Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,197 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 1 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 11.1% | 12 September 2026 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.8% | 26 August 2026 |
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | KEVCRITICAL 9.3EPSS 16.4% | 17 August 2026 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | KEVHIGH 8.9EPSS 32.4% | 13 August 2026 |
| CVE-2026-71362 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | CRITICAL 9.1EPSS 25.1% | 11 August 2026 |
| CVE-2026-48376 | is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. | MEDIUM 5.4EPSS 15.5% | 11 August 2026 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | KEVCRITICAL 10.0EPSS 94.2% | 10 August 2026 |
| CVE-2026-64638 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. | HIGH 8.9EPSS 31.2% | 7 August 2026 |
| CVE-2026-15733 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. | CRITICAL 9.8EPSS 13.5% | 6 August 2026 |
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVHIGH 8.2EPSS 54.1% | 2 August 2026 |
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVHIGH 8.2EPSS 40.2% | 1 August 2026 |
| CVE-2026-66066 | In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. | CRITICAL 9.5EPSS 27.9% | 30 July 2026 |
| CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 45.9% | 30 July 2026 |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | KEVMEDIUM 5.3EPSS 11.2% | 29 July 2026 |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 86.5% | 27 July 2026 |
| CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying… | CRITICAL 9.3EPSS 70.8% | 27 July 2026 |
| CVE-2026-16723 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. | CRITICAL 9.0EPSS 16.0% | 23 July 2026 |
| CVE-2026-62144 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. | CRITICAL 9.1EPSS 20.8% | 22 July 2026 |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 72.1% | 22 July 2026 |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 17 July 2026 |
| CVE-2026-60137 | WordPress Core SQL Injection Vulnerability | KEVMEDIUM 5.9EPSS 78.3% | 17 July 2026 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 60.6% | 17 July 2026 |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability | KEVCRITICAL 9.3EPSS 11.8% | 17 July 2026 |
| CVE-2026-48319 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.1EPSS 32.3% | 14 July 2026 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability | KEVHIGH 7.2EPSS 11.8% | 14 July 2026 |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | KEVCRITICAL 10.0EPSS 84.5% | 14 July 2026 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | KEVCRITICAL 9.1EPSS 50.6% | 14 July 2026 |
| CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 15.9% | 14 July 2026 |
| CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 26.6% | 14 July 2026 |
| CVE-2026-50522 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 85.4% | 14 July 2026 |
| CVE-2026-6875 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. | CRITICAL 9.5EPSS 77.6% | 13 July 2026 |
| CVE-2026-3576 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. | HIGH 7.2EPSS 12.9% | 11 July 2026 |
| CVE-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 14.9% | 9 July 2026 |
| CVE-2026-43825 | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream)… | HIGH 7.3EPSS 13.9% | 6 July 2026 |
| CVE-2026-48282 | Adobe ColdFusion Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 42.4% | 30 June 2026 |
| CVE-2026-8451 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | HIGH 8.8EPSS 15.7% | 30 June 2026 |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 30.4% | 29 June 2026 |
| CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 20.1% | 20 June 2026 |
| CVE-2026-48908 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 15.1% | 20 June 2026 |
| CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | KEVCRITICAL 9.3EPSS 40.6% | 18 June 2026 |
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | HIGH 7.0EPSS 11.4% | 16 June 2026 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | KEVMEDIUM 6.5EPSS 28.2% | 15 June 2026 |
| CVE-2026-48558 | SimpleHelp Authentication Bypass Vulnerability | KEVCRITICAL 9.5EPSS 64.3% | 12 June 2026 |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 95.5% | 11 June 2026 |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 96.9% | 10 June 2026 |
| CVE-2026-20251 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a… | HIGH 8.8EPSS 32.2% | 10 June 2026 |
| CVE-2026-53435 | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle… | HIGH 8.8EPSS 53.1% | 10 June 2026 |
| CVE-2026-49160 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | HIGH 7.5EPSS 53.8% | 9 June 2026 |
| CVE-2026-47291 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 22.8% | 9 June 2026 |
| CVE-2026-45657 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 15.5% | 9 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.