Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,288 results · page 124 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-40493 | Every pixel write overshoots, causing a deterministic heap buffer overflow on every row. | CRITICAL 9.8EPSS 0.37% | 18 April 2026 |
| CVE-2026-40492 | This is a different vulnerability from the previously reported GHSA-3g38-x2pj-mv55 (CVE-2026-27168), which addressed `bytes_per_line` validation. | CRITICAL 9.8EPSS 0.33% | 18 April 2026 |
| CVE-2026-40487 | Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. | CRITICAL 9.0EPSS 0.22% | 18 April 2026 |
| CVE-2026-40572 | In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical kernel structures such as the IDT,… | CRITICAL 9.0EPSS 0.21% | 18 April 2026 |
| CVE-2026-40317 | In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitrary code in Ring 0 context,… | CRITICAL 9.3EPSS 0.22% | 18 April 2026 |
| CVE-2026-40582 | In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authentication checks. | CRITICAL 9.1EPSS 0.50% | 18 April 2026 |
| CVE-2026-40484 | An authenticated administrator can upload a crafted backup archive containing a PHP webshell inside the Images/ directory, which is then written to a publicly accessible path and executable via HTTP requests, resulting in remote code execution as the… | CRITICAL 9.1EPSS 0.87% | 18 April 2026 |
| CVE-2026-40324 | A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a `StackOverflowException` on payloads as small as 40 KB. | CRITICAL 9.1EPSS 0.90% | 18 April 2026 |
| CVE-2026-40478 | Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. | CRITICAL 9.0EPSS 1.10% | 17 April 2026 |
| CVE-2026-40477 | Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. | CRITICAL 9.0EPSS 0.85% | 17 April 2026 |
| CVE-2026-40351 | In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. | CRITICAL 9.8EPSS 0.63% | 17 April 2026 |
| CVE-2026-40258 | Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. | CRITICAL 9.1EPSS 0.40% | 17 April 2026 |
| CVE-2026-23500 | An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. | CRITICAL 9.4EPSS 0.92% | 17 April 2026 |
| CVE-2026-40342 | An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. | CRITICAL 9.9EPSS 0.69% | 17 April 2026 |
| CVE-2026-35546 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. | CRITICAL 9.8EPSS 0.59% | 17 April 2026 |
| CVE-2026-32105 | An unauthenticated attacker with man-in-the-middle (MITM) capabilities can exploit this missing check to modify encrypted traffic in transit without detection. | CRITICAL 9.3EPSS 0.17% | 17 April 2026 |
| CVE-2026-40525 | OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. | CRITICAL 9.1EPSS 0.57% | 17 April 2026 |
| CVE-2026-6284 | An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. | CRITICAL 9.3EPSS 0.45% | 17 April 2026 |
| CVE-2026-41153 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file | CRITICAL 9.8EPSS 0.26% | 17 April 2026 |
| CVE-2026-37749 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. | CRITICAL 9.8EPSS 0.68% | 17 April 2026 |
| CVE-2025-15625 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. | CRITICAL 9.5EPSS 0.42% | 17 April 2026 |
| CVE-2025-15624 | Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. | CRITICAL 9.3EPSS 0.38% | 17 April 2026 |
| CVE-2025-15623 | Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. | CRITICAL 9.3EPSS 0.26% | 17 April 2026 |
| CVE-2026-6443 | All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. | CRITICAL 9.8EPSS 0.50% | 17 April 2026 |
| CVE-2026-40322 | In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. | CRITICAL 9.0EPSS 0.31% | 16 April 2026 |
| CVE-2026-5426 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState… | CRITICAL 9.1EPSS 1.01% | 16 April 2026 |
| CVE-2026-37347 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | CRITICAL 9.1EPSS 0.32% | 16 April 2026 |
| CVE-2026-37345 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | CRITICAL 9.8EPSS 0.35% | 16 April 2026 |
| CVE-2026-37340 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | CRITICAL 9.8EPSS 0.26% | 16 April 2026 |
| CVE-2026-37339 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | CRITICAL 9.8EPSS 0.26% | 16 April 2026 |
| CVE-2026-37338 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. | CRITICAL 9.4EPSS 0.31% | 16 April 2026 |
| CVE-2026-33804 | @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. | CRITICAL 9.1EPSS 0.28% | 16 April 2026 |
| CVE-2026-6270 | This allows unauthenticated requests to reach routes defined in child plugin scopes, bypassing authentication and authorization checks. | CRITICAL 9.1EPSS 0.50% | 16 April 2026 |
| CVE-2026-31843 | The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. | CRITICAL 10.0EPSS 1.38% | 16 April 2026 |
| CVE-2024-2374 | This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. | CRITICAL 9.1EPSS 0.38% | 16 April 2026 |
| CVE-2026-3596 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. | CRITICAL 9.8EPSS 0.79% | 16 April 2026 |
| CVE-2026-22619 | Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. | CRITICAL 9.9EPSS 0.32% | 16 April 2026 |
| CVE-2026-6350 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | CRITICAL 9.3EPSS 0.77% | 16 April 2026 |
| CVE-2026-6349 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. | CRITICAL 9.3EPSS 2.03% | 16 April 2026 |
| CVE-2026-6348 | WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where… | CRITICAL 9.3EPSS 0.18% | 16 April 2026 |
| CVE-2026-40962 | FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c. | CRITICAL 9.8EPSS 0.13% | 16 April 2026 |
| CVE-2026-40504 | Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. | CRITICAL 9.3EPSS 0.64% | 16 April 2026 |
| CVE-2026-40959 | Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. | CRITICAL 9.3EPSS 0.18% | 16 April 2026 |
| CVE-2026-4880 | The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. | CRITICAL 9.8EPSS 0.50% | 16 April 2026 |
| CVE-2026-6388 | This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. | CRITICAL 9.1EPSS 0.36% | 15 April 2026 |
| CVE-2026-40173 | Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line including the… | CRITICAL 9.4EPSS 0.51% | 15 April 2026 |
| CVE-2026-6296 | Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 15 April 2026 |
| CVE-2025-41118 | If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API. | CRITICAL 9.1EPSS 0.41% | 15 April 2026 |
| CVE-2026-5189 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS… | CRITICAL 9.2EPSS 0.53% | 15 April 2026 |
| CVE-2026-6290 | Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. | CRITICAL 9.1EPSS 0.22% | 15 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.