Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,286 results · page 112 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-7304 | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. | CRITICAL 9.8EPSS 0.58% | 18 May 2026 |
| CVE-2026-7302 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when… | CRITICAL 9.1EPSS 0.39% | 18 May 2026 |
| CVE-2026-7301 | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. | CRITICAL 9.8EPSS 0.40% | 18 May 2026 |
| CVE-2026-4320 | Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling… | CRITICAL 9.3EPSS 0.25% | 18 May 2026 |
| CVE-2026-8721 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. | CRITICAL 9.8EPSS 0.45% | 17 May 2026 |
| CVE-2026-8507 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. | CRITICAL 9.8EPSS 0.65% | 17 May 2026 |
| CVE-2018-25335 | WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. | CRITICAL 9.3EPSS 0.52% | 17 May 2026 |
| CVE-2018-25332 | GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. | CRITICAL 9.3EPSS 0.59% | 17 May 2026 |
| CVE-2018-25320 | ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. | CRITICAL 9.3EPSS 0.58% | 17 May 2026 |
| CVE-2021-47952 | python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. | CRITICAL 9.3EPSS 0.70% | 16 May 2026 |
| CVE-2020-37239 | libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. | CRITICAL 9.3EPSS 0.46% | 16 May 2026 |
| CVE-2020-37228 | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. | CRITICAL 9.3EPSS 0.43% | 16 May 2026 |
| CVE-2026-44566 | This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. | CRITICAL 9.8EPSS 0.34% | 15 May 2026 |
| CVE-2026-44551 | The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user. | CRITICAL 9.1EPSS 1.46% | 15 May 2026 |
| CVE-2026-46364 | phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. | CRITICAL 9.3EPSS 1.71% | 15 May 2026 |
| CVE-2026-45010 | phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session binding or rate limiting. | CRITICAL 9.3EPSS 0.34% | 15 May 2026 |
| CVE-2021-47965 | WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. | CRITICAL 9.3EPSS 0.60% | 15 May 2026 |
| CVE-2026-45035 | The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or sandboxing. | CRITICAL 9.4EPSS 0.38% | 15 May 2026 |
| CVE-2026-44717 | Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. | CRITICAL 9.8EPSS 0.48% | 15 May 2026 |
| CVE-2026-44699 | In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JWT without knowing any secret or RSA private key. | CRITICAL 9.1EPSS 0.21% | 15 May 2026 |
| CVE-2026-42155 | By narrowing the LCG window (via server state leaks or general predictability) and leveraging the lack of API rate-limiting, an attacker can generate a localized pool of candidate MD5 hashes and execute a high-speed online brute-force attack to hijack… | CRITICAL 9.3EPSS 0.30% | 15 May 2026 |
| CVE-2026-41258 | The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default UberspectImpl in place, which allows unrestricted Java reflection through template expressions. | CRITICAL 9.1EPSS 0.32% | 15 May 2026 |
| CVE-2026-2031 | An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using… | CRITICAL 10.0EPSS 0.53% | 15 May 2026 |
| CVE-2026-7182 | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. | CRITICAL 9.2EPSS 0.40% | 15 May 2026 |
| CVE-2026-41553 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. | CRITICAL 10.0EPSS 0.65% | 15 May 2026 |
| CVE-2026-41552 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. | CRITICAL 9.2EPSS 0.50% | 15 May 2026 |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability | KEVCRITICAL 9.3EPSS 1.46% | 15 May 2026 |
| CVE-2026-5229 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. | CRITICAL 9.8EPSS 0.73% | 15 May 2026 |
| CVE-2026-0481 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability | CRITICAL 9.2EPSS 0.31% | 15 May 2026 |
| CVE-2026-44666 | Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. | CRITICAL 9.3EPSS 0.30% | 14 May 2026 |
| CVE-2026-44212 | Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. | CRITICAL 9.3EPSS 0.33% | 14 May 2026 |
| CVE-2026-8634 | Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote… | CRITICAL 9.3EPSS 0.74% | 14 May 2026 |
| CVE-2026-8580 | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.21% | 14 May 2026 |
| CVE-2026-8511 | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 14 May 2026 |
| CVE-2026-45375 | As a consequence, malicious HTML in either field is parsed and executed when a user opens the marketplace tab. | CRITICAL 9.0EPSS 0.32% | 14 May 2026 |
| CVE-2026-44670 | Because the main BrowserWindow runs nodeIntegration:true, contextIsolation:false, webSecurity:false (app/electron/main.js:407-411), HTML injection in the renderer becomes Node.js code execution. | CRITICAL 9.4EPSS 0.51% | 14 May 2026 |
| CVE-2026-44592 | The resulting session has PeerAuth::Open, i.e. it sees jobs from every organisation, and can immediately NarPush/NarUploaded arbitrary store paths into nar_storage and the cached_path table. | CRITICAL 9.4EPSS 0.16% | 14 May 2026 |
| CVE-2026-44588 | Because the renderer runs with nodeIntegration: true, contextIsolation: false, webSecurity: false (app/electron/main.js:407-411), require('child_process') is reachable from the injected handler, escalating to arbitrary code execution.This vulnerability… | CRITICAL 9.4EPSS 0.51% | 14 May 2026 |
| CVE-2026-44523 | This vulnerability is fixed in 0.19.4. | CRITICAL 10.0EPSS 0.12% | 14 May 2026 |
| CVE-2026-41315 | From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. | CRITICAL 9.3EPSS 1.03% | 14 May 2026 |
| CVE-2026-27886 | An unauthenticated attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` (or other admin-relation) field to perform a boolean-oracle attack against private fields on the joined `admin_users` table,… | CRITICAL 9.2EPSS 0.61% | 14 May 2026 |
| CVE-2026-22599 | In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. | CRITICAL 9.3EPSS 1.18% | 14 May 2026 |
| CVE-2026-46470 | When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | CRITICAL 9.1EPSS 0.21% | 14 May 2026 |
| CVE-2026-44542 | Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. | CRITICAL 9.1EPSS 0.52% | 14 May 2026 |
| CVE-2026-42555 | An authenticated user with the ADMIN role can achieve Remote Code Execution and credential exfiltration. | CRITICAL 9.1EPSS 0.58% | 14 May 2026 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | KEVCRITICAL 10.0EPSS 91.5% | 14 May 2026 |
| CVE-2026-42596 | Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. | CRITICAL 9.4EPSS 1.24% | 14 May 2026 |
| CVE-2026-42589 | A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags — including -if, which evaluates Perl expressions. | CRITICAL 9.8EPSS 3.01% | 14 May 2026 |
| CVE-2026-42281 | Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and… | CRITICAL 9.2EPSS 1.62% | 14 May 2026 |
| CVE-2026-44484 | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. | CRITICAL 9.3EPSS 0.39% | 14 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.