SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,467 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 133 of 348

CVESummaryPriorityPublished
CVE-2018-16858It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document.CRITICAL 9.8EPSS 67.3%25 March 2019
CVE-2019-9978WordPress Social Warfare Plugin Cross-Site Scripting (XSS) VulnerabilityKEVMEDIUM 6.1EPSS 72.9%24 March 2019
CVE-2019-9960The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.CRITICAL 9.8EPSS 13.4%24 March 2019
CVE-2019-9948urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.CRITICAL 9.1EPSS 11.8%23 March 2019
CVE-2019-9649Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.MEDIUM 5.3EPSS 14.5%22 March 2019
CVE-2019-9648A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.MEDIUM 5.3EPSS 14.3%22 March 2019
CVE-2019-3871A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7.HIGH 8.8EPSS 12.6%21 March 2019
CVE-2019-7238Sonatype Nexus Repository Manager Incorrect Access Control VulnerabilityKEVCRITICAL 9.8EPSS 77.1%21 March 2019
CVE-2019-9083SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter.CRITICAL 9.8EPSS 17.6%21 March 2019
CVE-2019-7391ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.HIGH 8.8EPSS 13.6%21 March 2019
CVE-2019-7385An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and…HIGH 7.8EPSS 12.2%21 March 2019
CVE-2019-6973Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.HIGH 7.5EPSS 13.8%21 March 2019
CVE-2019-6967AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.HIGH 8.8EPSS 13.5%21 March 2019
CVE-2019-6714A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem.CRITICAL 9.8EPSS 31.7%21 March 2019
CVE-2019-6441By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.CRITICAL 9.8EPSS 53.6%21 March 2019
CVE-2019-6275Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.HIGH 8.8EPSS 12.5%21 March 2019
CVE-2019-6274Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.HIGH 8.8EPSS 11.2%21 March 2019
CVE-2019-6273download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.MEDIUM 6.5EPSS 11.5%21 March 2019
CVE-2019-6272Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.HIGH 8.8EPSS 12.5%21 March 2019
CVE-2019-6116In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.HIGH 7.8EPSS 41.6%21 March 2019
CVE-2018-20556SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.HIGH 8.8EPSS 18.9%21 March 2019
CVE-2018-20555The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code.CRITICAL 9.8EPSS 10.4%21 March 2019
CVE-2018-20526Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.CRITICAL 9.8EPSS 73.1%21 March 2019
CVE-2018-20525Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.CRITICAL 9.1EPSS 21.6%21 March 2019
CVE-2018-20323www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.HIGH 8.8EPSS 54.5%21 March 2019
CVE-2018-20221Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user.HIGH 8.8EPSS 10.3%21 March 2019
CVE-2018-20220While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication.HIGH 7.5EPSS 15.4%21 March 2019
CVE-2018-20219This token is hard-coded to a string in the source code (/usr/share/www/check.lp file).HIGH 8.1EPSS 14.6%21 March 2019
CVE-2018-20218An attacker is able to perform command injection using the "password" parameter in the login form.CRITICAL 9.8EPSS 10.7%21 March 2019
CVE-2018-19524A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.CRITICAL 9.8EPSS 50.5%21 March 2019
CVE-2018-19510subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.CRITICAL 9.8EPSS 20.0%21 March 2019
CVE-2018-19365The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.CRITICAL 9.1EPSS 22.3%21 March 2019
CVE-2018-19276OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.CRITICAL 9.8EPSS 98.7%21 March 2019
CVE-2018-19191Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.MEDIUM 5.4EPSS 39.1%21 March 2019
CVE-2018-10093AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.HIGH 8.8EPSS 68.2%21 March 2019
CVE-2019-3833Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests.HIGH 7.5EPSS 15.2%14 March 2019
CVE-2019-3816Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory.HIGH 7.5EPSS 14.7%14 March 2019
CVE-2019-9787WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration.HIGH 8.8EPSS 38.7%14 March 2019
CVE-2019-9768Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.HIGH 7.5EPSS 11.7%14 March 2019
CVE-2019-9760FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses.CRITICAL 9.8EPSS 53.1%14 March 2019
CVE-2019-5917azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service via unspecified vectors.HIGH 7.5EPSS 21.4%12 March 2019
CVE-2019-9692class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).MEDIUM 6.5EPSS 45.9%11 March 2019
CVE-2019-1003030Jenkins Matrix Project Plugin Remote Code Execution VulnerabilityKEVCRITICAL 9.9EPSS 96.9%8 March 2019
CVE-2019-1003029Jenkins Script Security Plugin Sandbox Bypass VulnerabilityKEVCRITICAL 9.9EPSS 73.9%8 March 2019
CVE-2017-3164Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive).HIGH 7.5EPSS 19.4%8 March 2019
CVE-2019-9632ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.HIGH 7.5EPSS 39.9%8 March 2019
CVE-2018-18809TIBCO JasperReports Library Directory Traversal VulnerabilityKEVMEDIUM 6.5EPSS 79.1%7 March 2019
CVE-2019-0192In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request.CRITICAL 9.8EPSS 77.5%7 March 2019
CVE-2019-1599A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.HIGH 8.6EPSS 14.3%7 March 2019
CVE-2019-3778Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code.MEDIUM 6.5EPSS 15.5%7 March 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.