Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,284 results · page 102 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-45602 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | CRITICAL 9.1EPSS 0.37% | 9 June 2026 |
| CVE-2026-44815 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.10% | 9 June 2026 |
| CVE-2026-42904 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | CRITICAL 9.6EPSS 0.44% | 9 June 2026 |
| CVE-2026-38615 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | CRITICAL 9.8EPSS 0.82% | 9 June 2026 |
| CVE-2026-34182 | Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message. | CRITICAL 9.1EPSS 0.61% | 9 June 2026 |
| CVE-2026-26142 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.91% | 9 June 2026 |
| CVE-2026-8025 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. | CRITICAL 9.8EPSS 0.27% | 9 June 2026 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 76.1% | 9 June 2026 |
| CVE-2026-10523 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access | CRITICAL 9.8EPSS 51.9% | 9 June 2026 |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 99.9% | 9 June 2026 |
| CVE-2026-7486 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. | CRITICAL 9.8EPSS 0.27% | 9 June 2026 |
| CVE-2026-46325 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. | CRITICAL 9.8EPSS 0.35% | 9 June 2026 |
| CVE-2026-46316 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the… | CRITICAL 9.3EPSS 0.44% | 9 June 2026 |
| CVE-2017-20251 | WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. | CRITICAL 9.3EPSS 0.56% | 9 June 2026 |
| CVE-2026-41031 | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. | CRITICAL 9.3EPSS 0.24% | 9 June 2026 |
| CVE-2026-10731 | SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. | CRITICAL 9.3EPSS 0.35% | 9 June 2026 |
| CVE-2025-10263 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to… | CRITICAL 9.1EPSS 0.57% | 9 June 2026 |
| CVE-2009-10007 | An attacker that obtains a session id cookie can use this to impersonate the victim. | CRITICAL 9.1EPSS 0.37% | 9 June 2026 |
| CVE-2026-9698 | Attackers that can influence the error text in an application can trigger a buffer overflow. | CRITICAL 9.8EPSS 0.46% | 9 June 2026 |
| CVE-2026-5067 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. | CRITICAL 9.8EPSS 0.64% | 9 June 2026 |
| CVE-2026-41855 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized… | CRITICAL 9.8EPSS 0.29% | 9 June 2026 |
| CVE-2026-44748 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. | CRITICAL 9.9EPSS 0.23% | 9 June 2026 |
| CVE-2026-40128 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. | CRITICAL 9.0EPSS 0.45% | 9 June 2026 |
| CVE-2026-27671 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to… | CRITICAL 9.8EPSS 0.44% | 9 June 2026 |
| CVE-2026-11697 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.20% | 9 June 2026 |
| CVE-2026-11671 | Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.24% | 9 June 2026 |
| CVE-2026-11659 | Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 9 June 2026 |
| CVE-2026-11654 | Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 9 June 2026 |
| CVE-2026-11651 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 9 June 2026 |
| CVE-2026-11638 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 9 June 2026 |
| CVE-2026-11634 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 9 June 2026 |
| CVE-2026-52778 | Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. | CRITICAL 9.8EPSS 0.56% | 8 June 2026 |
| CVE-2026-46289 | In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. | CRITICAL 9.8EPSS 0.46% | 8 June 2026 |
| CVE-2026-41448 | AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized… | CRITICAL 9.2EPSS 0.54% | 8 June 2026 |
| CVE-2026-25555 | OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. | CRITICAL 9.3EPSS 1.82% | 8 June 2026 |
| CVE-2026-46442 | Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. | CRITICAL 9.4EPSS 36.3% | 8 June 2026 |
| CVE-2026-46440 | Flowise is a drag & drop user interface to build a customized large language model flow. | CRITICAL 9.1EPSS 0.25% | 8 June 2026 |
| CVE-2026-44631 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. | CRITICAL 9.8EPSS 0.50% | 8 June 2026 |
| CVE-2026-42535 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. | CRITICAL 9.1EPSS 0.54% | 8 June 2026 |
| CVE-2026-29167 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. | CRITICAL 9.8EPSS 0.69% | 8 June 2026 |
| CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 83.8% | 8 June 2026 |
| CVE-2026-47430 | An attack abusing this weakness must be tailored to the specific plugins and callback IDs the host app uses. | CRITICAL 9.5EPSS 0.72% | 8 June 2026 |
| CVE-2026-11499 | A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. | CRITICAL 9.3EPSS 6.56% | 8 June 2026 |
| CVE-2024-58349 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. | CRITICAL 9.3EPSS 0.67% | 8 June 2026 |
| CVE-2024-58348 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. | CRITICAL 9.3EPSS 0.84% | 8 June 2026 |
| CVE-2023-54352 | WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. | CRITICAL 9.3EPSS 0.61% | 8 June 2026 |
| CVE-2026-11429 | Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files… | CRITICAL 10.0EPSS 1.15% | 5 June 2026 |
| CVE-2026-11423 | A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. | CRITICAL 9.4EPSS 0.32% | 5 June 2026 |
| CVE-2026-45779 | An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. | CRITICAL 9.3EPSS 0.48% | 5 June 2026 |
| CVE-2026-45777 | Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. | CRITICAL 9.3EPSS 0.39% | 5 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.