Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 134 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-9624 | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI. | HIGH 7.8EPSS 23.7% | 7 March 2019 |
| CVE-2019-9599 | The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests. | HIGH 7.5EPSS 13.3% | 6 March 2019 |
| CVE-2019-9581 | phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension. | HIGH 8.8EPSS 13.5% | 6 March 2019 |
| CVE-2019-0728 | A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 27.7% | 5 March 2019 |
| CVE-2019-0724 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | HIGH 8.1EPSS 23.8% | 5 March 2019 |
| CVE-2019-0675 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 14.8% | 5 March 2019 |
| CVE-2019-0674 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 18.4% | 5 March 2019 |
| CVE-2019-0673 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 14.8% | 5 March 2019 |
| CVE-2019-0672 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 14.8% | 5 March 2019 |
| CVE-2019-0671 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 14.8% | 5 March 2019 |
| CVE-2019-0662 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 15.4% | 5 March 2019 |
| CVE-2019-0655 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 12.7% | 5 March 2019 |
| CVE-2019-0652 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0651 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0650 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | HIGH 7.5EPSS 19.4% | 5 March 2019 |
| CVE-2019-0644 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0642 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0640 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0633 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 13.0% | 5 March 2019 |
| CVE-2019-0630 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 17.4% | 5 March 2019 |
| CVE-2019-0626 | A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | CRITICAL 9.8EPSS 69.3% | 5 March 2019 |
| CVE-2019-0625 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 5 March 2019 |
| CVE-2019-0618 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 67.0% | 5 March 2019 |
| CVE-2019-0613 | A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of… | HIGH 8.8EPSS 15.4% | 5 March 2019 |
| CVE-2019-0610 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0607 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0606 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0605 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 12.2% | 5 March 2019 |
| CVE-2019-0604 | Microsoft SharePoint Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 99.9% | 5 March 2019 |
| CVE-2019-0599 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 20.1% | 5 March 2019 |
| CVE-2019-0598 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 20.1% | 5 March 2019 |
| CVE-2019-0597 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 5 March 2019 |
| CVE-2019-0596 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 16.1% | 5 March 2019 |
| CVE-2019-0595 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. | HIGH 7.8EPSS 19.1% | 5 March 2019 |
| CVE-2019-0594 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | HIGH 8.8EPSS 11.9% | 5 March 2019 |
| CVE-2019-0593 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 19.8% | 5 March 2019 |
| CVE-2019-0591 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0590 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. | HIGH 7.5EPSS 11.1% | 5 March 2019 |
| CVE-2019-0540 | A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass… | MEDIUM 5.5EPSS 12.8% | 5 March 2019 |
| CVE-2019-3921 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. | HIGH 8.8EPSS 17.9% | 5 March 2019 |
| CVE-2019-6225 | A memory corruption issue was addressed with improved validation. | HIGH 7.8EPSS 28.8% | 5 March 2019 |
| CVE-2019-1674 | A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. | HIGH 8.8EPSS 10.8% | 28 February 2019 |
| CVE-2019-1663 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute… | CRITICAL 9.8EPSS 95.7% | 28 February 2019 |
| CVE-2019-1559 | If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. | MEDIUM 5.9EPSS 17.1% | 27 February 2019 |
| CVE-2019-4061 | IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. | MEDIUM 5.3EPSS 22.5% | 27 February 2019 |
| CVE-2019-9194 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | CRITICAL 9.8EPSS 96.7% | 26 February 2019 |
| CVE-2019-9122 | They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request. | HIGH 8.8EPSS 23.5% | 25 February 2019 |
| CVE-2019-9082 | ThinkPHP Remote Code Execution Vulnerability | KEVHIGH 8.8EPSS 97.4% | 24 February 2019 |
| CVE-2019-8375 | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of… | CRITICAL 9.8EPSS 16.1% | 24 February 2019 |
| CVE-2019-9041 | In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring. | HIGH 7.2EPSS 31.4% | 23 February 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.