SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 134 of 348

CVESummaryPriorityPublished
CVE-2019-9624Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.HIGH 7.8EPSS 23.7%7 March 2019
CVE-2019-9599The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.HIGH 7.5EPSS 13.3%6 March 2019
CVE-2019-9581phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.HIGH 8.8EPSS 13.5%6 March 2019
CVE-2019-0728A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.HIGH 7.8EPSS 27.7%5 March 2019
CVE-2019-0724An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.HIGH 8.1EPSS 23.8%5 March 2019
CVE-2019-0675A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 14.8%5 March 2019
CVE-2019-0674A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 18.4%5 March 2019
CVE-2019-0673A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 14.8%5 March 2019
CVE-2019-0672A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 14.8%5 March 2019
CVE-2019-0671A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 14.8%5 March 2019
CVE-2019-0662A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 15.4%5 March 2019
CVE-2019-0655A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 12.7%5 March 2019
CVE-2019-0652A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0651A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0650A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.HIGH 7.5EPSS 19.4%5 March 2019
CVE-2019-0644A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0642A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0640A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0633A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.HIGH 8.8EPSS 13.0%5 March 2019
CVE-2019-0630A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.HIGH 8.8EPSS 17.4%5 March 2019
CVE-2019-0626A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.CRITICAL 9.8EPSS 69.3%5 March 2019
CVE-2019-0625A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%5 March 2019
CVE-2019-0618A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.HIGH 8.8EPSS 67.0%5 March 2019
CVE-2019-0613A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of…HIGH 8.8EPSS 15.4%5 March 2019
CVE-2019-0610A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0607A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0606A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0605A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 12.2%5 March 2019
CVE-2019-0604Microsoft SharePoint Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 99.9%5 March 2019
CVE-2019-0599A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.1%5 March 2019
CVE-2019-0598A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 20.1%5 March 2019
CVE-2019-0597A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%5 March 2019
CVE-2019-0596A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 16.1%5 March 2019
CVE-2019-0595A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 19.1%5 March 2019
CVE-2019-0594A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.9%5 March 2019
CVE-2019-0593A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 19.8%5 March 2019
CVE-2019-0591A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0590A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 11.1%5 March 2019
CVE-2019-0540A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass…MEDIUM 5.5EPSS 12.8%5 March 2019
CVE-2019-3921The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/.HIGH 8.8EPSS 17.9%5 March 2019
CVE-2019-6225A memory corruption issue was addressed with improved validation.HIGH 7.8EPSS 28.8%5 March 2019
CVE-2019-1674A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user.HIGH 8.8EPSS 10.8%28 February 2019
CVE-2019-1663A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute…CRITICAL 9.8EPSS 95.7%28 February 2019
CVE-2019-1559If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data.MEDIUM 5.9EPSS 17.1%27 February 2019
CVE-2019-4061IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access.MEDIUM 5.3EPSS 22.5%27 February 2019
CVE-2019-9194elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.CRITICAL 9.8EPSS 96.7%26 February 2019
CVE-2019-9122They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.HIGH 8.8EPSS 23.5%25 February 2019
CVE-2019-9082ThinkPHP Remote Code Execution VulnerabilityKEVHIGH 8.8EPSS 97.4%24 February 2019
CVE-2019-8375The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of…CRITICAL 9.8EPSS 16.1%24 February 2019
CVE-2019-9041In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.HIGH 7.2EPSS 31.4%23 February 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.