Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
1,710 results · page 3 of 35
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | KEVCRITICAL 9.8EPSS 72.7% | 14 April 2026 |
| CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability | KEVMEDIUM 4.3EPSS 63.7% | 14 April 2026 |
| CVE-2026-32201 | Microsoft SharePoint Server Improper Input Validation Vulnerability | KEVMEDIUM 6.5EPSS 43.4% | 14 April 2026 |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 92.8% | 14 April 2026 |
| CVE-2026-34621 | Adobe Acrobat and Reader Prototype Pollution Vulnerability | KEVHIGH 8.6EPSS 7.09% | 11 April 2026 |
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | KEVHIGH 7.5EPSS 98.6% | 9 April 2026 |
| CVE-2026-39987 | Marimo Remote Code Execution Vulnerability | KEVCRITICAL 9.3EPSS 98.9% | 9 April 2026 |
| CVE-2026-34197 | Apache ActiveMQ Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 98.3% | 7 April 2026 |
| CVE-2026-35616 | Fortinet FortiClient EMS Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 90.7% | 4 April 2026 |
| CVE-2026-5281 | Google Dawn Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 4.94% | 1 April 2026 |
| CVE-2026-3502 | TrueConf Client Download of Code Without Integrity Check Vulnerability | KEVHIGH 7.8EPSS 5.75% | 30 March 2026 |
| CVE-2026-33634 | Aquasecurity Trivy Embedded Malicious Code Vulnerability | KEVCRITICAL 9.4EPSS 59.2% | 23 March 2026 |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability | KEVCRITICAL 9.3EPSS 87.2% | 23 March 2026 |
| CVE-2026-33017 | Langflow Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 96.2% | 20 March 2026 |
| CVE-2026-3910 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | KEVHIGH 8.8EPSS 2.00% | 13 March 2026 |
| CVE-2026-3909 | Google Skia Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 1.63% | 13 March 2026 |
| CVE-2025-67038 | Lantronix EDS5000 Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 19.3% | 11 March 2026 |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 10.0EPSS 33.4% | 4 March 2026 |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 10.0EPSS 75.8% | 4 March 2026 |
| CVE-2026-21385 | Qualcomm Multiple Chipsets Memory Corruption Vulnerability | KEVHIGH 7.8EPSS 1.29% | 2 March 2026 |
| CVE-2026-22719 | Broadcom VMware Aria Operations Command Injection Vulnerability | KEVHIGH 8.1EPSS 17.4% | 25 February 2026 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | KEVHIGH 7.5EPSS 31.4% | 25 February 2026 |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | KEVHIGH 7.5EPSS 6.94% | 25 February 2026 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 88.2% | 25 February 2026 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | KEVMEDIUM 5.4EPSS 24.6% | 25 February 2026 |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | KEVCRITICAL 10.0EPSS 13.1% | 17 February 2026 |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 22.4% | 13 February 2026 |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability | KEVHIGH 8.7EPSS 5.07% | 13 February 2026 |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability | KEVHIGH 7.8EPSS 1.34% | 11 February 2026 |
| CVE-2026-21533 | Microsoft Windows Improper Privilege Management Vulnerability | KEVHIGH 7.8EPSS 3.91% | 10 February 2026 |
| CVE-2026-21525 | Microsoft Windows NULL Pointer Dereference Vulnerability | KEVMEDIUM 6.2EPSS 5.04% | 10 February 2026 |
| CVE-2026-21519 | Microsoft Windows Type Confusion Vulnerability | KEVHIGH 7.8EPSS 2.46% | 10 February 2026 |
| CVE-2026-21514 | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | KEVHIGH 7.8EPSS 1.54% | 10 February 2026 |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | KEVHIGH 8.8EPSS 15.6% | 10 February 2026 |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | KEVHIGH 8.8EPSS 26.2% | 10 February 2026 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 80.6% | 10 February 2026 |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | KEVMEDIUM 5.9EPSS 29.6% | 10 February 2026 |
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | KEVCRITICAL 9.9EPSS 89.5% | 6 February 2026 |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.1% | 6 February 2026 |
| CVE-2025-15556 | Notepad++ Download of Code Without Integrity Check Vulnerability | KEVHIGH 7.7EPSS 1.71% | 3 February 2026 |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.2% | 29 January 2026 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 81.8% | 29 January 2026 |
| CVE-2025-40551 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 83.6% | 28 January 2026 |
| CVE-2025-40536 | SolarWinds Web Help Desk Security Control Bypass Vulnerability | KEVCRITICAL 9.8EPSS 81.6% | 28 January 2026 |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.8EPSS 86.1% | 27 January 2026 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 72.6% | 26 January 2026 |
| CVE-2026-24423 | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.3EPSS 88.0% | 23 January 2026 |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVCRITICAL 9.8EPSS 63.4% | 23 January 2026 |
| CVE-2026-23760 | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.3EPSS 96.4% | 22 January 2026 |
| CVE-2026-20045 | Cisco Unified Communications Products Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 4.48% | 21 January 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.