Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 131 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-9733 | This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist… | CRITICAL 9.8EPSS 52.9% | 11 April 2019 |
| CVE-2018-19300 | By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. | CRITICAL 9.8EPSS 74.3% | 11 April 2019 |
| CVE-2019-3914 | Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object… | HIGH 7.2EPSS 29.9% | 11 April 2019 |
| CVE-2019-11072 | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F?… | CRITICAL 9.8EPSS 73.8% | 10 April 2019 |
| CVE-2019-10945 | The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory. | CRITICAL 9.8EPSS 38.0% | 10 April 2019 |
| CVE-2019-7139 | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. | CRITICAL 9.8EPSS 18.3% | 10 April 2019 |
| CVE-2019-4013 | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. | CRITICAL 9.9EPSS 13.9% | 10 April 2019 |
| CVE-2019-0199 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. | HIGH 7.5EPSS 72.9% | 10 April 2019 |
| CVE-2019-8456 | Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server. | MEDIUM 5.9EPSS 20.4% | 9 April 2019 |
| CVE-2019-0862 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 9 April 2019 |
| CVE-2019-0861 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 9 April 2019 |
| CVE-2019-0860 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.8% | 9 April 2019 |
| CVE-2019-0856 | A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'. | HIGH 7.2EPSS 19.4% | 9 April 2019 |
| CVE-2019-0853 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 30.1% | 9 April 2019 |
| CVE-2019-0851 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 9 April 2019 |
| CVE-2019-0847 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 9 April 2019 |
| CVE-2019-0846 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 9 April 2019 |
| CVE-2019-0845 | A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 14.8% | 9 April 2019 |
| CVE-2019-0842 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 18.0% | 9 April 2019 |
| CVE-2019-0841 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 41.4% | 9 April 2019 |
| CVE-2019-0828 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 13.7% | 9 April 2019 |
| CVE-2019-0827 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.5% | 9 April 2019 |
| CVE-2019-0826 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.5% | 9 April 2019 |
| CVE-2019-0825 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.5% | 9 April 2019 |
| CVE-2019-0824 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.5% | 9 April 2019 |
| CVE-2019-0823 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.5% | 9 April 2019 |
| CVE-2019-0822 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 13.7% | 9 April 2019 |
| CVE-2019-0812 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 18.7% | 9 April 2019 |
| CVE-2019-0810 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.5% | 9 April 2019 |
| CVE-2019-0803 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 45.0% | 9 April 2019 |
| CVE-2019-0801 | A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file that points to an Excel or PowerPoint… | HIGH 7.8EPSS 18.5% | 9 April 2019 |
| CVE-2019-0795 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 21.3% | 9 April 2019 |
| CVE-2019-0794 | A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 15.5% | 9 April 2019 |
| CVE-2019-0793 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 18.2% | 9 April 2019 |
| CVE-2019-0792 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 18.2% | 9 April 2019 |
| CVE-2019-0791 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 18.2% | 9 April 2019 |
| CVE-2019-0790 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 16.2% | 9 April 2019 |
| CVE-2019-0752 | Microsoft Internet Explorer Type Confusion Vulnerability | KEVHIGH 7.5EPSS 81.6% | 9 April 2019 |
| CVE-2019-0739 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 9 April 2019 |
| CVE-2019-0809 | A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 10.6% | 9 April 2019 |
| CVE-2019-0808 | Microsoft Win32k Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 53.0% | 9 April 2019 |
| CVE-2019-0773 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.3% | 9 April 2019 |
| CVE-2019-0772 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.2% | 9 April 2019 |
| CVE-2019-0771 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.3% | 9 April 2019 |
| CVE-2019-0769 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 10.3% | 9 April 2019 |
| CVE-2019-0768 | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security… | MEDIUM 4.3EPSS 48.5% | 9 April 2019 |
| CVE-2019-0765 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 14.3% | 9 April 2019 |
| CVE-2019-0756 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 12.5% | 9 April 2019 |
| CVE-2019-0748 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 13.7% | 9 April 2019 |
| CVE-2019-0726 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 54.5% | 9 April 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.