Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 4 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-23696 | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. | CRITICAL 9.4EPSS 13.6% | 7 April 2026 |
| CVE-2026-22679 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking… | CRITICAL 9.3EPSS 20.4% | 7 April 2026 |
| CVE-2026-22666 | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. | HIGH 8.6EPSS 15.5% | 7 April 2026 |
| CVE-2026-34197 | Apache ActiveMQ Improper Input Validation Vulnerability | KEVHIGH 8.8EPSS 98.3% | 7 April 2026 |
| CVE-2026-0740 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. | CRITICAL 9.8EPSS 62.9% | 7 April 2026 |
| CVE-2026-35029 | A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code… | HIGH 8.7EPSS 25.1% | 6 April 2026 |
| CVE-2026-35616 | Fortinet FortiClient EMS Improper Access Control Vulnerability | KEVCRITICAL 9.8EPSS 90.7% | 4 April 2026 |
| CVE-2026-34938 | Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving… | CRITICAL 10.0EPSS 13.2% | 3 April 2026 |
| CVE-2026-35216 | Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. | CRITICAL 9.0EPSS 10.7% | 3 April 2026 |
| CVE-2026-2701 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | HIGH 8.8EPSS 54.5% | 2 April 2026 |
| CVE-2026-2699 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. | CRITICAL 9.8EPSS 59.5% | 2 April 2026 |
| CVE-2026-29014 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. | CRITICAL 9.3EPSS 39.5% | 1 April 2026 |
| CVE-2026-34156 | Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). | CRITICAL 9.9EPSS 35.0% | 31 March 2026 |
| CVE-2026-4020 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. | HIGH 7.5EPSS 40.0% | 31 March 2026 |
| CVE-2026-3300 | The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. | CRITICAL 9.8EPSS 39.2% | 31 March 2026 |
| CVE-2026-4257 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. | CRITICAL 9.8EPSS 41.5% | 30 March 2026 |
| CVE-2026-21710 | This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all… | HIGH 7.5EPSS 25.0% | 30 March 2026 |
| CVE-2026-33032 | In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. | CRITICAL 9.8EPSS 36.3% | 30 March 2026 |
| CVE-2026-5027 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../'). | HIGH 8.8EPSS 36.1% | 27 March 2026 |
| CVE-2026-4840 | Performing a manipulation of the argument IpAddr results in os command injection. | HIGH 7.4EPSS 10.5% | 26 March 2026 |
| CVE-2026-33340 | A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. | CRITICAL 9.1EPSS 21.6% | 24 March 2026 |
| CVE-2026-27654 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or… | HIGH 8.8EPSS 25.1% | 24 March 2026 |
| CVE-2026-33497 | Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. | HIGH 8.7EPSS 19.6% | 24 March 2026 |
| CVE-2026-33309 | Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. | CRITICAL 9.9EPSS 11.1% | 24 March 2026 |
| CVE-2026-33634 | Aquasecurity Trivy Embedded Malicious Code Vulnerability | KEVCRITICAL 9.4EPSS 59.2% | 23 March 2026 |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability | KEVCRITICAL 9.3EPSS 87.2% | 23 March 2026 |
| CVE-2026-33478 | In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. | CRITICAL 10.0EPSS 13.3% | 23 March 2026 |
| CVE-2026-33017 | Langflow Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 96.2% | 20 March 2026 |
| CVE-2026-22557 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account. | CRITICAL 10.0EPSS 28.1% | 19 March 2026 |
| CVE-2025-71260 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. | HIGH 8.7EPSS 34.4% | 19 March 2026 |
| CVE-2025-71259 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. | MEDIUM 5.3EPSS 12.9% | 19 March 2026 |
| CVE-2025-71258 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. | MEDIUM 5.3EPSS 17.4% | 19 March 2026 |
| CVE-2025-71257 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. | MEDIUM 6.9EPSS 44.6% | 19 March 2026 |
| CVE-2026-32255 | An unauthenticated attacker can use this to make HTTP requests from the server to internal services, cloud metadata endpoints, or private network resources. | HIGH 8.6EPSS 20.8% | 19 March 2026 |
| CVE-2026-4228 | A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. | LOW 2.1EPSS 12.2% | 16 March 2026 |
| CVE-2026-4197 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. | LOW 2.1EPSS 18.4% | 16 March 2026 |
| CVE-2026-3891 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. | CRITICAL 9.8EPSS 25.1% | 13 March 2026 |
| CVE-2026-32746 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | CRITICAL 9.8EPSS 23.7% | 13 March 2026 |
| CVE-2025-67038 | Lantronix EDS5000 Code Injection Vulnerability | KEVCRITICAL 9.3EPSS 19.3% | 11 March 2026 |
| CVE-2026-3943 | A vulnerability was found in H3C ACG1000-AK230 up to 20260227. | MEDIUM 5.5EPSS 39.5% | 11 March 2026 |
| CVE-2026-27825 | An attacker who can call this tool and supply or access a Confluence attachment with malicious content can write arbitrary content to any path the server process has write access to. | HIGH 8.0EPSS 12.7% | 10 March 2026 |
| CVE-2026-27826 | Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying two custom HTTP headers without an… | HIGH 8.2EPSS 13.6% | 10 March 2026 |
| CVE-2026-3854 | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. | HIGH 8.7EPSS 40.0% | 10 March 2026 |
| CVE-2026-31816 | In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. | CRITICAL 9.1EPSS 15.3% | 9 March 2026 |
| CVE-2026-3798 | A vulnerability was detected in Comfast CF-AC100 2.6.0.8. | LOW 2.0EPSS 15.5% | 9 March 2026 |
| CVE-2026-3662 | A vulnerability has been found in Wavlink WL-NU516U1 240425. | LOW 2.0EPSS 18.0% | 7 March 2026 |
| CVE-2026-3661 | This manipulation of the argument model causes command injection. | LOW 2.0EPSS 17.5% | 7 March 2026 |
| CVE-2026-30824 | Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. | HIGH 7.7EPSS 36.3% | 7 March 2026 |
| CVE-2026-30822 | Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. | HIGH 7.7EPSS 12.9% | 7 March 2026 |
| CVE-2026-30821 | Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. | HIGH 8.2EPSS 14.7% | 7 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.