Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,284 results · page 100 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-38061 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
| CVE-2026-38060 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
| CVE-2026-36537 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. | CRITICAL 9.8EPSS 0.51% | 15 June 2026 |
| CVE-2026-30121 | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. | CRITICAL 9.1EPSS 0.32% | 15 June 2026 |
| CVE-2026-30120 | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. | CRITICAL 9.8EPSS 0.81% | 15 June 2026 |
| CVE-2026-9862 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. | CRITICAL 9.8EPSS 0.99% | 15 June 2026 |
| CVE-2026-52704 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. | CRITICAL 10.0EPSS 0.30% | 15 June 2026 |
| CVE-2018-25436 | WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. | CRITICAL 9.3EPSS 0.66% | 15 June 2026 |
| CVE-2026-5482 | Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. | CRITICAL 9.3EPSS 0.45% | 15 June 2026 |
| CVE-2026-49757 | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. | CRITICAL 9.2EPSS 0.61% | 15 June 2026 |
| CVE-2026-8935 | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a… | CRITICAL 9.8EPSS 0.27% | 15 June 2026 |
| CVE-2026-11526 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. | CRITICAL 9.8EPSS 1.35% | 14 June 2026 |
| CVE-2026-12183 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. | CRITICAL 9.3EPSS 0.44% | 13 June 2026 |
| CVE-2026-11624 | In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. | CRITICAL 9.4EPSS 0.22% | 13 June 2026 |
| CVE-2026-53609 | In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator. | CRITICAL 9.1EPSS 0.24% | 12 June 2026 |
| CVE-2026-53519 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | CRITICAL 9.1EPSS 1.93% | 12 June 2026 |
| CVE-2026-46716 | From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. | CRITICAL 9.9EPSS 0.43% | 12 June 2026 |
| CVE-2026-41157 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. | CRITICAL 9.8EPSS 0.36% | 12 June 2026 |
| CVE-2026-44990 | Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. | CRITICAL 9.3EPSS 0.60% | 12 June 2026 |
| CVE-2026-53407 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | CRITICAL 9.8EPSS 0.23% | 12 June 2026 |
| CVE-2026-50101 | Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel. | CRITICAL 9.2EPSS 0.28% | 12 June 2026 |
| CVE-2026-28742 | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. | CRITICAL 9.2EPSS 0.33% | 12 June 2026 |
| CVE-2026-48558 | SimpleHelp Authentication Bypass Vulnerability | KEVCRITICAL 9.5EPSS 64.3% | 12 June 2026 |
| CVE-2026-50086 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. | CRITICAL 9.8EPSS 0.29% | 12 June 2026 |
| CVE-2026-50085 | The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. | CRITICAL 9.8EPSS 0.41% | 12 June 2026 |
| CVE-2026-50083 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). | CRITICAL 9.8EPSS 0.36% | 12 June 2026 |
| CVE-2026-47691 | An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). | CRITICAL 10.0EPSS 0.39% | 12 June 2026 |
| CVE-2026-45833 | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the… | CRITICAL 9.4EPSS 0.34% | 12 June 2026 |
| CVE-2026-6853 | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. | CRITICAL 9.8EPSS 0.35% | 12 June 2026 |
| CVE-2026-54133 | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. | CRITICAL 9.8EPSS 0.42% | 12 June 2026 |
| CVE-2026-53787 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or… | CRITICAL 9.3EPSS 5.64% | 12 June 2026 |
| CVE-2026-47210 | Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). | CRITICAL 9.8EPSS 1.80% | 12 June 2026 |
| CVE-2026-47208 | Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. | CRITICAL 10.0EPSS 0.76% | 12 June 2026 |
| CVE-2026-47140 | Both can be used from sandboxed code to reach host-side execution primitives. | CRITICAL 10.0EPSS 0.82% | 12 June 2026 |
| CVE-2026-47137 | However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. | CRITICAL 10.0EPSS 0.38% | 12 June 2026 |
| CVE-2026-47131 | Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained,… | CRITICAL 10.0EPSS 0.62% | 12 June 2026 |
| CVE-2026-45674 | Netty is a network application framework for development of protocol servers and clients. | CRITICAL 10.0EPSS 0.30% | 12 June 2026 |
| CVE-2026-10557 | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. | CRITICAL 9.3EPSS 0.35% | 12 June 2026 |
| CVE-2026-11849 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database. | CRITICAL 9.3EPSS 0.35% | 12 June 2026 |
| CVE-2026-50628 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. | CRITICAL 9.8EPSS 0.68% | 12 June 2026 |
| CVE-2026-50627 | This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. | CRITICAL 9.1EPSS 0.45% | 12 June 2026 |
| CVE-2026-49875 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. | CRITICAL 9.8EPSS 0.53% | 12 June 2026 |
| CVE-2026-11535 | An unauthorized access vulnerability exists in the PcSuite APP. | CRITICAL 9.4EPSS 0.15% | 12 June 2026 |
| CVE-2026-48611 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations. | CRITICAL 9.8EPSS 3.86% | 12 June 2026 |
| CVE-2026-47370 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances. | CRITICAL 9.9EPSS 0.83% | 12 June 2026 |
| CVE-2026-47369 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | CRITICAL 9.9EPSS 0.30% | 12 June 2026 |
| CVE-2026-47367 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 0.83% | 12 June 2026 |
| CVE-2026-47365 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. | CRITICAL 9.9EPSS 0.41% | 12 June 2026 |
| CVE-2026-45060 | Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. | CRITICAL 9.8EPSS 0.36% | 11 June 2026 |
| CVE-2026-42846 | Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. | CRITICAL 9.8EPSS 0.60% | 11 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.