Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 2 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-45502 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | MEDIUM 5.0EPSS 20.3% | 9 June 2026 |
| CVE-2026-45484 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | HIGH 8.8EPSS 35.2% | 9 June 2026 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 76.1% | 9 June 2026 |
| CVE-2026-10727 | An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root | HIGH 7.2EPSS 13.6% | 9 June 2026 |
| CVE-2026-10523 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access | CRITICAL 9.8EPSS 51.9% | 9 June 2026 |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 99.9% | 9 June 2026 |
| CVE-2026-49975 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. | HIGH 7.5EPSS 34.3% | 8 June 2026 |
| CVE-2026-46442 | Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. | CRITICAL 9.4EPSS 36.3% | 8 June 2026 |
| CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 83.8% | 8 June 2026 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 78.1% | 5 June 2026 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | KEVHIGH 7.8EPSS 25.3% | 4 June 2026 |
| CVE-2026-28318 | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | KEVHIGH 7.5EPSS 40.0% | 4 June 2026 |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 4 June 2026 |
| CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 8.6EPSS 88.2% | 3 June 2026 |
| CVE-2026-0826 | In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform. | CRITICAL 9.2EPSS 32.2% | 1 June 2026 |
| CVE-2026-49373 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | HIGH 8.8EPSS 27.1% | 29 May 2026 |
| CVE-2026-8732 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. | CRITICAL 9.8EPSS 22.7% | 29 May 2026 |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | KEVCRITICAL 9.8EPSS 13.0% | 28 May 2026 |
| CVE-2026-45087 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. | CRITICAL 10.0EPSS 13.0% | 27 May 2026 |
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | KEVMEDIUM 6.5EPSS 36.3% | 26 May 2026 |
| CVE-2026-4480 | A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. | CRITICAL 9.0EPSS 13.9% | 26 May 2026 |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.3EPSS 27.5% | 26 May 2026 |
| CVE-2026-9534 | Executing a manipulation of the argument PIN can lead to os command injection. | LOW 2.1EPSS 10.8% | 26 May 2026 |
| CVE-2026-9533 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. | LOW 2.1EPSS 10.8% | 26 May 2026 |
| CVE-2026-9532 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. | LOW 2.1EPSS 10.8% | 26 May 2026 |
| CVE-2026-9531 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. | LOW 2.1EPSS 10.8% | 26 May 2026 |
| CVE-2026-9515 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. | LOW 2.1EPSS 10.8% | 26 May 2026 |
| CVE-2026-9514 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. | LOW 2.1EPSS 10.8% | 25 May 2026 |
| CVE-2026-9441 | Performing a manipulation of the argument rootAPmac results in command injection. | LOW 2.1EPSS 11.7% | 25 May 2026 |
| CVE-2026-9440 | A vulnerability was identified in Edimax BR-6478AC 1.23. | LOW 2.1EPSS 13.0% | 25 May 2026 |
| CVE-2026-45659 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | KEVHIGH 8.8EPSS 76.1% | 22 May 2026 |
| CVE-2026-9256 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. | CRITICAL 9.2EPSS 10.9% | 22 May 2026 |
| CVE-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability | KEVCRITICAL 10.0EPSS 87.5% | 22 May 2026 |
| CVE-2026-34909 | Ubiquiti UniFi OS Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 65.0% | 22 May 2026 |
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 85.2% | 22 May 2026 |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | KEVMEDIUM 6.7EPSS 12.7% | 21 May 2026 |
| CVE-2026-48172 | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | KEVCRITICAL 10.0EPSS 18.9% | 21 May 2026 |
| CVE-2026-9082 | Drupal Core SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 87.9% | 20 May 2026 |
| CVE-2026-23734 | Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. | CRITICAL 9.3EPSS 19.6% | 20 May 2026 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | KEVHIGH 7.5EPSS 63.1% | 20 May 2026 |
| CVE-2026-45434 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. | CRITICAL 9.8EPSS 22.4% | 19 May 2026 |
| CVE-2026-45829 | A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true… | CRITICAL 10.0EPSS 12.4% | 18 May 2026 |
| CVE-2026-2652 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). | HIGH 8.6EPSS 20.8% | 15 May 2026 |
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting Vulnerability | KEVMEDIUM 6.1EPSS 71.2% | 14 May 2026 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 91.5% | 14 May 2026 |
| CVE-2026-8181 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. | CRITICAL 9.8EPSS 14.6% | 14 May 2026 |
| CVE-2026-0257 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | KEVHIGH 7.8EPSS 95.2% | 13 May 2026 |
| CVE-2026-44578 | From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. | HIGH 8.6EPSS 38.9% | 13 May 2026 |
| CVE-2026-42945 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. | CRITICAL 9.2EPSS 68.0% | 13 May 2026 |
| CVE-2026-34650 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. | HIGH 7.5EPSS 15.9% | 12 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.