Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 5 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-3612 | A vulnerability was determined in Wavlink WL-NU516U1 V240425. | HIGH 7.3EPSS 12.7% | 6 March 2026 |
| CVE-2026-27944 | Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. | CRITICAL 9.8EPSS 22.2% | 5 March 2026 |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 10.0EPSS 33.4% | 4 March 2026 |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 10.0EPSS 75.8% | 4 March 2026 |
| CVE-2026-27446 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. | CRITICAL 9.3EPSS 10.0% | 4 March 2026 |
| CVE-2026-28289 | A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width… | HIGH 8.1EPSS 31.1% | 3 March 2026 |
| CVE-2026-1492 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including,… | CRITICAL 9.8EPSS 28.0% | 3 March 2026 |
| CVE-2026-28208 | Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. | MEDIUM 5.9EPSS 12.0% | 26 February 2026 |
| CVE-2026-27966 | Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). | CRITICAL 9.8EPSS 33.7% | 26 February 2026 |
| CVE-2026-22719 | Broadcom VMware Aria Operations Command Injection Vulnerability | KEVHIGH 8.1EPSS 17.4% | 25 February 2026 |
| CVE-2026-21902 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. | CRITICAL 9.3EPSS 17.7% | 25 February 2026 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | KEVHIGH 7.5EPSS 31.4% | 25 February 2026 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 88.2% | 25 February 2026 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | KEVMEDIUM 5.4EPSS 24.6% | 25 February 2026 |
| CVE-2026-27483 | Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. | HIGH 8.8EPSS 11.1% | 24 February 2026 |
| CVE-2026-3066 | This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformUtils.java of the component Cloud Compliance Scanning. | LOW 2.1EPSS 11.8% | 24 February 2026 |
| CVE-2026-3065 | A vulnerability was detected in HummerRisk up to 1.5.0. | LOW 2.1EPSS 30.5% | 24 February 2026 |
| CVE-2026-3064 | A security vulnerability has been detected in HummerRisk up to 1.5.0. | LOW 2.1EPSS 19.5% | 24 February 2026 |
| CVE-2026-26046 | A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. | HIGH 7.2EPSS 11.9% | 21 February 2026 |
| CVE-2026-2043 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 72.9% | 20 February 2026 |
| CVE-2026-2041 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. | HIGH 8.8EPSS 73.4% | 20 February 2026 |
| CVE-2026-2824 | Executing a manipulation of the argument destination can lead to command injection. | LOW 2.1EPSS 15.3% | 20 February 2026 |
| CVE-2026-2823 | A vulnerability was detected in Comfast CF-E7 2.6.0.9. | LOW 2.1EPSS 16.8% | 20 February 2026 |
| CVE-2026-26980 | Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. | HIGH 7.5EPSS 70.2% | 20 February 2026 |
| CVE-2026-2670 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA… | HIGH 7.3EPSS 12.3% | 18 February 2026 |
| CVE-2026-2329 | An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. | CRITICAL 9.3EPSS 40.0% | 18 February 2026 |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | KEVCRITICAL 10.0EPSS 13.1% | 17 February 2026 |
| CVE-2026-2615 | Executing a manipulation of the argument del_flag can lead to command injection. | HIGH 7.3EPSS 11.6% | 17 February 2026 |
| CVE-2026-2537 | A vulnerability was identified in Comfast CF-E4 2.6.0.1. | LOW 2.0EPSS 24.5% | 16 February 2026 |
| CVE-2026-2535 | A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. | LOW 2.1EPSS 13.5% | 16 February 2026 |
| CVE-2026-2534 | A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. | LOW 2.1EPSS 13.0% | 16 February 2026 |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability | KEVHIGH 8.8EPSS 22.4% | 13 February 2026 |
| CVE-2026-26190 | Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. | CRITICAL 9.8EPSS 36.9% | 13 February 2026 |
| CVE-2026-1357 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. | CRITICAL 9.8EPSS 32.7% | 11 February 2026 |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | KEVHIGH 8.8EPSS 15.6% | 10 February 2026 |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | KEVHIGH 8.8EPSS 26.2% | 10 February 2026 |
| CVE-2026-21249 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | LOW 3.3EPSS 11.1% | 10 February 2026 |
| CVE-2026-20841 | Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally. | HIGH 7.8EPSS 11.8% | 10 February 2026 |
| CVE-2026-0652 | On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. | HIGH 8.7EPSS 21.9% | 10 February 2026 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | KEVHIGH 7.5EPSS 80.6% | 10 February 2026 |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | KEVMEDIUM 5.9EPSS 29.6% | 10 February 2026 |
| CVE-2026-25939 | From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. | CRITICAL 9.3EPSS 11.7% | 9 February 2026 |
| CVE-2026-25895 | A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. | CRITICAL 9.5EPSS 11.2% | 9 February 2026 |
| CVE-2026-2184 | A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. | MEDIUM 6.9EPSS 10.3% | 8 February 2026 |
| CVE-2026-2131 | A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. | LOW 2.1EPSS 15.6% | 8 February 2026 |
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | KEVCRITICAL 9.9EPSS 89.5% | 6 February 2026 |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 94.1% | 6 February 2026 |
| CVE-2026-2000 | A vulnerability was found in DCN DCME-320 up to 20260121. | LOW 2.0EPSS 17.8% | 6 February 2026 |
| CVE-2026-25512 | Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. | CRITICAL 9.4EPSS 18.5% | 4 February 2026 |
| CVE-2026-1207 | Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. | MEDIUM 5.4EPSS 13.0% | 3 February 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.