Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 2 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | KEVHIGH 7.8EPSS 0.51% | 4 July 2026 |
| CVE-2026-48282 | Adobe ColdFusion Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 42.4% | 30 June 2026 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | KEVHIGH 8.8EPSS 1.61% | 30 June 2026 |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 30.4% | 29 June 2026 |
| CVE-2026-49869 | Kestra OSS OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 1.92% | 26 June 2026 |
| CVE-2026-55255 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | KEVHIGH 8.4EPSS 0.89% | 23 June 2026 |
| CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 20.1% | 20 June 2026 |
| CVE-2026-48908 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 15.1% | 20 June 2026 |
| CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | KEVCRITICAL 9.3EPSS 40.6% | 18 June 2026 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | KEVMEDIUM 6.5EPSS 28.2% | 15 June 2026 |
| CVE-2026-54420 | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | KEVHIGH 8.5EPSS 1.44% | 14 June 2026 |
| CVE-2026-48558 | SimpleHelp Authentication Bypass Vulnerability | KEVCRITICAL 9.5EPSS 64.3% | 12 June 2026 |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 95.5% | 11 June 2026 |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 96.9% | 10 June 2026 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 76.1% | 9 June 2026 |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 99.9% | 9 June 2026 |
| CVE-2026-11645 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | KEVHIGH 8.8EPSS 2.19% | 9 June 2026 |
| CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 83.8% | 8 June 2026 |
| CVE-2026-7473 | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | KEVMEDIUM 6.9EPSS 1.11% | 5 June 2026 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 78.1% | 5 June 2026 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | KEVHIGH 7.8EPSS 25.3% | 4 June 2026 |
| CVE-2026-28318 | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | KEVHIGH 7.5EPSS 40.0% | 4 June 2026 |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 4 June 2026 |
| CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 8.6EPSS 88.2% | 3 June 2026 |
| CVE-2025-48595 | Android Framework Integer Overflow Vulnerability | KEVHIGH 8.4EPSS 1.71% | 1 June 2026 |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 13.0% | 28 May 2026 |
| CVE-2026-48027 | Nx Console Embedded Malicious Code Vulnerability | KEVCRITICAL 9.3EPSS 1.85% | 27 May 2026 |
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | KEVMEDIUM 6.5EPSS 36.3% | 26 May 2026 |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.3EPSS 27.5% | 26 May 2026 |
| CVE-2026-45659 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 76.1% | 22 May 2026 |
| CVE-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability | KEVCRITICAL 10.0EPSS 87.5% | 22 May 2026 |
| CVE-2026-34909 | Ubiquiti UniFi OS Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 65.0% | 22 May 2026 |
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 85.2% | 22 May 2026 |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | KEVMEDIUM 6.7EPSS 12.7% | 21 May 2026 |
| CVE-2026-48172 | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | KEVCRITICAL 10.0EPSS 18.9% | 21 May 2026 |
| CVE-2026-9082 | Drupal Core SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 87.9% | 20 May 2026 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | KEVHIGH 7.5EPSS 63.1% | 20 May 2026 |
| CVE-2026-41091 | Microsoft Defender Link Following Vulnerability | KEVHIGH 7.8EPSS 8.20% | 20 May 2026 |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability | KEVCRITICAL 9.3EPSS 1.46% | 15 May 2026 |
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 71.2% | 14 May 2026 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 91.5% | 14 May 2026 |
| CVE-2026-0257 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | KEVHIGH 7.8EPSS 95.2% | 13 May 2026 |
| CVE-2026-45321 | TanStack Unspecified Vulnerability | KEVCRITICAL 9.6EPSS 2.34% | 12 May 2026 |
| CVE-2026-42271 | BerriAI LiteLLM Command Injection Vulnerability | KEVHIGH 8.7EPSS 83.6% | 8 May 2026 |
| CVE-2026-42208 | BerriAI LiteLLM SQL Injection Vulnerability | KEVCRITICAL 9.3EPSS 89.4% | 8 May 2026 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | KEVHIGH 7.2EPSS 34.5% | 7 May 2026 |
| CVE-2026-0300 | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | KEVCRITICAL 9.3EPSS 31.7% | 6 May 2026 |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.3EPSS 98.5% | 29 April 2026 |
| CVE-2026-31431 | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | KEVHIGH 7.8EPSS 99.9% | 22 April 2026 |
| CVE-2026-33825 | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | KEVHIGH 7.8EPSS 6.75% | 14 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.