Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 1 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-54647 | An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's… | EXPLOITHIGH 7.2EPSS 1.45% | 17 September 2026 |
| CVE-2026-54646 | An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database… | EXPLOITHIGH 7.2EPSS 1.45% | 17 September 2026 |
| CVE-2026-54645 | An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product… | EXPLOITMEDIUM 4.8EPSS 1.26% | 17 September 2026 |
| CVE-2026-54644 | Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. | EXPLOITMEDIUM 6.1EPSS 1.06% | 17 September 2026 |
| CVE-2026-51134 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml. | EXPLOITHIGH 7.5EPSS 1.89% | 15 September 2026 |
| CVE-2026-51133 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component | EXPLOITMEDIUM 6.1EPSS 0.87% | 15 September 2026 |
| CVE-2026-55584 | Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. | EXPLOITHIGH 7.5EPSS 2.42% | 28 August 2026 |
| CVE-2026-80428 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and… | EXPLOITCRITICAL 9.3EPSS 2.33% | 26 August 2026 |
| CVE-2026-67206 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. | EXPLOITHIGH 8.7EPSS 1.40% | 30 July 2026 |
| CVE-2025-50455 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. | EXPLOITCRITICAL 9.1EPSS 0.95% | 27 July 2026 |
| CVE-2026-65008 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without… | EXPLOITCRITICAL 9.3EPSS 2.02% | 21 July 2026 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 60.6% | 17 July 2026 |
| CVE-2026-44596 | Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote… | EXPLOITCRITICAL 9.8EPSS 2.06% | 16 July 2026 |
| CVE-2026-44595 | Yamcs is a mission control framework. | EXPLOITMEDIUM 4.3EPSS 1.06% | 16 July 2026 |
| CVE-2026-15013 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. | EXPLOITCRITICAL 9.8EPSS 1.50% | 16 July 2026 |
| CVE-2026-61876 | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. | EXPLOITCRITICAL 9.4EPSS 1.28% | 12 July 2026 |
| CVE-2026-61447 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. | EXPLOITCRITICAL 10.0EPSS 2.49% | 11 July 2026 |
| CVE-2026-3576 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. | EXPLOITHIGH 7.2EPSS 12.9% | 11 July 2026 |
| CVE-2026-61459 | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and… | EXPLOITCRITICAL 9.3EPSS 2.10% | 10 July 2026 |
| CVE-2026-55780 | A crafted bundle can cause an attacker-chosen allocation inside Extract, where std::bad_alloc or std::length_error can escape across the COM STDMETHODCALLTYPE boundary and crash the process. | EXPLOITLOW 2.4EPSS 0.42% | 10 July 2026 |
| CVE-2026-59827 | Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation,… | EXPLOITHIGH 8.8EPSS 3.25% | 9 July 2026 |
| CVE-2026-58480 | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through… | EXPLOITCRITICAL 9.2EPSS 3.57% | 8 July 2026 |
| CVE-2026-58289 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | EXPLOITHIGH 8.3EPSS 1.99% | 3 July 2026 |
| CVE-2026-14620 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request… | EXPLOITMEDIUM 4.7EPSS 0.52% | 3 July 2026 |
| CVE-2026-58138 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python… | EXPLOITCRITICAL 9.3EPSS 9.26% | 30 June 2026 |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 30.9% | 29 June 2026 |
| CVE-2026-58058 | A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans. | EXPLOITMEDIUM 6.9EPSS 1.37% | 28 June 2026 |
| CVE-2026-58057 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. | EXPLOITLOW 2.3EPSS 1.56% | 28 June 2026 |
| CVE-2026-48778 | When the user triggers IDM_FILE_OPEN_CMD (File → Open Containing Folder → cmd), NppCommands.cpp:228 creates a Command object with this value and calls run(), which invokes ShellExecute (RunDlg.cpp:221) with the attacker-controlled string as the… | EXPLOITHIGH 7.8EPSS 0.62% | 26 June 2026 |
| CVE-2026-56766 | Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. | EXPLOITHIGH 8.6EPSS 2.44% | 25 June 2026 |
| CVE-2026-57588 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data. | EXPLOITLOW 1.8EPSS 0.33% | 25 June 2026 |
| CVE-2026-48909 | SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server. | EXPLOITCRITICAL 9.5EPSS 4.94% | 20 June 2026 |
| CVE-2026-49952 | X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key… | EXPLOITCRITICAL 9.3EPSS 4.72% | 15 June 2026 |
| CVE-2026-36213 | An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component. | EXPLOITHIGH 7.8EPSS 0.58% | 15 June 2026 |
| CVE-2026-9271 | Vulnerability Title | EXPLOITMEDIUM 5.9EPSS 0.71% | 12 June 2026 |
| CVE-2026-42568 | Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. | EXPLOITMEDIUM 4.3EPSS 1.03% | 10 June 2026 |
| CVE-2026-46522 | Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. | EXPLOITHIGH 7.5EPSS 1.85% | 10 June 2026 |
| CVE-2026-49069 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. | EXPLOITHIGH 7.1EPSS 1.17% | 10 June 2026 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | KEVEXPLOIT ×2CRITICAL 10.0EPSS 78.1% | 5 June 2026 |
| CVE-2026-44680 | When application code passes attacker-influenced strings to public ORM APIs that expect an identifier or a JSON-property filter, an attacker can break out of the quoted context and inject arbitrary SQL. | EXPLOITHIGH 7.6EPSS 1.45% | 26 May 2026 |
| CVE-2026-46368 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the… | EXPLOITHIGH 8.7EPSS 6.58% | 26 May 2026 |
| CVE-2026-46300 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. | EXPLOITHIGH 7.8EPSS 9.33% | 23 May 2026 |
| CVE-2026-9082 | Drupal Core SQL Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 90.0% | 20 May 2026 |
| CVE-2026-44376 | Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. | EXPLOITMEDIUM 6.1EPSS 0.70% | 13 May 2026 |
| CVE-2026-44262 | From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code… | EXPLOITCRITICAL 9.4EPSS 5.86% | 12 May 2026 |
| CVE-2026-44403 | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. | EXPLOITHIGH 8.6EPSS 2.64% | 12 May 2026 |
| CVE-2026-44225 | Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. | EXPLOITCRITICAL 9.3EPSS 1.35% | 12 May 2026 |
| CVE-2026-6815 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. | EXPLOITMEDIUM 5.9EPSS 0.51% | 11 May 2026 |
| CVE-2026-42607 | Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. | EXPLOITCRITICAL 9.1EPSS 3.94% | 11 May 2026 |
| CVE-2026-43500 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the… | EXPLOIT ×2HIGH 7.8EPSS 92.9% | 11 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.