Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 132 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-0698 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 62.8% | 9 April 2019 |
| CVE-2019-0697 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 32.9% | 9 April 2019 |
| CVE-2019-0667 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | HIGH 7.5EPSS 31.3% | 8 April 2019 |
| CVE-2019-0666 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | HIGH 7.5EPSS 20.4% | 8 April 2019 |
| CVE-2019-0639 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 12.0% | 8 April 2019 |
| CVE-2019-0617 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 19.5% | 8 April 2019 |
| CVE-2019-0612 | A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. | MEDIUM 5.3EPSS 10.5% | 8 April 2019 |
| CVE-2019-0603 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. | HIGH 7.5EPSS 34.2% | 8 April 2019 |
| CVE-2019-0592 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 22.9% | 8 April 2019 |
| CVE-2019-0211 | Apache HTTP Server Privilege Escalation Vulnerability | KEVHIGH 7.8EPSS 65.0% | 8 April 2019 |
| CVE-2019-0217 | In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions. | HIGH 7.5EPSS 17.4% | 8 April 2019 |
| CVE-2019-0215 | In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions. | HIGH 7.5EPSS 10.7% | 8 April 2019 |
| CVE-2019-11001 | Reolink Multiple IP Cameras OS Command Injection Vulnerability | KEVHIGH 7.2EPSS 37.5% | 8 April 2019 |
| CVE-2019-6553 | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. | CRITICAL 9.8EPSS 60.1% | 4 April 2019 |
| CVE-2019-10867 | An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to… | HIGH 8.8EPSS 68.9% | 4 April 2019 |
| CVE-2019-10863 | A command injection vulnerability exists in TeemIp versions before 2.4.0. | HIGH 7.2EPSS 13.4% | 4 April 2019 |
| CVE-2018-4441 | A memory corruption issue was addressed with improved memory handling. | HIGH 8.8EPSS 12.7% | 3 April 2019 |
| CVE-2018-4416 | Multiple memory corruption issues were addressed with improved memory handling. | HIGH 8.8EPSS 34.2% | 3 April 2019 |
| CVE-2018-4407 | A memory corruption issue was addressed with improved validation. | HIGH 8.8EPSS 22.0% | 3 April 2019 |
| CVE-2018-4314 | A use after free issue was addressed with improved memory management. | HIGH 8.8EPSS 10.3% | 3 April 2019 |
| CVE-2019-10692 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement. | CRITICAL 9.8EPSS 78.7% | 2 April 2019 |
| CVE-2019-9193 | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. | HIGH 7.2EPSS 91.7% | 1 April 2019 |
| CVE-2019-6715 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. | HIGH 7.5EPSS 19.4% | 1 April 2019 |
| CVE-2019-1002101 | The kubectl cp command allows copying files between containers and the user machine. | MEDIUM 5.5EPSS 12.7% | 1 April 2019 |
| CVE-2019-1002100 | In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type:… | MEDIUM 6.5EPSS 10.8% | 1 April 2019 |
| CVE-2019-10678 | Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. | HIGH 7.5EPSS 17.3% | 31 March 2019 |
| CVE-2019-10663 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? | HIGH 8.8EPSS 27.9% | 30 March 2019 |
| CVE-2019-10662 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? | HIGH 8.8EPSS 43.9% | 30 March 2019 |
| CVE-2019-10655 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority… | CRITICAL 9.8EPSS 15.5% | 30 March 2019 |
| CVE-2019-9922 | Directory Traversal allows read access to arbitrary files. | HIGH 7.5EPSS 10.6% | 29 March 2019 |
| CVE-2019-0225 | A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details. | HIGH 7.5EPSS 10.3% | 28 March 2019 |
| CVE-2019-0222 | In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. | HIGH 7.5EPSS 12.0% | 28 March 2019 |
| CVE-2019-9167 | Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter. | MEDIUM 6.1EPSS 21.7% | 28 March 2019 |
| CVE-2019-9204 | SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands. | CRITICAL 9.8EPSS 19.7% | 28 March 2019 |
| CVE-2019-9203 | Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. | CRITICAL 9.8EPSS 20.4% | 28 March 2019 |
| CVE-2019-9202 | Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues. | HIGH 8.8EPSS 23.8% | 28 March 2019 |
| CVE-2019-9164 | Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job. | HIGH 8.8EPSS 46.0% | 28 March 2019 |
| CVE-2019-5737 | In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. | HIGH 7.5EPSS 16.2% | 28 March 2019 |
| CVE-2017-18365 | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. | CRITICAL 9.8EPSS 21.2% | 28 March 2019 |
| CVE-2019-3829 | A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. | HIGH 7.5EPSS 59.0% | 27 March 2019 |
| CVE-2019-10232 | Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. | CRITICAL 9.8EPSS 23.2% | 27 March 2019 |
| CVE-2019-5420 | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. | CRITICAL 9.8EPSS 92.1% | 27 March 2019 |
| CVE-2019-5418 | Rails Ruby on Rails Path Traversal Vulnerability | KEVHIGH 7.5EPSS 98.5% | 27 March 2019 |
| CVE-2019-6341 | Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability. | MEDIUM 5.4EPSS 12.2% | 26 March 2019 |
| CVE-2019-10068 | Kentico Xperience Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 95.1% | 26 March 2019 |
| CVE-2019-9055 | In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and… | HIGH 8.8EPSS 12.3% | 26 March 2019 |
| CVE-2019-9053 | It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter. | HIGH 8.1EPSS 68.6% | 26 March 2019 |
| CVE-2019-7609 | Kibana Arbitrary Code Execution | KEVCRITICAL 10.0EPSS 95.3% | 25 March 2019 |
| CVE-2019-3396 | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 25 March 2019 |
| CVE-2019-3810 | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. | MEDIUM 6.1EPSS 13.9% | 25 March 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.