Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 12 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-89533 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range svc_rdma_read_chunk_range() walks a Read chunk's segment list to build a sub-range starting at byte offset and spanning length bytes… | CRITICAL 9.8EPSS 0.51% | 11 September 2026 |
| CVE-2026-89532 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks When a parsed chunk list contains a chunk whose ch_segcount is zero, pcl_for_each_segment computes its inclusive upper bound as… | CRITICAL 9.1EPSS 0.51% | 11 September 2026 |
| CVE-2026-89530 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the pull-up buffer An RPC-over-RDMA client can request a reply, such as an NFS READ payload, without providing a Write list or a Reply chunk… | CRITICAL 9.8EPSS 0.46% | 11 September 2026 |
| CVE-2026-89526 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read chunk position field is supplied by the remote client and stored verbatim in the parsed chunk list.… | CRITICAL 9.8EPSS 0.63% | 11 September 2026 |
| CVE-2026-89495 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Patch series "ocfs2/dlm: bound peer-controlled lengths in the o2dlm". | CRITICAL 9.8EPSS 0.70% | 11 September 2026 |
| CVE-2026-89494 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation.… | CRITICAL 9.8EPSS 0.70% | 11 September 2026 |
| CVE-2026-89492 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-directory block before… | CRITICAL 9.8EPSS 0.60% | 11 September 2026 |
| CVE-2026-89485 | In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved… | CRITICAL 9.8EPSS 0.70% | 11 September 2026 |
| CVE-2026-89482 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone Commit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes processing") established that… | CRITICAL 9.8EPSS 0.70% | 11 September 2026 |
| CVE-2026-89479 | In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association is deleted sctp_endpoint_bh_rcv() looks the association up only when chunk->asoc is NULL, and caches the result in chunk->asoc and… | CRITICAL 9.8EPSS 0.51% | 11 September 2026 |
| CVE-2026-89478 | In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sctp_rcv() resolves the transport once per packet and leaves it in chunk->transport. | CRITICAL 9.8EPSS 0.52% | 11 September 2026 |
| CVE-2026-89448 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration… | CRITICAL 9.3EPSS 0.14% | 11 September 2026 |
| CVE-2026-81002 | In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. | CRITICAL 9.8EPSS 0.52% | 11 September 2026 |
| CVE-2026-80986 | In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device has max_recv_sge == 1 there is no shared v2 receive buffer, and smc_llc_save_add_link_rkeys() takes… | CRITICAL 9.8EPSS 0.60% | 11 September 2026 |
| CVE-2026-80981 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link;… | CRITICAL 9.8EPSS 0.59% | 11 September 2026 |
| CVE-2026-80980 | In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to… | CRITICAL 9.8EPSS 0.60% | 11 September 2026 |
| CVE-2026-80976 | In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the inner packet the skb network header. | CRITICAL 9.8EPSS 0.70% | 11 September 2026 |
| CVE-2026-80945 | In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while… | CRITICAL 9.1EPSS 0.47% | 11 September 2026 |
| CVE-2026-80926 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. | CRITICAL 9.8EPSS 0.43% | 11 September 2026 |
| CVE-2026-53952 | A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. | CRITICAL 9.8EPSS 0.33% | 11 September 2026 |
| CVE-2026-52630 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php | CRITICAL 9.8EPSS 0.47% | 11 September 2026 |
| CVE-2026-79396 | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote… | CRITICAL 9.8EPSS 0.39% | 11 September 2026 |
| CVE-2026-79395 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication… | CRITICAL 9.8EPSS 0.41% | 11 September 2026 |
| CVE-2026-62105 | Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. | CRITICAL 9.8EPSS 0.31% | 11 September 2026 |
| CVE-2026-62103 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | CRITICAL 9.8EPSS 0.31% | 11 September 2026 |
| CVE-2026-54072 | Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. | CRITICAL 9.3EPSS 0.27% | 11 September 2026 |
| CVE-2026-82617 | The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. | CRITICAL 10.0EPSS 0.44% | 11 September 2026 |
| CVE-2026-72710 | SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter… | CRITICAL 9.3EPSS 0.62% | 11 September 2026 |
| CVE-2026-72709 | SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side… | CRITICAL 9.3EPSS 0.36% | 11 September 2026 |
| CVE-2026-54047 | Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. | CRITICAL 9.2EPSS 0.23% | 11 September 2026 |
| CVE-2026-3869 | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC. | CRITICAL 9.2EPSS 0.54% | 11 September 2026 |
| CVE-2026-89010 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server… | CRITICAL 9.3EPSS 2.85% | 11 September 2026 |
| CVE-2026-87988 | An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. | CRITICAL 10.0EPSS 0.25% | 11 September 2026 |
| CVE-2026-87987 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. | CRITICAL 10.0EPSS 0.33% | 11 September 2026 |
| CVE-2026-87986 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. | CRITICAL 10.0EPSS 0.44% | 11 September 2026 |
| CVE-2026-87985 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. | CRITICAL 10.0EPSS 0.44% | 11 September 2026 |
| CVE-2026-87984 | An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. | CRITICAL 9.3EPSS 0.43% | 11 September 2026 |
| CVE-2026-87983 | An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. | CRITICAL 9.2EPSS 0.42% | 11 September 2026 |
| CVE-2026-38056 | A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. | CRITICAL 9.4EPSS 0.10% | 11 September 2026 |
| CVE-2026-89212 | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. | CRITICAL 9.2EPSS 0.33% | 11 September 2026 |
| CVE-2026-71644 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm… | CRITICAL 9.8EPSS 0.35% | 11 September 2026 |
| CVE-2026-84390 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | CRITICAL 9.8EPSS 0.52% | 11 September 2026 |
| CVE-2026-80462 | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | CRITICAL 10.0EPSS 0.30% | 11 September 2026 |
| CVE-2026-89259 | From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). | CRITICAL 9.3EPSS 0.41% | 11 September 2026 |
| CVE-2026-89258 | In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. | CRITICAL 9.3EPSS 0.32% | 11 September 2026 |
| CVE-2026-89256 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. | CRITICAL 9.3EPSS 0.32% | 11 September 2026 |
| CVE-2026-89255 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. | CRITICAL 9.3EPSS 0.35% | 11 September 2026 |
| CVE-2026-89254 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. | CRITICAL 9.3EPSS 0.28% | 11 September 2026 |
| CVE-2026-89253 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. | CRITICAL 9.3EPSS 0.35% | 11 September 2026 |
| CVE-2026-89249 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in… | CRITICAL 9.3EPSS 0.28% | 11 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.