SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 130 of 348

CVESummaryPriorityPublished
CVE-2019-3799Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module.MEDIUM 6.5EPSS 85.3%6 May 2019
CVE-2018-20824The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.MEDIUM 6.1EPSS 38.0%3 May 2019
CVE-2019-9017DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.HIGH 7.5EPSS 20.6%2 May 2019
CVE-2018-12404A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content.MEDIUM 5.9EPSS 44.2%2 May 2019
CVE-2017-18372The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user.HIGH 8.8EPSS 21.9%2 May 2019
CVE-2017-18371The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username…CRITICAL 9.8EPSS 22.5%2 May 2019
CVE-2017-18370The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user.HIGH 8.8EPSS 24.4%2 May 2019
CVE-2017-18369The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user.CRITICAL 9.8EPSS 67.6%2 May 2019
CVE-2017-18368Zyxel P660HN-T1A Routers Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 94.4%2 May 2019
CVE-2019-0227A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006.HIGH 7.5EPSS 91.9%1 May 2019
CVE-2019-3932Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi.CRITICAL 9.8EPSS 36.3%30 April 2019
CVE-2019-3929Crestron Multiple Products Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.0%30 April 2019
CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 7.5EPSS 81.0%30 April 2019
CVE-2019-11577dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.CRITICAL 9.8EPSS 53.1%28 April 2019
CVE-2019-2725Oracle WebLogic Server, InjectionKEVCRITICAL 9.8EPSS 100.0%26 April 2019
CVE-2019-9810Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow.HIGH 8.8EPSS 29.7%26 April 2019
CVE-2019-9792The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout.CRITICAL 9.8EPSS 13.2%26 April 2019
CVE-2019-9791The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack…CRITICAL 9.8EPSS 19.9%26 April 2019
CVE-2019-0186The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks.MEDIUM 6.1EPSS 20.6%26 April 2019
CVE-2019-11542In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before…HIGH 7.2EPSS 65.6%26 April 2019
CVE-2019-11539Ivanti Pulse Connect Secure and Policy Secure Command Injection VulnerabilityKEVHIGH 7.2EPSS 98.5%26 April 2019
CVE-2018-16660A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.HIGH 8.8EPSS 17.4%25 April 2019
CVE-2018-20434LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a…CRITICAL 9.8EPSS 71.5%24 April 2019
CVE-2019-10008Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an…HIGH 8.8EPSS 19.4%24 April 2019
CVE-2019-7214SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.CRITICAL 9.8EPSS 84.8%24 April 2019
CVE-2019-7213SmarterTools SmarterMail 16.x before build 6985 allows directory traversal.MEDIUM 6.5EPSS 41.5%24 April 2019
CVE-2019-2698Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D).HIGH 8.1EPSS 12.0%23 April 2019
CVE-2019-2697Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D).HIGH 8.1EPSS 11.5%23 April 2019
CVE-2019-2684Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI).MEDIUM 5.9EPSS 37.6%23 April 2019
CVE-2019-2650Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services).HIGH 7.5EPSS 39.3%23 April 2019
CVE-2019-2649Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services).HIGH 7.5EPSS 36.8%23 April 2019
CVE-2019-2618Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).MEDIUM 5.5EPSS 32.9%23 April 2019
CVE-2019-2616Oracle BI Publisher Unauthorized Access VulnerabilityKEVHIGH 7.2EPSS 92.2%23 April 2019
CVE-2019-2588Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).MEDIUM 4.9EPSS 36.8%23 April 2019
CVE-2019-2578Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).HIGH 8.6EPSS 72.4%23 April 2019
CVE-2019-7304Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root.CRITICAL 9.8EPSS 60.8%23 April 2019
CVE-2019-11469Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection.CRITICAL 9.8EPSS 17.0%23 April 2019
CVE-2019-9955On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via…MEDIUM 6.1EPSS 21.2%22 April 2019
CVE-2019-11448An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability.CRITICAL 9.8EPSS 12.4%22 April 2019
CVE-2019-11447An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal.HIGH 8.8EPSS 52.3%22 April 2019
CVE-2019-11445OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileUpload and admin/repository_export.jsp.HIGH 7.2EPSS 14.2%22 April 2019
CVE-2019-11444An attacker can use Liferay's Groovy script console to execute OS commands.HIGH 7.2EPSS 12.6%22 April 2019
CVE-2019-11415A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.HIGH 7.5EPSS 13.7%22 April 2019
CVE-2019-11395A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT TO, POP3 USER, POP3 LIST, POP3 TOP, or POP3 RETR.CRITICAL 9.8EPSS 14.6%22 April 2019
CVE-2019-11358jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution.MEDIUM 6.1EPSS 87.2%20 April 2019
CVE-2019-11354The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.HIGH 7.8EPSS 23.1%19 April 2019
CVE-2019-3719Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability.HIGH 8.0EPSS 16.1%18 April 2019
CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal VulnerabilityKEVHIGH 8.8EPSS 96.8%18 April 2019
CVE-2019-0232When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to…HIGH 8.1EPSS 99.7%15 April 2019
CVE-2019-11229models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.HIGH 8.8EPSS 55.0%15 April 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.