Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026
17,375 results · page 6 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-0599 | A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. | HIGH 7.5EPSS 27.6% | 2 February 2026 |
| CVE-2026-25253 | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value. | HIGH 8.8EPSS 24.0% | 1 February 2026 |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.2% | 29 January 2026 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 81.8% | 29 January 2026 |
| CVE-2020-36962 | Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. | MEDIUM 5.3EPSS 10.9% | 28 January 2026 |
| CVE-2026-1056 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. | CRITICAL 9.8EPSS 12.5% | 28 January 2026 |
| CVE-2025-40554 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk. | CRITICAL 9.8EPSS 58.4% | 28 January 2026 |
| CVE-2025-40553 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. | CRITICAL 9.8EPSS 60.4% | 28 January 2026 |
| CVE-2025-40552 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. | CRITICAL 9.8EPSS 49.7% | 28 January 2026 |
| CVE-2025-40551 | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 83.6% | 28 January 2026 |
| CVE-2025-40536 | SolarWinds Web Help Desk Security Control Bypass Vulnerability | KEVCRITICAL 9.8EPSS 81.6% | 28 January 2026 |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.8EPSS 86.1% | 27 January 2026 |
| CVE-2025-15467 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. | HIGH 8.8EPSS 48.2% | 27 January 2026 |
| CVE-2026-1470 | n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. | CRITICAL 9.9EPSS 19.0% | 27 January 2026 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | KEVHIGH 7.8EPSS 72.6% | 26 January 2026 |
| CVE-2026-1419 | A weakness has been identified in D-Link DCS700l 1.03.09. | LOW 2.0EPSS 15.7% | 26 January 2026 |
| CVE-2026-24423 | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.3EPSS 88.0% | 23 January 2026 |
| CVE-2022-25369 | An attacker can add a new administrator user without authentication. | CRITICAL 9.8EPSS 41.4% | 23 January 2026 |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEVCRITICAL 9.8EPSS 63.4% | 23 January 2026 |
| CVE-2026-0769 | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 38.6% | 23 January 2026 |
| CVE-2026-23760 | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.3EPSS 96.4% | 22 January 2026 |
| CVE-2026-21852 | Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. | MEDIUM 5.3EPSS 24.8% | 21 January 2026 |
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability | KEVCRITICAL 9.8EPSS 98.0% | 21 January 2026 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | KEVCRITICAL 10.0EPSS 42.0% | 20 January 2026 |
| CVE-2025-56005 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. | CRITICAL 9.8EPSS 17.5% | 20 January 2026 |
| CVE-2026-22844 | A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access. | CRITICAL 9.9EPSS 13.5% | 20 January 2026 |
| CVE-2026-1125 | A weakness has been identified in D-Link DIR-823X 250416. | MEDIUM 5.5EPSS 14.9% | 18 January 2026 |
| CVE-2026-23744 | Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. | CRITICAL 9.8EPSS 64.8% | 16 January 2026 |
| CVE-2025-60021 | Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. | CRITICAL 9.8EPSS 25.7% | 16 January 2026 |
| CVE-2026-23550 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1. | CRITICAL 9.8EPSS 21.7% | 14 January 2026 |
| CVE-2020-36911 | Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. | CRITICAL 9.3EPSS 12.1% | 13 January 2026 |
| CVE-2026-20963 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 32.6% | 13 January 2026 |
| CVE-2026-20947 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | HIGH 8.8EPSS 18.8% | 13 January 2026 |
| CVE-2026-20925 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | MEDIUM 6.5EPSS 18.2% | 13 January 2026 |
| CVE-2026-20872 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | MEDIUM 6.5EPSS 20.1% | 13 January 2026 |
| CVE-2025-64155 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through… | CRITICAL 9.8EPSS 45.4% | 13 January 2026 |
| CVE-2026-22755 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389,… | CRITICAL 9.3EPSS 20.6% | 13 January 2026 |
| CVE-2025-13447 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in… | MEDIUM 6.8EPSS 27.2% | 13 January 2026 |
| CVE-2025-13444 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in… | MEDIUM 6.8EPSS 27.2% | 13 January 2026 |
| CVE-2026-22812 | Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. | HIGH 8.8EPSS 16.8% | 12 January 2026 |
| CVE-2025-12420 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. | CRITICAL 9.3EPSS 49.1% | 12 January 2026 |
| CVE-2026-22200 | Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. | HIGH 8.7EPSS 73.9% | 12 January 2026 |
| CVE-2025-68472 | Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. | CRITICAL 9.1EPSS 20.3% | 12 January 2026 |
| CVE-2025-52694 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality,… | CRITICAL 9.8EPSS 40.4% | 12 January 2026 |
| CVE-2025-68493 | Missing XML Validation vulnerability in Apache Struts, Apache Struts. | HIGH 8.1EPSS 43.3% | 11 January 2026 |
| CVE-2025-61686 | In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix… | CRITICAL 9.1EPSS 17.6% | 10 January 2026 |
| CVE-2025-70161 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. | CRITICAL 9.8EPSS 27.1% | 9 January 2026 |
| CVE-2026-0732 | A vulnerability was found in D-Link DI-8200G 17.12.20A1. | LOW 2.1EPSS 11.7% | 9 January 2026 |
| CVE-2026-21876 | Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. | MEDIUM 5.3EPSS 14.2% | 8 January 2026 |
| CVE-2026-21858 | Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. | CRITICAL 10.0EPSS 78.4% | 8 January 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.