Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
25,049 results · page 3 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-25732 | Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern UPLOAD_DIR / file.name. | EXPLOITHIGH 7.5EPSS 3.34% | 6 February 2026 |
| CVE-2026-25544 | Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. | EXPLOITCRITICAL 9.8EPSS 0.77% | 6 February 2026 |
| CVE-2026-25643 | Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. | EXPLOITCRITICAL 9.1EPSS 2.93% | 6 February 2026 |
| CVE-2026-25047 | A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. | EXPLOITCRITICAL 9.4EPSS 0.74% | 29 January 2026 |
| CVE-2026-24897 | In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares. | EXPLOITHIGH 8.8EPSS 3.13% | 28 January 2026 |
| CVE-2025-70336 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. | EXPLOITMEDIUM 4.8EPSS 0.40% | 28 January 2026 |
| CVE-2026-24486 | Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. | EXPLOITHIGH 7.5EPSS 2.21% | 27 January 2026 |
| CVE-2026-24479 | Attackers can craft a malicious ZIP file containing files with path traversal sequences (e.g., ../../shell.php). | EXPLOITCRITICAL 9.3EPSS 8.21% | 27 January 2026 |
| CVE-2026-24421 | Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoint to any authenticated user despite their permissions. | EXPLOITMEDIUM 6.5EPSS 1.83% | 24 January 2026 |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 63.4% | 23 January 2026 |
| CVE-2025-68137 | Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. | EXPLOITHIGH 8.3EPSS 1.09% | 21 January 2026 |
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 98.1% | 21 January 2026 |
| CVE-2026-23744 | Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. | EXPLOITCRITICAL 9.8EPSS 64.8% | 16 January 2026 |
| CVE-2026-22704 | In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. | EXPLOITMEDIUM 5.4EPSS 1.04% | 10 January 2026 |
| CVE-2026-22241 | Prior to version 4.2, an arbitrary file upload vulnerability in the theme import functionality enables an attacker with administrative privileges to upload arbitrary files on the server's file system. | EXPLOITHIGH 7.3EPSS 3.31% | 8 January 2026 |
| CVE-2026-21876 | Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. | EXPLOITMEDIUM 5.3EPSS 17.5% | 8 January 2026 |
| CVE-2025-69210 | Prior to version 2025.7, a stored cross-site scripting (XSS) vulnerability exists in the product file upload functionality. | EXPLOITLOW 1.2EPSS 0.99% | 30 December 2025 |
| CVE-2025-68664 | Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. | EXPLOITHIGH 8.2EPSS 42.9% | 23 December 2025 |
| CVE-2025-14018 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. | EXPLOITHIGH 7.3EPSS 0.45% | 22 December 2025 |
| CVE-2025-67586 | Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0. | EXPLOITMEDIUM 4.7EPSS 0.44% | 9 December 2025 |
| CVE-2025-40271 | In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. | EXPLOITHIGH 7.8EPSS 0.46% | 6 December 2025 |
| CVE-2025-65027 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. | EXPLOITHIGH 7.6EPSS 0.33% | 3 December 2025 |
| CVE-2025-55182 | Meta React Server Components Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 99.8% | 3 December 2025 |
| CVE-2025-12744 | An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges. | EXPLOITHIGH 8.8EPSS 0.64% | 3 December 2025 |
| CVE-2025-11001 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. | EXPLOITHIGH 7.8EPSS 27.0% | 19 November 2025 |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability | KEVEXPLOIT ×2CRITICAL 9.8EPSS 91.8% | 14 November 2025 |
| CVE-2025-60690 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). | EXPLOITHIGH 8.8EPSS 3.91% | 13 November 2025 |
| CVE-2025-60689 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). | EXPLOITMEDIUM 5.4EPSS 17.5% | 13 November 2025 |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability | KEVEXPLOITHIGH 7.0EPSS 5.99% | 11 November 2025 |
| CVE-2025-60188 | Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.1. | EXPLOITHIGH 7.5EPSS 3.48% | 6 November 2025 |
| CVE-2025-64459 | The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. | EXPLOITCRITICAL 9.1EPSS 19.4% | 5 November 2025 |
| CVE-2025-60751 | GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. | EXPLOITHIGH 7.5EPSS 2.15% | 21 October 2025 |
| CVE-2025-62639 | Rejected reason: Not used | EXPLOITUnscoredEPSS — | 18 October 2025 |
| CVE-2025-34282 | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. | EXPLOITMEDIUM 6.9EPSS 1.82% | 17 October 2025 |
| CVE-2025-59254 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | EXPLOITHIGH 7.8EPSS 1.13% | 14 October 2025 |
| CVE-2025-55315 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | EXPLOITCRITICAL 9.9EPSS 65.9% | 14 October 2025 |
| CVE-2025-62360 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente… | EXPLOITCRITICAL 9.4EPSS 0.89% | 13 October 2025 |
| CVE-2025-10162 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal… | EXPLOITHIGH 7.5EPSS 3.89% | 7 October 2025 |
| CVE-2025-60787 | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. | EXPLOITHIGH 7.2EPSS 18.5% | 3 October 2025 |
| CVE-2025-48868 | An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive view. | EXPLOITHIGH 7.2EPSS 2.47% | 24 September 2025 |
| CVE-2025-59528 | In version 3.0.5, Flowise is vulnerable to remote code execution. | EXPLOITCRITICAL 10.0EPSS 86.2% | 22 September 2025 |
| CVE-2025-52367 | Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field. | EXPLOITMEDIUM 5.4EPSS 4.11% | 22 September 2025 |
| CVE-2025-55912 | An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler | EXPLOITHIGH 7.3EPSS 1.54% | 18 September 2025 |
| CVE-2025-55911 | An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter | EXPLOITMEDIUM 6.5EPSS 1.07% | 18 September 2025 |
| CVE-2025-10666 | Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. | EXPLOITHIGH 7.4EPSS 3.30% | 18 September 2025 |
| CVE-2025-40677 | SQL injection vulnerability in Summar Software´s Portal del Empleado. | EXPLOITHIGH 8.7EPSS 0.63% | 18 September 2025 |
| CVE-2025-10493 | The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. | EXPLOITMEDIUM 5.3EPSS 0.92% | 18 September 2025 |
| CVE-2025-59342 | In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. | EXPLOITMEDIUM 5.5EPSS 3.03% | 17 September 2025 |
| CVE-2025-10042 | The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | EXPLOITHIGH 7.5EPSS 0.94% | 17 September 2025 |
| CVE-2025-57176 | On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. | EXPLOITMEDIUM 6.5EPSS 0.41% | 15 September 2025 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.