Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,287 results · page 120 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-42799 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. | CRITICAL 9.8EPSS 0.28% | 30 April 2026 |
| CVE-2026-22070 | ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. | CRITICAL 9.8EPSS 0.21% | 30 April 2026 |
| CVE-2026-7381 | Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. | CRITICAL 9.1EPSS 0.44% | 29 April 2026 |
| CVE-2018-25318 | Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. | CRITICAL 9.3EPSS 0.65% | 29 April 2026 |
| CVE-2018-25317 | Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. | CRITICAL 9.3EPSS 0.65% | 29 April 2026 |
| CVE-2018-25316 | Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. | CRITICAL 9.3EPSS 0.65% | 29 April 2026 |
| CVE-2026-30893 | From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the intended extraction directory on other cluster… | CRITICAL 9.9EPSS 0.40% | 29 April 2026 |
| CVE-2026-26015 | From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). | CRITICAL 10.0EPSS 1.17% | 29 April 2026 |
| CVE-2026-5166 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. | CRITICAL 9.6EPSS 0.33% | 29 April 2026 |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 98.5% | 29 April 2026 |
| CVE-2026-38992 | Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. | CRITICAL 9.8EPSS 0.43% | 29 April 2026 |
| CVE-2026-36841 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. | CRITICAL 9.8EPSS 1.13% | 29 April 2026 |
| CVE-2026-42523 | Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability… | CRITICAL 9.0EPSS 0.28% | 29 April 2026 |
| CVE-2026-3325 | SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. | CRITICAL 10.0EPSS 0.27% | 29 April 2026 |
| CVE-2026-7333 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.36% | 28 April 2026 |
| CVE-2026-41446 | Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical… | CRITICAL 9.2EPSS 0.43% | 28 April 2026 |
| CVE-2026-41386 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. | CRITICAL 9.1EPSS 0.33% | 28 April 2026 |
| CVE-2026-3893 | The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials. | CRITICAL 9.4EPSS 0.37% | 28 April 2026 |
| CVE-2026-24178 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. | CRITICAL 9.8EPSS 0.57% | 28 April 2026 |
| CVE-2026-41873 | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. | CRITICAL 9.8EPSS 0.44% | 28 April 2026 |
| CVE-2025-60889 | Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. | CRITICAL 9.8EPSS 0.48% | 28 April 2026 |
| CVE-2026-7321 | This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1. | CRITICAL 9.6EPSS 0.26% | 28 April 2026 |
| CVE-2026-27760 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. | CRITICAL 9.2EPSS 34.6% | 28 April 2026 |
| CVE-2026-5779 | An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. | CRITICAL 9.4EPSS 0.25% | 28 April 2026 |
| CVE-2026-32644 | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. | CRITICAL 9.2EPSS 0.22% | 28 April 2026 |
| CVE-2026-40976 | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. | CRITICAL 9.1EPSS 0.49% | 28 April 2026 |
| CVE-2026-40974 | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. | CRITICAL 9.8EPSS 0.18% | 28 April 2026 |
| CVE-2026-40971 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. | CRITICAL 9.1EPSS 0.16% | 27 April 2026 |
| CVE-2024-46636 | NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter | CRITICAL 9.4EPSS 0.33% | 27 April 2026 |
| CVE-2026-35903 | MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. | CRITICAL 9.8EPSS 0.49% | 27 April 2026 |
| CVE-2026-31255 | A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. | CRITICAL 9.8EPSS 1.12% | 27 April 2026 |
| CVE-2026-41462 | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. | CRITICAL 9.3EPSS 0.56% | 27 April 2026 |
| CVE-2026-30352 | A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter. | CRITICAL 9.8EPSS 0.52% | 27 April 2026 |
| CVE-2026-33453 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. | CRITICAL 10.0EPSS 6.16% | 27 April 2026 |
| CVE-2026-22337 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. | CRITICAL 9.8EPSS 0.32% | 27 April 2026 |
| CVE-2026-22336 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. | CRITICAL 9.3EPSS 0.28% | 27 April 2026 |
| CVE-2026-41409 | The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. | CRITICAL 9.8EPSS 0.43% | 27 April 2026 |
| CVE-2026-33454 | The Camel-Mail component is vulnerable to Camel message header injection. | CRITICAL 9.4EPSS 0.62% | 27 April 2026 |
| CVE-2026-41635 | Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. | CRITICAL 9.8EPSS 0.64% | 27 April 2026 |
| CVE-2026-40860 | JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class… | CRITICAL 9.8EPSS 1.23% | 27 April 2026 |
| CVE-2026-40453 | The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. | CRITICAL 9.9EPSS 1.56% | 27 April 2026 |
| CVE-2026-42363 | An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. | CRITICAL 9.3EPSS 0.19% | 27 April 2026 |
| CVE-2026-31685 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the… | CRITICAL 9.4EPSS 0.34% | 25 April 2026 |
| CVE-2026-31682 | In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part of… | CRITICAL 9.1EPSS 0.48% | 25 April 2026 |
| CVE-2026-41478 | Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. | CRITICAL 9.9EPSS 0.26% | 24 April 2026 |
| CVE-2026-41248 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream… | CRITICAL 9.1EPSS 0.32% | 24 April 2026 |
| CVE-2026-41428 | Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint by appending a public endpoint path as a query parameter. | CRITICAL 9.1EPSS 0.45% | 24 April 2026 |
| CVE-2026-41492 | Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. | CRITICAL 9.8EPSS 3.08% | 24 April 2026 |
| CVE-2026-41328 | Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. | CRITICAL 9.1EPSS 0.41% | 24 April 2026 |
| CVE-2026-41327 | Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. | CRITICAL 9.1EPSS 0.49% | 24 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.