Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 135 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-9021 | A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. | CRITICAL 9.8EPSS 10.1% | 22 February 2019 |
| CVE-2019-9020 | An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. | CRITICAL 9.8EPSS 10.1% | 22 February 2019 |
| CVE-2019-6340 | Drupal Core Remote Code Execution Vulnerability | KEVHIGH 8.1EPSS 92.0% | 21 February 2019 |
| CVE-2019-8985 | On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. | CRITICAL 9.8EPSS 13.3% | 21 February 2019 |
| CVE-2019-8982 | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF. | CRITICAL 9.6EPSS 28.0% | 21 February 2019 |
| CVE-2019-3924 | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. | HIGH 7.5EPSS 15.7% | 20 February 2019 |
| CVE-2019-8953 | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php. | MEDIUM 6.1EPSS 52.2% | 20 February 2019 |
| CVE-2019-8331 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | MEDIUM 6.1EPSS 16.4% | 20 February 2019 |
| CVE-2019-8943 | WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). | MEDIUM 6.5EPSS 92.6% | 20 February 2019 |
| CVE-2019-8942 | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. | HIGH 8.8EPSS 82.7% | 20 February 2019 |
| CVE-2019-5782 | Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | HIGH 8.8EPSS 12.8% | 19 February 2019 |
| CVE-2019-8917 | SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. | CRITICAL 9.8EPSS 36.4% | 18 February 2019 |
| CVE-2019-8903 | index.js in Total.js Platform before 3.2.3 allows path traversal. | HIGH 7.5EPSS 72.1% | 18 February 2019 |
| CVE-2019-6453 | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. | HIGH 8.1EPSS 54.3% | 18 February 2019 |
| CVE-2018-20782 | The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. | HIGH 7.5EPSS 10.0% | 17 February 2019 |
| CVE-2019-8394 | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | KEVMEDIUM 6.5EPSS 63.3% | 17 February 2019 |
| CVE-2019-6974 | In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. | HIGH 8.1EPSS 16.5% | 15 February 2019 |
| CVE-2019-8341 | The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. | CRITICAL 9.8EPSS 44.8% | 15 February 2019 |
| CVE-2019-6545 | An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine. | HIGH 7.5EPSS 13.9% | 13 February 2019 |
| CVE-2019-6543 | Code is executed under the program runtime privileges, which could lead to the compromise of the machine. | CRITICAL 9.8EPSS 17.3% | 13 February 2019 |
| CVE-2017-0938 | Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks. | HIGH 7.5EPSS 21.0% | 12 February 2019 |
| CVE-2019-5736 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of… | HIGH 8.6EPSS 98.5% | 11 February 2019 |
| CVE-2019-3822 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. | CRITICAL 9.8EPSS 12.9% | 6 February 2019 |
| CVE-2019-1003005 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy… | HIGH 8.8EPSS 19.0% | 6 February 2019 |
| CVE-2018-3991 | An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. | CRITICAL 9.8EPSS 34.3% | 5 February 2019 |
| CVE-2018-18500 | A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. | CRITICAL 9.8EPSS 12.7% | 5 February 2019 |
| CVE-2018-20251 | In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. | MEDIUM 5.5EPSS 31.5% | 5 February 2019 |
| CVE-2018-20250 | WinRAR Absolute Path Traversal Vulnerability | KEVHIGH 7.8EPSS 96.3% | 5 February 2019 |
| CVE-2018-18990 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. | MEDIUM 5.3EPSS 39.5% | 5 February 2019 |
| CVE-2018-11803 | Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation. | HIGH 7.5EPSS 58.5% | 5 February 2019 |
| CVE-2016-1000282 | Versions 2.8.8 and earlier can be vulnerable to command injection. | CRITICAL 9.8EPSS 13.5% | 5 February 2019 |
| CVE-2018-20753 | Kaseya VSA Remote Code Execution Vulnerability | KEVCRITICAL 9.8EPSS 29.3% | 5 February 2019 |
| CVE-2017-18362 | Kaseya VSA SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.8% | 5 February 2019 |
| CVE-2019-7298 | A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. | HIGH 8.1EPSS 10.1% | 1 February 2019 |
| CVE-2019-7297 | A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. | CRITICAL 9.8EPSS 12.5% | 31 January 2019 |
| CVE-2018-19043 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI. | MEDIUM 5.3EPSS 10.0% | 31 January 2019 |
| CVE-2018-19042 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI. | MEDIUM 5.3EPSS 10.0% | 31 January 2019 |
| CVE-2018-19040 | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | MEDIUM 5.3EPSS 12.1% | 31 January 2019 |
| CVE-2018-15517 | The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an… | HIGH 8.6EPSS 44.1% | 31 January 2019 |
| CVE-2019-6111 | However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). | MEDIUM 5.9EPSS 58.2% | 31 January 2019 |
| CVE-2019-6110 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred. | MEDIUM 6.8EPSS 20.9% | 31 January 2019 |
| CVE-2019-0190 | A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. | HIGH 7.5EPSS 59.1% | 30 January 2019 |
| CVE-2018-3956 | An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. | HIGH 7.1EPSS 46.0% | 30 January 2019 |
| CVE-2018-17199 | In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. | HIGH 7.5EPSS 20.2% | 30 January 2019 |
| CVE-2018-17189 | In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. | MEDIUM 5.3EPSS 20.1% | 30 January 2019 |
| CVE-2018-17431 | Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL. | CRITICAL 9.8EPSS 83.9% | 30 January 2019 |
| CVE-2019-3462 | Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine. | HIGH 8.1EPSS 14.6% | 28 January 2019 |
| CVE-2019-6977 | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. | HIGH 8.8EPSS 71.5% | 27 January 2019 |
| CVE-2019-6703 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. | CRITICAL 9.8EPSS 26.1% | 27 January 2019 |
| CVE-2019-6799 | When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. | MEDIUM 5.9EPSS 14.8% | 26 January 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.