Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,284 results · page 101 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-49060 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. | CRITICAL 9.8EPSS 0.51% | 11 June 2026 |
| CVE-2026-42647 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. | CRITICAL 9.3EPSS 1.32% | 11 June 2026 |
| CVE-2026-39494 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.39% | 11 June 2026 |
| CVE-2026-12027 | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.22% | 11 June 2026 |
| CVE-2026-41005 | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser… | CRITICAL 9.0EPSS 0.13% | 11 June 2026 |
| CVE-2026-49973 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin… | CRITICAL 9.2EPSS 0.54% | 11 June 2026 |
| CVE-2026-47174 | If an attacker can make a pull request build satisfy the deploy workflow’s main branch condition, the deploy job checks out the triggering workflow commit, builds it into a Docker image, pushes it as latest, and triggers Dokploy deployment. | CRITICAL 9.5EPSS 0.31% | 11 June 2026 |
| CVE-2026-47172 | If an attacker can open a pull request from a branch named main, the deploy workflow condition can treat the PR build as deployable and build the attacker-controlled commit in a privileged deployment context. | CRITICAL 9.5EPSS 0.32% | 11 June 2026 |
| CVE-2026-45177 | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. | CRITICAL 9.1EPSS 0.50% | 11 June 2026 |
| CVE-2026-49261 | Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. | CRITICAL 9.8EPSS 1.58% | 11 June 2026 |
| CVE-2026-9648 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. | CRITICAL 9.1EPSS 0.22% | 11 June 2026 |
| CVE-2026-11839 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. | CRITICAL 9.9EPSS 0.34% | 11 June 2026 |
| CVE-2026-38581 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). | CRITICAL 9.8EPSS 0.33% | 11 June 2026 |
| CVE-2026-7852 | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. | CRITICAL 9.8EPSS 0.36% | 11 June 2026 |
| CVE-2026-11561 | Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. | CRITICAL 9.8EPSS 0.45% | 11 June 2026 |
| CVE-2026-4764 | A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously… | CRITICAL 9.4EPSS 0.21% | 11 June 2026 |
| CVE-2026-41699 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. | CRITICAL 9.8EPSS 0.43% | 11 June 2026 |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 95.5% | 11 June 2026 |
| CVE-2026-46703 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. | CRITICAL 9.6EPSS 0.48% | 10 June 2026 |
| CVE-2026-46695 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. | CRITICAL 10.0EPSS 0.29% | 10 June 2026 |
| CVE-2026-50638 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. | CRITICAL 9.1EPSS 0.34% | 10 June 2026 |
| CVE-2026-50566 | Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability containers in the Fission function or builder namespace, scheduled under the executor's high-privilege… | CRITICAL 9.9EPSS 0.29% | 10 June 2026 |
| CVE-2026-50564 | Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods. | CRITICAL 9.9EPSS 0.27% | 10 June 2026 |
| CVE-2026-50563 | Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image. | CRITICAL 9.9EPSS 0.27% | 10 June 2026 |
| CVE-2026-50545 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. | CRITICAL 9.9EPSS 0.30% | 10 June 2026 |
| CVE-2026-46614 | The route was mounted on the same listener as user-defined HTTPTriggers (svc/router, port 8888), so any caller who could reach the router could invoke any function by guessing its metadata.name (and namespace), bypassing the host / path / method /… | CRITICAL 9.8EPSS 0.35% | 10 June 2026 |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | KEVCRITICAL 9.8EPSS 96.9% | 10 June 2026 |
| CVE-2026-53476 | An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. | CRITICAL 9.6EPSS 0.29% | 10 June 2026 |
| CVE-2026-45558 | Because Roxy-WI then pushes the generated config to the load balancer and runs systemctl reload haproxy, an authenticated user with role ≤ 3 (user) can inject arbitrary HAProxy directives into the config that runs on every load balancer their group… | CRITICAL 9.9EPSS 0.44% | 10 June 2026 |
| CVE-2026-45556 | The validation chain (_replace_config_path_to_correct → check_is_conf) only requires the path to contain a hard-coded service substring (nginx/haproxy/apache2/httpd/keepalived) and the substring conf or cfg, and to not contain ... | CRITICAL 9.9EPSS 0.37% | 10 June 2026 |
| CVE-2026-45552 | Because the missing decorators omit both role and group checks, any logged-in user — including the default guest role 4 — can install/reconfigure exporters, WAF, and GeoIP databases on every server in the Roxy-WI database, regardless of tenant ownership. | CRITICAL 9.9EPSS 0.27% | 10 June 2026 |
| CVE-2026-45550 | The downstream SQL update functions update_smon, update_smonHttp, update_smonTcp, update_smonPing, update_smonDns (app/modules/db/smon.py:515-562) all execute WHERE smon_id = ? with no user_group filter. | CRITICAL 9.1EPSS 0.20% | 10 June 2026 |
| CVE-2025-6254 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. | CRITICAL 9.8EPSS 0.49% | 10 June 2026 |
| CVE-2026-9067 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type,… | CRITICAL 9.1EPSS 0.57% | 10 June 2026 |
| CVE-2025-66276 | We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later | CRITICAL 9.2EPSS 0.29% | 10 June 2026 |
| CVE-2026-44963 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | CRITICAL 9.4EPSS 2.35% | 9 June 2026 |
| CVE-2026-48303 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 0.55% | 9 June 2026 |
| CVE-2026-47938 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. | CRITICAL 10.0EPSS 0.45% | 9 June 2026 |
| CVE-2026-47928 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.6EPSS 2.32% | 9 June 2026 |
| CVE-2026-36727 | An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. | CRITICAL 9.1EPSS 0.36% | 9 June 2026 |
| CVE-2026-36721 | A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. | CRITICAL 9.8EPSS 0.27% | 9 June 2026 |
| CVE-2026-30141 | A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file. | CRITICAL 9.8EPSS 0.57% | 9 June 2026 |
| CVE-2026-10045 | Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. | CRITICAL 9.8EPSS 0.21% | 9 June 2026 |
| CVE-2026-34691 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. | CRITICAL 9.3EPSS 0.36% | 9 June 2026 |
| CVE-2026-49841 | The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs. | CRITICAL 9.8EPSS 0.39% | 9 June 2026 |
| CVE-2026-49840 | A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer. | CRITICAL 9.1EPSS 0.31% | 9 June 2026 |
| CVE-2026-47643 | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.75% | 9 June 2026 |
| CVE-2026-47291 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 22.8% | 9 June 2026 |
| CVE-2026-47281 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.76% | 9 June 2026 |
| CVE-2026-45657 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 15.5% | 9 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.