Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,516 CVEs1,716 in CISA KEV17,386 with EPSS ≥ 10%Updated 19 September 2026
17,386 results · page 136 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | KEVHIGH 7.5EPSS 99.9% | 24 January 2019 |
| CVE-2019-1652 | Cisco Small Business Routers Improper Input Validation Vulnerability | KEVHIGH 7.2EPSS 95.9% | 24 January 2019 |
| CVE-2018-17686 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. | MEDIUM 6.5EPSS 24.4% | 24 January 2019 |
| CVE-2019-1636 | A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. | HIGH 7.8EPSS 46.9% | 23 January 2019 |
| CVE-2019-6706 | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. | HIGH 7.5EPSS 17.2% | 23 January 2019 |
| CVE-2019-6339 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. | CRITICAL 9.8EPSS 33.2% | 22 January 2019 |
| CVE-2019-1003002 | A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read… | HIGH 8.8EPSS 81.4% | 22 January 2019 |
| CVE-2019-1003001 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows… | HIGH 8.8EPSS 86.1% | 22 January 2019 |
| CVE-2019-1003000 | A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute… | HIGH 8.8EPSS 98.4% | 22 January 2019 |
| CVE-2018-13374 | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | KEVMEDIUM 4.3EPSS 37.8% | 22 January 2019 |
| CVE-2018-16042 | Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have… | MEDIUM 6.5EPSS 82.4% | 18 January 2019 |
| CVE-2018-15982 | Adobe Flash Player Use-After-Free Vulnerability | KEVHIGH 7.8EPSS 89.1% | 18 January 2019 |
| CVE-2018-5740 | "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. | HIGH 7.5EPSS 59.6% | 16 January 2019 |
| CVE-2018-5738 | The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the… | HIGH 7.5EPSS 11.2% | 16 January 2019 |
| CVE-2018-5737 | Deliberate exploitation of this condition could cause operational problems depending on the particular manifestation -- either degradation or denial of service. | HIGH 7.5EPSS 10.4% | 16 January 2019 |
| CVE-2018-5736 | This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate zone transfers (for example: by sending valid NOTIFY messages), causing the named process to exit after failing the assertion test. | MEDIUM 5.3EPSS 18.0% | 16 January 2019 |
| CVE-2018-5733 | A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. | HIGH 7.5EPSS 20.2% | 16 January 2019 |
| CVE-2017-3145 | BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. | HIGH 7.5EPSS 27.9% | 16 January 2019 |
| CVE-2017-3144 | A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. | HIGH 7.5EPSS 72.7% | 16 January 2019 |
| CVE-2017-3143 | An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. | MEDIUM 5.9EPSS 18.3% | 16 January 2019 |
| CVE-2017-3140 | If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. | MEDIUM 5.9EPSS 12.2% | 16 January 2019 |
| CVE-2017-3136 | An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. | MEDIUM 5.9EPSS 11.2% | 16 January 2019 |
| CVE-2017-3135 | Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. | MEDIUM 5.9EPSS 17.2% | 16 January 2019 |
| CVE-2019-6447 | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. | HIGH 8.1EPSS 63.8% | 16 January 2019 |
| CVE-2019-6446 | It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. | CRITICAL 9.8EPSS 17.5% | 16 January 2019 |
| CVE-2019-6445 | An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem. | MEDIUM 6.5EPSS 14.1% | 16 January 2019 |
| CVE-2019-6444 | An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd. | CRITICAL 9.1EPSS 45.7% | 16 January 2019 |
| CVE-2019-6443 | An issue was discovered in NTPsec before 1.1.3. | CRITICAL 9.1EPSS 66.9% | 16 January 2019 |
| CVE-2019-6442 | An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y. | MEDIUM 6.5EPSS 13.7% | 16 January 2019 |
| CVE-2017-18357 | Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object. | MEDIUM 6.5EPSS 27.1% | 15 January 2019 |
| CVE-2018-4404 | In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling. | HIGH 8.8EPSS 13.9% | 11 January 2019 |
| CVE-2019-5893 | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. | CRITICAL 9.8EPSS 24.7% | 10 January 2019 |
| CVE-2018-16167 | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | CRITICAL 9.8EPSS 74.9% | 9 January 2019 |
| CVE-2017-15428 | Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | HIGH 8.8EPSS 18.1% | 9 January 2019 |
| CVE-2016-9651 | A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | HIGH 8.8EPSS 11.2% | 9 January 2019 |
| CVE-2019-0586 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | CRITICAL 9.8EPSS 15.4% | 8 January 2019 |
| CVE-2019-0585 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer,… | HIGH 8.8EPSS 22.0% | 8 January 2019 |
| CVE-2019-0584 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 13.6% | 8 January 2019 |
| CVE-2019-0583 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 16.1% | 8 January 2019 |
| CVE-2019-0582 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 12.3% | 8 January 2019 |
| CVE-2019-0581 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 13.6% | 8 January 2019 |
| CVE-2019-0580 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 17.3% | 8 January 2019 |
| CVE-2019-0579 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 17.3% | 8 January 2019 |
| CVE-2019-0578 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 13.6% | 8 January 2019 |
| CVE-2019-0577 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 17.3% | 8 January 2019 |
| CVE-2019-0576 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 17.3% | 8 January 2019 |
| CVE-2019-0575 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | HIGH 7.8EPSS 13.6% | 8 January 2019 |
| CVE-2019-0574 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | HIGH 7.8EPSS 19.4% | 8 January 2019 |
| CVE-2019-0573 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | HIGH 7.8EPSS 20.1% | 8 January 2019 |
| CVE-2019-0572 | An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows… | HIGH 7.8EPSS 25.1% | 8 January 2019 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.