Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 2 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-43284 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. | EXPLOIT ×2HIGH 8.8EPSS 93.2% | 8 May 2026 |
| CVE-2024-30167 | /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter. | EXPLOITMEDIUM 6.3EPSS 1.14% | 8 May 2026 |
| CVE-2026-34474 | Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. | EXPLOITHIGH 7.5EPSS 24.7% | 6 May 2026 |
| CVE-2026-34473 | A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. | EXPLOITHIGH 7.5EPSS 2.38% | 6 May 2026 |
| CVE-2026-36356 | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint. | EXPLOITCRITICAL 9.1EPSS 13.5% | 5 May 2026 |
| CVE-2026-36355 | The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into… | EXPLOITHIGH 7.7EPSS 0.67% | 5 May 2026 |
| CVE-2026-23918 | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. | EXPLOITHIGH 8.8EPSS 49.7% | 4 May 2026 |
| CVE-2026-42471 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. | EXPLOITHIGH 8.1EPSS 1.76% | 1 May 2026 |
| CVE-2026-7567 | The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. | EXPLOITCRITICAL 9.8EPSS 9.25% | 1 May 2026 |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 98.5% | 29 April 2026 |
| CVE-2026-42167 | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM). | EXPLOITHIGH 8.1EPSS 7.39% | 28 April 2026 |
| CVE-2026-41456 | Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. | EXPLOITMEDIUM 5.1EPSS 1.90% | 21 April 2026 |
| CVE-2026-33829 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | EXPLOITMEDIUM 4.3EPSS 3.45% | 14 April 2026 |
| CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability | KEVEXPLOITMEDIUM 4.3EPSS 63.7% | 14 April 2026 |
| CVE-2026-38526 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. | EXPLOITCRITICAL 9.9EPSS 3.82% | 14 April 2026 |
| CVE-2026-33534 | Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4 representations such as octal notation (e.g., 0177.0.0.1 instead of… | EXPLOITMEDIUM 4.3EPSS 1.98% | 13 April 2026 |
| CVE-2026-39987 | Marimo Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 99.6% | 9 April 2026 |
| CVE-2026-1830 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. | EXPLOITCRITICAL 9.8EPSS 8.09% | 9 April 2026 |
| CVE-2026-4631 | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. | EXPLOITCRITICAL 9.8EPSS 15.5% | 7 April 2026 |
| CVE-2026-0740 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. | EXPLOITCRITICAL 9.8EPSS 62.9% | 7 April 2026 |
| CVE-2026-33641 | Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. | EXPLOITHIGH 7.8EPSS 0.87% | 2 April 2026 |
| CVE-2026-34156 | Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). | EXPLOITCRITICAL 9.9EPSS 35.0% | 31 March 2026 |
| CVE-2026-4257 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. | EXPLOITCRITICAL 9.8EPSS 41.5% | 30 March 2026 |
| CVE-2026-34472 | Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including… | EXPLOITHIGH 7.1EPSS 8.55% | 30 March 2026 |
| CVE-2026-5027 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../'). | EXPLOITHIGH 8.8EPSS 36.1% | 27 March 2026 |
| CVE-2026-25099 | Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. | EXPLOITHIGH 8.7EPSS 1.92% | 27 March 2026 |
| CVE-2026-33017 | Langflow Code Injection Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 96.2% | 20 March 2026 |
| CVE-2026-3891 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. | EXPLOITCRITICAL 9.8EPSS 25.1% | 13 March 2026 |
| CVE-2026-32746 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | EXPLOITCRITICAL 9.8EPSS 23.7% | 13 March 2026 |
| CVE-2025-14558 | A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed. | EXPLOITHIGH 7.2EPSS 6.27% | 9 March 2026 |
| CVE-2026-29053 | From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. | EXPLOITCRITICAL 9.8EPSS 3.58% | 5 March 2026 |
| CVE-2026-23231 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before… | EXPLOITHIGH 7.8EPSS 0.79% | 4 March 2026 |
| CVE-2026-3180 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to… | EXPLOITHIGH 7.5EPSS 0.95% | 2 March 2026 |
| CVE-2026-2624 | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. | EXPLOITCRITICAL 9.8EPSS 2.19% | 25 February 2026 |
| CVE-2026-24849 | Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. | EXPLOITMEDIUM 6.5EPSS 2.16% | 25 February 2026 |
| CVE-2025-69985 | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). | EXPLOITCRITICAL 9.8EPSS 5.63% | 24 February 2026 |
| CVE-2026-27483 | Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. | EXPLOITHIGH 8.8EPSS 11.1% | 24 February 2026 |
| CVE-2025-68930 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. | EXPLOITMEDIUM 6.5EPSS 0.54% | 23 February 2026 |
| CVE-2026-26980 | Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. | EXPLOITHIGH 7.5EPSS 70.2% | 20 February 2026 |
| CVE-2026-0926 | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[template_name]' parameter. | EXPLOITCRITICAL 9.8EPSS 9.40% | 19 February 2026 |
| CVE-2026-26335 | An attacker who obtains these keys can craft a valid ASP.NET ViewState payload that passes integrity validation and is accepted by the application, resulting in server-side deserialization and remote code execution in the context of the IIS application. | EXPLOITCRITICAL 9.3EPSS 2.92% | 13 February 2026 |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability | KEVEXPLOITHIGH 8.8EPSS 22.4% | 13 February 2026 |
| CVE-2026-26235 | JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. | EXPLOITHIGH 8.7EPSS 1.85% | 12 February 2026 |
| CVE-2026-26157 | Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. | EXPLOITHIGH 7.0EPSS 0.71% | 11 February 2026 |
| CVE-2026-25994 | In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames. | EXPLOITHIGH 8.1EPSS 2.00% | 11 February 2026 |
| CVE-2026-21250 | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.8EPSS 1.08% | 10 February 2026 |
| CVE-2026-21248 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | EXPLOITHIGH 7.3EPSS 1.29% | 10 February 2026 |
| CVE-2026-21244 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | EXPLOITHIGH 7.3EPSS 1.29% | 10 February 2026 |
| CVE-2026-25895 | A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. | EXPLOITCRITICAL 9.5EPSS 11.2% | 9 February 2026 |
| CVE-2026-25961 | In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installers without signature checks. | EXPLOITHIGH 7.5EPSS 0.45% | 9 February 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.