SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026

17,386 results · page 135 of 348

CVESummaryPriorityPublished
CVE-2019-9021A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783.CRITICAL 9.8EPSS 10.1%22 February 2019
CVE-2019-9020An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.CRITICAL 9.8EPSS 10.1%22 February 2019
CVE-2019-6340Drupal Core Remote Code Execution VulnerabilityKEVHIGH 8.1EPSS 92.0%21 February 2019
CVE-2019-8985On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication.CRITICAL 9.8EPSS 13.3%21 February 2019
CVE-2019-8982com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.CRITICAL 9.6EPSS 28.0%21 February 2019
CVE-2019-3924MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.HIGH 7.5EPSS 15.7%20 February 2019
CVE-2019-8953The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.MEDIUM 6.1EPSS 52.2%20 February 2019
CVE-2019-8331In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.MEDIUM 6.1EPSS 16.4%20 February 2019
CVE-2019-8943WordPress through 5.0.3 allows Path Traversal in wp_crop_image().MEDIUM 6.5EPSS 92.6%20 February 2019
CVE-2019-8942WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring.HIGH 8.8EPSS 82.7%20 February 2019
CVE-2019-5782Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.HIGH 8.8EPSS 12.8%19 February 2019
CVE-2019-8917SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service.CRITICAL 9.8EPSS 36.4%18 February 2019
CVE-2019-8903index.js in Total.js Platform before 3.2.3 allows path traversal.HIGH 7.5EPSS 72.1%18 February 2019
CVE-2019-6453mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers.HIGH 8.1EPSS 54.3%18 February 2019
CVE-2018-20782The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.HIGH 7.5EPSS 10.0%17 February 2019
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) File Upload VulnerabilityKEVMEDIUM 6.5EPSS 63.3%17 February 2019
CVE-2019-6974In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.HIGH 8.1EPSS 16.5%15 February 2019
CVE-2019-8341The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it.CRITICAL 9.8EPSS 44.8%15 February 2019
CVE-2019-6545An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.HIGH 7.5EPSS 13.9%13 February 2019
CVE-2019-6543Code is executed under the program runtime privileges, which could lead to the compromise of the machine.CRITICAL 9.8EPSS 17.3%13 February 2019
CVE-2017-0938Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.HIGH 7.5EPSS 21.0%12 February 2019
CVE-2019-5736runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of…HIGH 8.6EPSS 98.5%11 February 2019
CVE-2019-3822libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow.CRITICAL 9.8EPSS 12.9%6 February 2019
CVE-2019-1003005A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy…HIGH 8.8EPSS 19.0%6 February 2019
CVE-2018-3991An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500.CRITICAL 9.8EPSS 34.3%5 February 2019
CVE-2018-18500A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements.CRITICAL 9.8EPSS 12.7%5 February 2019
CVE-2018-20251In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format.MEDIUM 5.5EPSS 31.5%5 February 2019
CVE-2018-20250WinRAR Absolute Path Traversal VulnerabilityKEVHIGH 7.8EPSS 96.3%5 February 2019
CVE-2018-18990LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.MEDIUM 5.3EPSS 39.5%5 February 2019
CVE-2018-11803Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.HIGH 7.5EPSS 58.5%5 February 2019
CVE-2016-1000282Versions 2.8.8 and earlier can be vulnerable to command injection.CRITICAL 9.8EPSS 13.5%5 February 2019
CVE-2018-20753Kaseya VSA Remote Code Execution VulnerabilityKEVCRITICAL 9.8EPSS 29.3%5 February 2019
CVE-2017-18362Kaseya VSA SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 86.8%5 February 2019
CVE-2019-7298A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request.HIGH 8.1EPSS 10.1%1 February 2019
CVE-2019-7297A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request.CRITICAL 9.8EPSS 12.5%31 January 2019
CVE-2018-19043The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.MEDIUM 5.3EPSS 10.0%31 January 2019
CVE-2018-19042The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.MEDIUM 5.3EPSS 10.0%31 January 2019
CVE-2018-19040The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.MEDIUM 5.3EPSS 12.1%31 January 2019
CVE-2018-15517The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an…HIGH 8.6EPSS 44.1%31 January 2019
CVE-2019-6111However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented).MEDIUM 5.9EPSS 58.2%31 January 2019
CVE-2019-6110In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.MEDIUM 6.8EPSS 20.9%31 January 2019
CVE-2019-0190A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service.HIGH 7.5EPSS 59.1%30 January 2019
CVE-2018-3956An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096.HIGH 7.1EPSS 46.0%30 January 2019
CVE-2018-17199In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session.HIGH 7.5EPSS 20.2%30 January 2019
CVE-2018-17189In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data.MEDIUM 5.3EPSS 20.1%30 January 2019
CVE-2018-17431Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.CRITICAL 9.8EPSS 83.9%30 January 2019
CVE-2019-3462Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.HIGH 8.1EPSS 14.6%28 January 2019
CVE-2019-6977gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow.HIGH 8.8EPSS 71.5%27 January 2019
CVE-2019-6703Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover.CRITICAL 9.8EPSS 26.1%27 January 2019
CVE-2019-6799When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access.MEDIUM 5.9EPSS 14.8%26 January 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.