Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,286 results · page 114 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-42889 | Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. | CRITICAL 9.1EPSS 0.37% | 12 May 2026 |
| CVE-2026-8431 | An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax. | CRITICAL 9.4EPSS 0.37% | 12 May 2026 |
| CVE-2026-8430 | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. | CRITICAL 9.2EPSS 0.43% | 12 May 2026 |
| CVE-2026-34660 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.3EPSS 0.44% | 12 May 2026 |
| CVE-2026-34659 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.6EPSS 0.64% | 12 May 2026 |
| CVE-2026-44343 | Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. | CRITICAL 9.3EPSS 1.55% | 12 May 2026 |
| CVE-2026-44277 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via… | CRITICAL 9.8EPSS 0.55% | 12 May 2026 |
| CVE-2026-44196 | From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. | CRITICAL 9.1EPSS 0.30% | 12 May 2026 |
| CVE-2026-44183 | That entry is attacker-controlled — X-Forwarded-For is append-only, so the leftmost value is whatever the original HTTP client claimed. | CRITICAL 9.8EPSS 0.22% | 12 May 2026 |
| CVE-2026-42898 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | CRITICAL 9.9EPSS 1.19% | 12 May 2026 |
| CVE-2026-42833 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | CRITICAL 9.1EPSS 0.75% | 12 May 2026 |
| CVE-2026-42823 | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.60% | 12 May 2026 |
| CVE-2026-42300 | DevGuard provides vulnerability management for the full software supply chain. | CRITICAL 9.3EPSS 0.26% | 12 May 2026 |
| CVE-2026-42048 | Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). | CRITICAL 9.6EPSS 4.42% | 12 May 2026 |
| CVE-2026-41103 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.1EPSS 5.38% | 12 May 2026 |
| CVE-2026-41096 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.93% | 12 May 2026 |
| CVE-2026-41089 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 79.6% | 12 May 2026 |
| CVE-2026-40402 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | CRITICAL 9.3EPSS 0.33% | 12 May 2026 |
| CVE-2026-33821 | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.66% | 12 May 2026 |
| CVE-2026-33117 | In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. | CRITICAL 9.1EPSS 0.48% | 12 May 2026 |
| CVE-2026-31242 | An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE SQL statement. | CRITICAL 9.1EPSS 0.49% | 12 May 2026 |
| CVE-2026-31239 | The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. | CRITICAL 9.8EPSS 0.41% | 12 May 2026 |
| CVE-2026-31238 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. | CRITICAL 9.8EPSS 0.50% | 12 May 2026 |
| CVE-2026-31237 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. | CRITICAL 9.8EPSS 0.60% | 12 May 2026 |
| CVE-2026-31236 | The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. | CRITICAL 9.8EPSS 0.33% | 12 May 2026 |
| CVE-2026-31235 | The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. | CRITICAL 9.8EPSS 0.47% | 12 May 2026 |
| CVE-2026-31234 | Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. | CRITICAL 9.8EPSS 0.69% | 12 May 2026 |
| CVE-2026-31233 | Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. | CRITICAL 9.8EPSS 0.64% | 12 May 2026 |
| CVE-2026-31231 | Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. | CRITICAL 9.8EPSS 0.64% | 12 May 2026 |
| CVE-2026-31230 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). | CRITICAL 9.8EPSS 0.55% | 12 May 2026 |
| CVE-2026-31229 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. | CRITICAL 9.8EPSS 0.60% | 12 May 2026 |
| CVE-2026-29204 | Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account. | CRITICAL 9.1EPSS 0.32% | 12 May 2026 |
| CVE-2026-26083 | A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS… | CRITICAL 9.8EPSS 0.73% | 12 May 2026 |
| CVE-2026-43992 | Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit tool-call parameter. | CRITICAL 9.8EPSS 0.22% | 12 May 2026 |
| CVE-2026-20794 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. | CRITICAL 9.3EPSS 0.13% | 12 May 2026 |
| CVE-2025-65719 | An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page. | CRITICAL 9.8EPSS 0.58% | 12 May 2026 |
| CVE-2026-43515 | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. | CRITICAL 9.1EPSS 1.22% | 12 May 2026 |
| CVE-2026-43512 | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. | CRITICAL 9.8EPSS 1.33% | 12 May 2026 |
| CVE-2026-41293 | Improper Input Validation vulnerability in Apache Tomcat. | CRITICAL 9.8EPSS 1.68% | 12 May 2026 |
| CVE-2026-31228 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. | CRITICAL 9.8EPSS 0.61% | 12 May 2026 |
| CVE-2026-31226 | The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. | CRITICAL 9.8EPSS 1.16% | 12 May 2026 |
| CVE-2026-31220 | PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. | CRITICAL 9.8EPSS 0.63% | 12 May 2026 |
| CVE-2026-31217 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. | CRITICAL 9.8EPSS 0.43% | 12 May 2026 |
| CVE-2026-31216 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. | CRITICAL 9.1EPSS 0.40% | 12 May 2026 |
| CVE-2026-31215 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. | CRITICAL 9.1EPSS 0.41% | 12 May 2026 |
| CVE-2026-31214 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). | CRITICAL 9.8EPSS 0.49% | 12 May 2026 |
| CVE-2026-30805 | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. | CRITICAL 9.1EPSS 0.34% | 12 May 2026 |
| CVE-2026-8401 | This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. | CRITICAL 9.8EPSS 0.31% | 12 May 2026 |
| CVE-2026-8043 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks. | CRITICAL 9.6EPSS 0.87% | 12 May 2026 |
| CVE-2026-45091 | This vulnerability is fixed in 0.1.0-alpha.4. | CRITICAL 9.1EPSS 0.33% | 12 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.