Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,284 results · page 103 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-45758 | On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. | CRITICAL 9.6EPSS 0.28% | 5 June 2026 |
| CVE-2026-11420 | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive… | CRITICAL 10.0EPSS 0.71% | 5 June 2026 |
| CVE-2026-11419 | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. | CRITICAL 9.4EPSS 0.55% | 5 June 2026 |
| CVE-2026-11414 | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. | CRITICAL 10.0EPSS 0.48% | 5 June 2026 |
| CVE-2026-46496 | A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-player>` component. | CRITICAL 9.3EPSS 0.23% | 5 June 2026 |
| CVE-2026-46399 | The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. | CRITICAL 9.4EPSS 0.29% | 5 June 2026 |
| CVE-2026-46396 | A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of `<iframe>` elements. | CRITICAL 9.3EPSS 0.23% | 5 June 2026 |
| CVE-2026-46395 | Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary… | CRITICAL 9.3EPSS 0.29% | 5 June 2026 |
| CVE-2026-46389 | An attacker who can reach the Keycloak token endpoint and knows a `client_id` using this authenticator can authenticate as that client with any `client_secret` value and obtain OAuth2 tokens scoped to the client's service account. | CRITICAL 9.8EPSS 0.34% | 5 June 2026 |
| CVE-2026-10580 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. | CRITICAL 9.8EPSS 2.95% | 5 June 2026 |
| CVE-2026-45750 | Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processes the path parameter and embeds it into a shell command executed over the active SSH session. | CRITICAL 9.0EPSS 0.29% | 5 June 2026 |
| CVE-2026-45748 | The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (`endpointIP`, `endpointUsername`, `password`) directly into a shell command without escaping,… | CRITICAL 9.8EPSS 1.73% | 5 June 2026 |
| CVE-2026-45746 | Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Broken Access Control vulnerability due to improper validation of the sessionId parameter. | CRITICAL 9.0EPSS 0.39% | 5 June 2026 |
| CVE-2026-45744 | Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in Termix is vulnerable to OS command injection. | CRITICAL 9.9EPSS 2.01% | 5 June 2026 |
| CVE-2026-36500 | An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. | CRITICAL 9.1EPSS 0.69% | 5 June 2026 |
| CVE-2025-71318 | A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and… | CRITICAL 9.3EPSS 0.53% | 5 June 2026 |
| CVE-2025-71317 | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. | CRITICAL 9.3EPSS 0.43% | 5 June 2026 |
| CVE-2026-9270 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. | CRITICAL 9.1EPSS 0.33% | 5 June 2026 |
| CVE-2026-11362 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. | CRITICAL 9.8EPSS 0.45% | 5 June 2026 |
| CVE-2026-10879 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. | CRITICAL 9.8EPSS 0.48% | 5 June 2026 |
| CVE-2026-6274 | Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. | CRITICAL 9.8EPSS 0.46% | 5 June 2026 |
| CVE-2026-49777 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. | CRITICAL 10.0EPSS 1.66% | 5 June 2026 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | KEVEXPLOIT ×2CRITICAL 10.0EPSS 78.1% | 5 June 2026 |
| CVE-2026-7763 | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or… | CRITICAL 9.8EPSS 0.54% | 5 June 2026 |
| CVE-2026-7762 | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or… | CRITICAL 9.8EPSS 0.57% | 5 June 2026 |
| CVE-2026-11293 | Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.20% | 5 June 2026 |
| CVE-2026-11282 | Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.24% | 5 June 2026 |
| CVE-2026-11250 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. | CRITICAL 9.6EPSS 0.24% | 5 June 2026 |
| CVE-2026-48567 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 1.03% | 4 June 2026 |
| CVE-2026-11213 | Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.19% | 4 June 2026 |
| CVE-2026-11207 | Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. | CRITICAL 9.6EPSS 0.22% | 4 June 2026 |
| CVE-2026-11198 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. | CRITICAL 9.6EPSS 0.22% | 4 June 2026 |
| CVE-2026-11167 | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11165 | Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11163 | Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11153 | Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | CRITICAL 9.1EPSS 0.26% | 4 June 2026 |
| CVE-2026-11152 | Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11146 | Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11131 | Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11120 | Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.27% | 4 June 2026 |
| CVE-2026-11119 | Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11114 | Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11113 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.27% | 4 June 2026 |
| CVE-2026-11112 | Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. | CRITICAL 9.6EPSS 0.22% | 4 June 2026 |
| CVE-2026-11100 | Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 4 June 2026 |
| CVE-2026-11095 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.28% | 4 June 2026 |
| CVE-2026-11094 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11088 | Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 4 June 2026 |
| CVE-2026-11082 | Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11070 | Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via malicious network traffic. | CRITICAL 9.6EPSS 0.22% | 4 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.