Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,287 results · page 121 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-42044 | From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API… | CRITICAL 9.1EPSS 0.59% | 24 April 2026 |
| CVE-2026-42043 | Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. | CRITICAL 10.0EPSS 0.66% | 24 April 2026 |
| CVE-2026-6911 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants… | CRITICAL 9.3EPSS 0.25% | 24 April 2026 |
| CVE-2026-39920 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. | CRITICAL 9.3EPSS 0.54% | 24 April 2026 |
| CVE-2026-31669 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU… | CRITICAL 9.8EPSS 0.46% | 24 April 2026 |
| CVE-2026-31668 | In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 lwtunnel uses a single dst_cache per encap route, shared between seg6_input_core() and seg6_output_core(). | CRITICAL 9.8EPSS 0.44% | 24 April 2026 |
| CVE-2026-31659 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global TT response in 16-bit temporaries. | CRITICAL 9.8EPSS 0.40% | 24 April 2026 |
| CVE-2026-31657 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old gateway's last reference while readers still follow the… | CRITICAL 9.8EPSS 0.40% | 24 April 2026 |
| CVE-2026-31649 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len = skb_headlen(skb)… | CRITICAL 9.8EPSS 0.46% | 24 April 2026 |
| CVE-2026-31637 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets rxkad_decrypt_ticket() decrypts the RXKAD response ticket and then parses the buffer as plaintext without checking whether… | CRITICAL 9.8EPSS 0.51% | 24 April 2026 |
| CVE-2026-31636 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and then passes p + auth_len as the parser limit to… | CRITICAL 9.1EPSS 0.44% | 24 April 2026 |
| CVE-2026-31633 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response(), there's a potential integer overflow due to rounding up token_len before checking it, thereby allowing… | CRITICAL 9.8EPSS 0.47% | 24 April 2026 |
| CVE-2026-31609 | In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() smbd_send_batch_flush() already calls smbd_free_send_io(), so we should not call it again after… | CRITICAL 9.8EPSS 0.46% | 24 April 2026 |
| CVE-2026-31608 | In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() smb_direct_flush_send_list() already calls smb_direct_free_sendmsg(), so we should not call… | CRITICAL 9.8EPSS 0.46% | 24 April 2026 |
| CVE-2026-31607 | In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites… | CRITICAL 9.8EPSS 0.31% | 24 April 2026 |
| CVE-2026-31589 | In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call filemap_free_folio() if we have a reference to (or hold a lock on) the mapping. | CRITICAL 9.8EPSS 0.44% | 24 April 2026 |
| CVE-2026-31536 | In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in… | CRITICAL 9.8EPSS 0.44% | 24 April 2026 |
| CVE-2026-25660 | Authentication bypass occurs when the URL ends with Authentication with certain function calls. | CRITICAL 9.3EPSS 0.45% | 24 April 2026 |
| CVE-2026-21515 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.70% | 24 April 2026 |
| CVE-2026-1951 | Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability. | CRITICAL 9.8EPSS 0.61% | 24 April 2026 |
| CVE-2026-1950 | Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. | CRITICAL 9.8EPSS 0.31% | 24 April 2026 |
| CVE-2026-1949 | Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service. | CRITICAL 9.8EPSS 0.61% | 24 April 2026 |
| CVE-2026-41323 | The service URL has no validation — it can point anywhere, including attacker-controlled servers. | CRITICAL 9.1EPSS 0.56% | 24 April 2026 |
| CVE-2026-40630 | A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. | CRITICAL 9.3EPSS 0.73% | 24 April 2026 |
| CVE-2026-40620 | A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. | CRITICAL 9.3EPSS 0.55% | 24 April 2026 |
| CVE-2026-39462 | A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. | CRITICAL 9.3EPSS 0.39% | 24 April 2026 |
| CVE-2026-35503 | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. | CRITICAL 9.3EPSS 0.55% | 24 April 2026 |
| CVE-2026-27843 | A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. | CRITICAL 9.2EPSS 0.52% | 24 April 2026 |
| CVE-2026-25775 | A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. | CRITICAL 9.3EPSS 0.40% | 24 April 2026 |
| CVE-2026-41274 | Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. | CRITICAL 9.3EPSS 0.50% | 23 April 2026 |
| CVE-2026-35431 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | CRITICAL 10.0EPSS 0.51% | 23 April 2026 |
| CVE-2026-33819 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.84% | 23 April 2026 |
| CVE-2026-33102 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.3EPSS 0.40% | 23 April 2026 |
| CVE-2026-26210 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using… | CRITICAL 9.3EPSS 0.70% | 23 April 2026 |
| CVE-2026-26150 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.57% | 23 April 2026 |
| CVE-2026-24303 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.39% | 23 April 2026 |
| CVE-2026-6942 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). | CRITICAL 9.3EPSS 1.92% | 23 April 2026 |
| CVE-2026-41268 | Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. | CRITICAL 9.8EPSS 13.8% | 23 April 2026 |
| CVE-2026-41267 | Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. | CRITICAL 9.8EPSS 0.33% | 23 April 2026 |
| CVE-2026-41265 | Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using the Airtable Agent node may convince an LLM to respond with a malicious python script that executes attacker controlled commands on the… | CRITICAL 9.2EPSS 0.57% | 23 April 2026 |
| CVE-2026-41264 | An attacker can leverage this vulnerability to execute code in the context of the user running the server. | CRITICAL 9.2EPSS 1.44% | 23 April 2026 |
| CVE-2026-41137 | Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. | CRITICAL 9.4EPSS 1.45% | 23 April 2026 |
| CVE-2026-25874 | LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client… | CRITICAL 9.3EPSS 15.5% | 23 April 2026 |
| CVE-2026-6074 | Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. | CRITICAL 9.3EPSS 0.55% | 23 April 2026 |
| CVE-2026-6920 | Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.21% | 23 April 2026 |
| CVE-2026-6919 | Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.29% | 23 April 2026 |
| CVE-2026-31533 | In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of… | CRITICAL 9.8EPSS 0.39% | 23 April 2026 |
| CVE-2026-31181 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.58% | 23 April 2026 |
| CVE-2026-31178 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.58% | 23 April 2026 |
| CVE-2026-31177 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.60% | 23 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.