Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,288 results · page 123 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-40933 | Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. | CRITICAL 9.9EPSS 12.0% | 21 April 2026 |
| CVE-2026-40911 | In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields. | CRITICAL 10.0EPSS 0.65% | 21 April 2026 |
| CVE-2026-40910 | From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. | CRITICAL 9.1EPSS 0.27% | 21 April 2026 |
| CVE-2026-34287 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.1EPSS 0.35% | 21 April 2026 |
| CVE-2026-34286 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.1EPSS 0.41% | 21 April 2026 |
| CVE-2026-34285 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.1EPSS 0.41% | 21 April 2026 |
| CVE-2026-34279 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). | CRITICAL 9.1EPSS 0.44% | 21 April 2026 |
| CVE-2026-34275 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). | CRITICAL 9.8EPSS 0.38% | 21 April 2026 |
| CVE-2026-33519 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. | CRITICAL 9.8EPSS 0.31% | 21 April 2026 |
| CVE-2026-40903 | Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. | CRITICAL 9.1EPSS 0.24% | 21 April 2026 |
| CVE-2026-40887 | Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. | CRITICAL 9.1EPSS 1.76% | 21 April 2026 |
| CVE-2026-40884 | Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. | CRITICAL 9.8EPSS 0.48% | 21 April 2026 |
| CVE-2026-40872 | By submitting an unauthenticated Autodiscover request with a crafted EMailAddress containing HTML/JS, the payload is stored in Redis and executed when an admin views the Autodiscover logs. | CRITICAL 9.3EPSS 0.28% | 21 April 2026 |
| CVE-2026-40372 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.1EPSS 11.2% | 21 April 2026 |
| CVE-2026-41193 | Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP. | CRITICAL 9.1EPSS 0.39% | 21 April 2026 |
| CVE-2026-5652 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. | CRITICAL 9.0EPSS 0.44% | 21 April 2026 |
| CVE-2026-40576 | A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. | CRITICAL 9.4EPSS 0.39% | 21 April 2026 |
| CVE-2026-40569 | Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at line 398). | CRITICAL 9.0EPSS 0.30% | 21 April 2026 |
| CVE-2026-40050 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. | CRITICAL 9.8EPSS 0.60% | 21 April 2026 |
| CVE-2026-38835 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. | CRITICAL 9.8EPSS 2.15% | 21 April 2026 |
| CVE-2026-21571 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. | CRITICAL 9.4EPSS 1.34% | 21 April 2026 |
| CVE-2019-25714 | Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with… | CRITICAL 9.3EPSS 0.65% | 21 April 2026 |
| CVE-2025-41029 | SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. | CRITICAL 9.3EPSS 0.24% | 21 April 2026 |
| CVE-2025-15638 | Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. | CRITICAL 10.0EPSS 0.57% | 21 April 2026 |
| CVE-2017-20230 | Storable versions before 3.05 for Perl has a stack overflow. | CRITICAL 10.0EPSS 0.64% | 21 April 2026 |
| CVE-2026-6771 | Mitigation bypass in the DOM: Security component. | CRITICAL 9.8EPSS 0.31% | 21 April 2026 |
| CVE-2026-6768 | Mitigation bypass in the Networking: Cookies component. | CRITICAL 9.8EPSS 0.29% | 21 April 2026 |
| CVE-2026-6760 | Mitigation bypass in the Networking: Cookies component. | CRITICAL 9.8EPSS 0.28% | 21 April 2026 |
| CVE-2026-6748 | This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | CRITICAL 9.8EPSS 0.40% | 21 April 2026 |
| CVE-2026-5965 | NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. | CRITICAL 9.3EPSS 1.64% | 21 April 2026 |
| CVE-2026-41329 | OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. | CRITICAL 9.0EPSS 0.30% | 21 April 2026 |
| CVE-2026-5450 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. | CRITICAL 9.8EPSS 0.50% | 20 April 2026 |
| CVE-2026-32613 | In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. | CRITICAL 9.9EPSS 0.55% | 20 April 2026 |
| CVE-2026-32604 | In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. | CRITICAL 9.9EPSS 0.61% | 20 April 2026 |
| CVE-2026-29646 | This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization. | CRITICAL 9.8EPSS 0.36% | 20 April 2026 |
| CVE-2026-6257 | Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess. | CRITICAL 9.2EPSS 0.63% | 20 April 2026 |
| CVE-2026-32311 | Flowsint allows a user to create investigations, which are used to manage sketches and analyses. | CRITICAL 9.3EPSS 0.51% | 20 April 2026 |
| CVE-2026-29649 | This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps or denial of service when executing cache-block management instructions in virtualized contexts (V=1). | CRITICAL 9.8EPSS 0.45% | 20 April 2026 |
| CVE-2026-39109 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). | CRITICAL 9.4EPSS 0.33% | 20 April 2026 |
| CVE-2026-30269 | Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. | CRITICAL 9.9EPSS 0.28% | 20 April 2026 |
| CVE-2026-39918 | Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. | CRITICAL 9.2EPSS 0.66% | 20 April 2026 |
| CVE-2026-24467 | OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. | CRITICAL 9.8EPSS 0.90% | 20 April 2026 |
| CVE-2026-5760 | SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment(). | CRITICAL 9.8EPSS 0.85% | 20 April 2026 |
| CVE-2026-33557 | A possible security vulnerability has been identified in Apache Kafka. | CRITICAL 9.1EPSS 0.68% | 20 April 2026 |
| CVE-2026-5964 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | CRITICAL 9.3EPSS 0.37% | 20 April 2026 |
| CVE-2026-5963 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | CRITICAL 9.3EPSS 0.37% | 20 April 2026 |
| CVE-2026-6644 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. | CRITICAL 9.4EPSS 1.45% | 20 April 2026 |
| CVE-2026-32956 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. | CRITICAL 9.3EPSS 0.52% | 20 April 2026 |
| CVE-2026-41242 | In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. | CRITICAL 9.4EPSS 0.77% | 18 April 2026 |
| CVE-2026-40494 | Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE decoder in `tga.c` has an asymmetric bounds check vulnerability. | CRITICAL 9.8EPSS 0.31% | 18 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.