Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,288 results · page 122 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-31178 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.58% | 23 April 2026 |
| CVE-2026-31177 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.60% | 23 April 2026 |
| CVE-2026-31175 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.58% | 23 April 2026 |
| CVE-2026-40472 | In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks. | CRITICAL 9.9EPSS 0.30% | 23 April 2026 |
| CVE-2026-40471 | hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. | CRITICAL 9.6EPSS 0.14% | 23 April 2026 |
| CVE-2026-40470 | A critical XSS vulnerability affected hackage-server and hackage.haskell.org. | CRITICAL 9.9EPSS 0.31% | 23 April 2026 |
| CVE-2026-23751 | Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a… | CRITICAL 9.3EPSS 0.88% | 23 April 2026 |
| CVE-2025-62373 | Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration. | CRITICAL 9.8EPSS 0.70% | 23 April 2026 |
| CVE-2025-50229 | Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. | CRITICAL 9.8EPSS 0.36% | 23 April 2026 |
| CVE-2026-41460 | SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. | CRITICAL 9.3EPSS 0.97% | 23 April 2026 |
| CVE-2026-39440 | Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1. | CRITICAL 9.9EPSS 0.36% | 23 April 2026 |
| CVE-2026-6887 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | CRITICAL 9.3EPSS 0.36% | 23 April 2026 |
| CVE-2026-6886 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user. | CRITICAL 9.3EPSS 0.45% | 23 April 2026 |
| CVE-2026-6885 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on… | CRITICAL 9.3EPSS 0.50% | 23 April 2026 |
| CVE-2026-3960 | A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. | CRITICAL 9.8EPSS 0.94% | 23 April 2026 |
| CVE-2026-41229 | Since this file is `require`d on every request via `Database::getDB()`, an attacker can inject arbitrary PHP code that executes as the web server user on every subsequent page load. | CRITICAL 9.1EPSS 0.48% | 23 April 2026 |
| CVE-2026-41228 | An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. | CRITICAL 9.9EPSS 0.52% | 23 April 2026 |
| CVE-2026-3844 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. | CRITICAL 9.8EPSS 27.7% | 23 April 2026 |
| CVE-2026-41679 | Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. | CRITICAL 10.0EPSS 18.9% | 23 April 2026 |
| CVE-2026-41197 | Foreign calls returning nested arrays of tuples or other composite types corrupt the Brillig VM heap. | CRITICAL 9.3EPSS 0.40% | 23 April 2026 |
| CVE-2026-41196 | Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. | CRITICAL 9.0EPSS 0.37% | 23 April 2026 |
| CVE-2026-5935 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | CRITICAL 9.8EPSS 0.34% | 23 April 2026 |
| CVE-2026-41179 | Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. | CRITICAL 9.2EPSS 8.58% | 23 April 2026 |
| CVE-2026-41176 | The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. | CRITICAL 9.2EPSS 32.7% | 23 April 2026 |
| CVE-2026-29198 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured. | CRITICAL 9.8EPSS 0.42% | 23 April 2026 |
| CVE-2026-41167 | An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails` and `POST /api/getLibrary`, enabling full read of any table in the database - including `app_config`, which stores the Jellystat admin credentials, the Jellyfin API key, and… | CRITICAL 9.1EPSS 0.52% | 22 April 2026 |
| CVE-2026-33656 | Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Attachment` entities. | CRITICAL 9.1EPSS 0.50% | 22 April 2026 |
| CVE-2026-33471 | Prior to version 1.3.0, if an attacker can get a `SkipBlockProof` verified where `MultiSignature.signers` contains out-of-range indices spaced by 65536, these indices inflate `len()` but collide onto the same in-range `u16` slot during aggregation. | CRITICAL 9.6EPSS 0.22% | 22 April 2026 |
| CVE-2026-41468 | When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM… | CRITICAL 9.3EPSS 0.39% | 22 April 2026 |
| CVE-2026-34415 | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. | CRITICAL 9.3EPSS 3.57% | 22 April 2026 |
| CVE-2026-26354 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer… | CRITICAL 9.8EPSS 0.50% | 22 April 2026 |
| CVE-2026-32885 | Downloads and extracts archives from remote sources without path validation. | CRITICAL 9.1EPSS 0.42% | 22 April 2026 |
| CVE-2018-25272 | ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. | CRITICAL 9.3EPSS 0.42% | 22 April 2026 |
| CVE-2018-25270 | ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. | CRITICAL 9.3EPSS 0.89% | 22 April 2026 |
| CVE-2026-6356 | A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information. | CRITICAL 9.6EPSS 0.29% | 22 April 2026 |
| CVE-2026-33608 | An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring… | CRITICAL 9.8EPSS 0.38% | 22 April 2026 |
| CVE-2026-33598 | A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache. | CRITICAL 9.1EPSS 1.07% | 22 April 2026 |
| CVE-2026-31501 | In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI descriptor. | CRITICAL 9.8EPSS 0.38% | 22 April 2026 |
| CVE-2026-31478 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add support for read compound"), response buffer management was… | CRITICAL 9.8EPSS 0.50% | 22 April 2026 |
| CVE-2026-31463 | In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Commit aa35dd5cbc06 ("iomap: fix invalid folio access after folio_end_read()") partially addressed invalid… | CRITICAL 9.8EPSS 0.38% | 22 April 2026 |
| CVE-2026-31448 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this… | CRITICAL 9.4EPSS 0.44% | 22 April 2026 |
| CVE-2026-31444 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequence: 1) opinfo is linked into ci->m_op_list (via… | CRITICAL 9.8EPSS 0.45% | 22 April 2026 |
| CVE-2026-31436 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal cursor of flist, but the code completes found instead. | CRITICAL 9.8EPSS 0.46% | 22 April 2026 |
| CVE-2026-6235 | The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. | CRITICAL 9.8EPSS 0.58% | 22 April 2026 |
| CVE-2026-4119 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. | CRITICAL 9.1EPSS 0.73% | 22 April 2026 |
| CVE-2026-6023 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. | CRITICAL 9.8EPSS 0.54% | 22 April 2026 |
| CVE-2026-41144 | Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. | CRITICAL 9.8EPSS 0.43% | 22 April 2026 |
| CVE-2026-41064 | WWBN AVideo is an open source video platform. | CRITICAL 9.3EPSS 0.34% | 22 April 2026 |
| CVE-2026-40575 | An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application. | CRITICAL 9.1EPSS 0.48% | 22 April 2026 |
| CVE-2026-40946 | This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. | CRITICAL 9.2EPSS 0.26% | 21 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.