITICAL 9.8EPSS 84.4%15 May 2019
CVE-2019-12099In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during…HIGH 8.8EPSS 17.2%14 May 2019
CVE-2018-14839LG N1A1 NAS Remote Command Execution VulnerabilityKEVCRITICAL 9.8EPSS 89.4%14 May 2019
CVE-2019-3568WhatsApp VOIP Stack Buffer Overflow VulnerabilityKEVCRITICAL 9.8EPSS 30.1%14 May 2019
CVE-2019-9618The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.CRITICAL 9.8EPSS 43.8%13 May 2019
CVE-2019-11600A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter.HIGH 8.1EPSS 80.0%13 May 2019
CVE-2019-9726Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem.HIGH 7.5EPSS 16.3%13 May 2019
CVE-2018-19987After the script file is executed, the command injection occurs.CRITICAL 9.8EPSS 12.9%13 May 2019
CVE-2018-19986In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices.CRITICAL 9.8EPSS 41.6%13 May 2019
CVE-2018-14714System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.CRITICAL 9.8EPSS 27.4%13 May 2019
CVE-2018-12296Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.HIGH 7.5EPSS 11.3%13 May 2019
CVE-2019-1867A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API.CRITICAL 10.0EPSS 30.3%10 May 2019
CVE-2019-7442An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML…CRITICAL 9.8EPSS 40.0%8 May 2019
CVE-2019-11510Ivanti Pulse Connect Secure Arbitrary File Read VulnerabilityKEVCRITICAL 10.0EPSS 100.0%8 May 2019
CVE-2019-11508In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the…HIGH 7.2EPSS 14.7%8 May 2019
CVE-2019-8387MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.CRITICAL 9.8EPSS 55.7%8 May 2019
CVE-2018-14485BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.CRITICAL 9.8EPSS 16.3%7 May 2019
CVE-2018-4073An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.HIGH 8.8EPSS 25.6%6 May 2019
CVE-2018-4072An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.HIGH 8.8EPSS 26.4%6 May 2019
CVE-2018-4071An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.HIGH 8.8EPSS 18.3%6 May 2019
CVE-2018-4070An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.HIGH 8.8EPSS 18.0%6 May 2019
CVE-2018-4063Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type VulnerabilityKEVHIGH 8.8EPSS 27.1%6 May 2019
CVE-2018-4068An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3.MEDIUM 5.3EPSS 11.4%6 May 2019
CVE-2018-4061An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.HIGH 8.8EPSS 19.5%6 May 2019
CVE-2019-5434An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method.CRITICAL 9.8EPSS 57.0%6 May 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.