Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,287 results · page 118 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-59852 | HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of… | CRITICAL 9.1EPSS 0.09% | 6 May 2026 |
| CVE-2025-59851 | HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to… | CRITICAL 9.8EPSS 0.21% | 6 May 2026 |
| CVE-2026-43117 | In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid… | CRITICAL 9.1EPSS 0.40% | 6 May 2026 |
| CVE-2026-43114 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. | CRITICAL 9.4EPSS 0.37% | 6 May 2026 |
| CVE-2026-43083 | In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can… | CRITICAL 9.1EPSS 0.44% | 6 May 2026 |
| CVE-2026-40010 | Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. | CRITICAL 9.1EPSS 0.38% | 6 May 2026 |
| CVE-2026-28780 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. | CRITICAL 9.8EPSS 1.38% | 5 May 2026 |
| CVE-2026-40331 | This value is injected directly into a SQL FROM clause within feedGateway.cfc. | CRITICAL 9.3EPSS 0.32% | 5 May 2026 |
| CVE-2026-40330 | In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's handling of the sortDirection parameter. | CRITICAL 9.3EPSS 0.43% | 5 May 2026 |
| CVE-2026-40329 | In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of the sortBy parameter. | CRITICAL 9.3EPSS 0.30% | 5 May 2026 |
| CVE-2026-34458 | In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandboxie.ini configuration file. | CRITICAL 9.3EPSS 0.25% | 5 May 2026 |
| CVE-2026-34084 | In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as… | CRITICAL 9.2EPSS 0.71% | 5 May 2026 |
| CVE-2026-33324 | In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. | CRITICAL 9.4EPSS 0.60% | 5 May 2026 |
| CVE-2026-38428 | Kestra v1.3.3 and before is vulnerable to SQL Injection. | CRITICAL 9.8EPSS 0.37% | 5 May 2026 |
| CVE-2026-27960 | In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. | CRITICAL 9.8EPSS 1.99% | 5 May 2026 |
| CVE-2026-38431 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). | CRITICAL 9.8EPSS 0.39% | 5 May 2026 |
| CVE-2026-38429 | OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml. | CRITICAL 9.8EPSS 0.30% | 5 May 2026 |
| CVE-2026-7411 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. | CRITICAL 10.0EPSS 3.68% | 5 May 2026 |
| CVE-2026-43071 | In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address:… | CRITICAL 9.1EPSS 0.40% | 5 May 2026 |
| CVE-2026-43067 | In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit 4865c768b563 ("ext4: always allocate blocks only from groups inode can use") restricts what blocks… | CRITICAL 9.8EPSS 0.40% | 5 May 2026 |
| CVE-2026-34002 | This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. | CRITICAL 9.1EPSS 0.49% | 5 May 2026 |
| CVE-2026-34000 | This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. | CRITICAL 9.1EPSS 0.49% | 5 May 2026 |
| CVE-2026-36356 | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint. | EXPLOITCRITICAL 9.1EPSS 13.5% | 5 May 2026 |
| CVE-2026-34408 | The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known. | CRITICAL 9.1EPSS 0.26% | 5 May 2026 |
| CVE-2026-43566 | OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. | CRITICAL 9.1EPSS 0.42% | 5 May 2026 |
| CVE-2026-43534 | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. | CRITICAL 9.3EPSS 0.19% | 5 May 2026 |
| CVE-2023-54344 | Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. | CRITICAL 9.3EPSS 0.55% | 5 May 2026 |
| CVE-2023-54342 | Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. | CRITICAL 9.3EPSS 0.46% | 5 May 2026 |
| CVE-2026-40797 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.35% | 5 May 2026 |
| CVE-2026-5294 | The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. | CRITICAL 9.8EPSS 0.46% | 5 May 2026 |
| CVE-2025-13618 | The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. | CRITICAL 9.8EPSS 0.34% | 5 May 2026 |
| CVE-2026-5722 | The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. | CRITICAL 9.8EPSS 0.46% | 5 May 2026 |
| CVE-2026-42238 | Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. | CRITICAL 9.0EPSS 0.76% | 4 May 2026 |
| CVE-2026-42222 | In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. | CRITICAL 9.8EPSS 0.34% | 4 May 2026 |
| CVE-2026-42221 | From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. | CRITICAL 9.8EPSS 1.17% | 4 May 2026 |
| CVE-2026-41926 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request handlers that apply insufficient input validation. | CRITICAL 9.3EPSS 1.23% | 4 May 2026 |
| CVE-2026-41925 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious… | CRITICAL 9.3EPSS 3.39% | 4 May 2026 |
| CVE-2026-41924 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the… | CRITICAL 9.3EPSS 2.71% | 4 May 2026 |
| CVE-2026-41923 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the… | CRITICAL 9.3EPSS 2.61% | 4 May 2026 |
| CVE-2026-41922 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the… | CRITICAL 9.3EPSS 4.98% | 4 May 2026 |
| CVE-2026-42232 | Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution. | CRITICAL 9.4EPSS 0.48% | 4 May 2026 |
| CVE-2026-42231 | Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. | CRITICAL 9.4EPSS 0.85% | 4 May 2026 |
| CVE-2026-42796 | Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. | CRITICAL 9.2EPSS 2.75% | 4 May 2026 |
| CVE-2026-42087 | From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. | CRITICAL 9.6EPSS 0.32% | 4 May 2026 |
| CVE-2026-41571 | In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. | CRITICAL 9.4EPSS 0.30% | 4 May 2026 |
| CVE-2026-42812 | For a table already registered in a Polaris-managed catalog, changing only that property through an `ALTER TABLE`-style settings change (not a row-level `INSERT`, `SELECT`, `UPDATE`, or `DELETE`) bypasses the commit-time branch that is supposed to… | CRITICAL 9.4EPSS 0.36% | 4 May 2026 |
| CVE-2026-42811 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. | CRITICAL 9.4EPSS 0.43% | 4 May 2026 |
| CVE-2026-42810 | A control case using ordinary different names did not allow the same cross-table access. | CRITICAL 9.4EPSS 0.43% | 4 May 2026 |
| CVE-2026-42809 | Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker- directed because the attacker can choose a reachable target location. | CRITICAL 9.4EPSS 0.36% | 4 May 2026 |
| CVE-2026-42376 | D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. | CRITICAL 9.8EPSS 0.46% | 4 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.