SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 131 of 348

CVESummaryPriorityPublished
CVE-2019-9733This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist…CRITICAL 9.8EPSS 52.9%11 April 2019
CVE-2018-19300By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device.CRITICAL 9.8EPSS 74.3%11 April 2019
CVE-2019-3914Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object…HIGH 7.2EPSS 29.9%11 April 2019
CVE-2019-11072lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F?…CRITICAL 9.8EPSS 73.8%10 April 2019
CVE-2019-10945The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.CRITICAL 9.8EPSS 38.0%10 April 2019
CVE-2019-7139An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage.CRITICAL 9.8EPSS 18.3%10 April 2019
CVE-2019-4013IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges.CRITICAL 9.9EPSS 13.9%10 April 2019
CVE-2019-0199The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data.HIGH 7.5EPSS 72.9%10 April 2019
CVE-2019-8456Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.MEDIUM 5.9EPSS 20.4%9 April 2019
CVE-2019-0862A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%9 April 2019
CVE-2019-0861A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%9 April 2019
CVE-2019-0860A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.8%9 April 2019
CVE-2019-0856A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.HIGH 7.2EPSS 19.4%9 April 2019
CVE-2019-0853A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 30.1%9 April 2019
CVE-2019-0851A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%9 April 2019
CVE-2019-0847A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%9 April 2019
CVE-2019-0846A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%9 April 2019
CVE-2019-0845A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.HIGH 8.8EPSS 14.8%9 April 2019
CVE-2019-0842A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.HIGH 8.8EPSS 18.0%9 April 2019
CVE-2019-0841Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 41.4%9 April 2019
CVE-2019-0828A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%9 April 2019
CVE-2019-0827A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.5%9 April 2019
CVE-2019-0826A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.5%9 April 2019
CVE-2019-0825A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.5%9 April 2019
CVE-2019-0824A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.5%9 April 2019
CVE-2019-0823A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.5%9 April 2019
CVE-2019-0822A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%9 April 2019
CVE-2019-0812A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 18.7%9 April 2019
CVE-2019-0810A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.5%9 April 2019
CVE-2019-0803Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 45.0%9 April 2019
CVE-2019-0801A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint…HIGH 7.8EPSS 18.5%9 April 2019
CVE-2019-0795A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 21.3%9 April 2019
CVE-2019-0794A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'.HIGH 8.8EPSS 15.5%9 April 2019
CVE-2019-0793A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 18.2%9 April 2019
CVE-2019-0792A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 18.2%9 April 2019
CVE-2019-0791A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 18.2%9 April 2019
CVE-2019-0790A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 16.2%9 April 2019
CVE-2019-0752Microsoft Internet Explorer Type Confusion VulnerabilityKEVHIGH 7.5EPSS 81.6%9 April 2019
CVE-2019-0739A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%9 April 2019
CVE-2019-0809A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.HIGH 7.8EPSS 10.6%9 April 2019
CVE-2019-0808Microsoft Win32k Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 53.0%9 April 2019
CVE-2019-0773A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.3%9 April 2019
CVE-2019-0772A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.2%9 April 2019
CVE-2019-0771A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.3%9 April 2019
CVE-2019-0769A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.3%9 April 2019
CVE-2019-0768A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security…MEDIUM 4.3EPSS 48.5%9 April 2019
CVE-2019-0765A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.HIGH 8.8EPSS 14.3%9 April 2019
CVE-2019-0756A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.5%9 April 2019
CVE-2019-0748A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.7%9 April 2019
CVE-2019-0726A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'.CRITICAL 9.8EPSS 54.5%9 April 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.