Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
400,783 CVEs1,731 in CISA KEV17,275 with EPSS ≥ 10%25,052 with a public exploitUpdated 2 October 2026
Known exploited — most recently added
All KEV entries →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-104286 | Fortinet FortiMail Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS — | 1 October 2026 |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | KEVCRITICAL 9.8EPSS 1.10% | 30 September 2026 |
| CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 1.24% | 28 September 2026 |
| CVE-2026-88771 | Citrix NetScaler Improper Input Validation Vulnerability | KEVCRITICAL 9.5EPSS 1.06% | 27 September 2026 |
| CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | KEVCRITICAL 9.5EPSS 1.30% | 27 September 2026 |
| CVE-2026-65660 | Microsoft SharePoint Code Injection Vulnerability | KEVHIGH 8.8EPSS 2.10% | 11 August 2026 |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability | KEVEXPLOITHIGH 8.1EPSS 19.8% | 22 September 2026 |
| CVE-2026-67279 | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | KEVMEDIUM 6.9EPSS 1.03% | 5 September 2026 |
Newest public exploits
All with a public exploit →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-100885 | A vulnerability was found in Krayin laravel-crm up to 2.2.4. | EXPLOITMEDIUM 5.5EPSS 0.40% | 27 September 2026 |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability | KEVEXPLOITHIGH 8.1EPSS 19.8% | 22 September 2026 |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | KEVEXPLOITCRITICAL 9.2EPSS 1.85% | 5 September 2026 |
| CVE-2026-80428 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and… | EXPLOITCRITICAL 9.3EPSS 4.67% | 26 August 2026 |
| CVE-2025-57819 | Sangoma FreePBX Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 85.5% | 28 August 2025 |
| CVE-2026-59827 | Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation,… | EXPLOITHIGH 8.8EPSS 3.79% | 9 July 2026 |
| CVE-2026-39987 | Marimo Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 37.9% | 9 April 2026 |
| CVE-2025-70336 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. | EXPLOITMEDIUM 4.8EPSS 0.55% | 28 January 2026 |
Most likely to be exploited this month
All with EPSS ≥ 10% →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 13 August 2024 |
| CVE-2024-3400 | Palo Alto Networks PAN-OS Command Injection Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 100.0% | 12 April 2024 |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 24 January 2024 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 8.2EPSS 100.0% | 31 January 2024 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 12 January 2024 |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-44487 | HTTP/2 Rapid Reset Attack Vulnerability | KEVEXPLOITHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 15 August 2023 |
Newest CVEs
Browse everything →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-96289 | Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. | HIGH 8.2EPSS — | 2 October 2026 |
| CVE-2026-96287 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. | HIGH 8.2EPSS — | 2 October 2026 |
| CVE-2026-96286 | Uncaught exception vulnerability in Apache Thrift Perl bindings. | HIGH 8.2EPSS — | 2 October 2026 |
| CVE-2026-96277 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. | HIGH 8.7EPSS — | 2 October 2026 |
| CVE-2026-94658 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. | HIGH 8.7EPSS — | 2 October 2026 |
| CVE-2026-94657 | Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. | HIGH 8.2EPSS — | 2 October 2026 |
| CVE-2026-94656 | Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. | HIGH 8.2EPSS — | 2 October 2026 |
| CVE-2026-94655 | Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. | HIGH 8.2EPSS — | 2 October 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.