Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,197 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 1 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS — | 14 September 2026 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 11.1% | 12 September 2026 |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | KEVHIGH 8.8EPSS 0.86% | 9 September 2026 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | KEVCRITICAL 9.9EPSS 0.69% | 8 September 2026 |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 0.57% | 8 September 2026 |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | KEVHIGH 7.8EPSS 0.63% | 8 September 2026 |
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | KEVCRITICAL 10.0EPSS 2.15% | 7 September 2026 |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability | KEVCRITICAL 10.0EPSS 0.74% | 6 September 2026 |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | KEVCRITICAL 9.2EPSS 1.02% | 5 September 2026 |
| CVE-2026-67277 | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | KEVHIGH 8.8EPSS 0.86% | 5 September 2026 |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | KEVHIGH 8.8EPSS 1.26% | 3 September 2026 |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | KEVHIGH 7.8EPSS 8.51% | 1 September 2026 |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | KEVCRITICAL 10.0EPSS 4.67% | 1 September 2026 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 7.67% | 28 August 2026 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | KEVCRITICAL 9.4EPSS 1.69% | 28 August 2026 |
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | KEVHIGH 8.8EPSS 1.62% | 28 August 2026 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.8% | 26 August 2026 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | KEVCRITICAL 9.5EPSS 1.83% | 19 August 2026 |
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.3EPSS 1.55% | 19 August 2026 |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.3EPSS 5.60% | 19 August 2026 |
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | KEVCRITICAL 9.3EPSS 16.4% | 17 August 2026 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | KEVHIGH 8.9EPSS 32.4% | 13 August 2026 |
| CVE-2026-42018 | JFrog Artifactory Improper Authentication Vulnerability | KEVHIGH 7.5EPSS 0.92% | 12 August 2026 |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | KEVMEDIUM 5.3EPSS 0.58% | 12 August 2026 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | KEVHIGH 7.0EPSS 6.18% | 11 August 2026 |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | KEVHIGH 8.6EPSS 2.21% | 11 August 2026 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | KEVCRITICAL 10.0EPSS 94.2% | 10 August 2026 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 9.90% | 6 August 2026 |
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVHIGH 8.2EPSS 54.1% | 2 August 2026 |
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVHIGH 8.2EPSS 40.2% | 1 August 2026 |
| CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 45.9% | 30 July 2026 |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | KEVMEDIUM 5.3EPSS 11.2% | 29 July 2026 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | KEVHIGH 8.8EPSS 0.89% | 27 July 2026 |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 86.5% | 27 July 2026 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 1.57% | 27 July 2026 |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 72.1% | 22 July 2026 |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 17 July 2026 |
| CVE-2026-60137 | WordPress Core SQL Injection Vulnerability | KEVMEDIUM 5.9EPSS 78.3% | 17 July 2026 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 60.6% | 17 July 2026 |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability | KEVCRITICAL 9.3EPSS 11.8% | 17 July 2026 |
| CVE-2021-27137 | DD-WRT Stack-Based Buffer Overflow Vulnerability | KEVHIGH 8.1EPSS 4.00% | 16 July 2026 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability | KEVHIGH 7.2EPSS 11.8% | 14 July 2026 |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | KEVCRITICAL 10.0EPSS 84.5% | 14 July 2026 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | KEVCRITICAL 9.1EPSS 50.6% | 14 July 2026 |
| CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 15.9% | 14 July 2026 |
| CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 26.6% | 14 July 2026 |
| CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | KEVHIGH 7.8EPSS 0.35% | 14 July 2026 |
| CVE-2026-50522 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 85.4% | 14 July 2026 |
| CVE-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 14.9% | 9 July 2026 |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | KEVHIGH 8.8EPSS 0.87% | 8 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.