Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,288 results · page 125 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-30993 | Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. | CRITICAL 9.8EPSS 0.52% | 15 April 2026 |
| CVE-2026-20186 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | CRITICAL 9.9EPSS 5.60% | 15 April 2026 |
| CVE-2026-20184 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. | CRITICAL 9.8EPSS 0.52% | 15 April 2026 |
| CVE-2026-20180 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | CRITICAL 9.9EPSS 6.02% | 15 April 2026 |
| CVE-2026-20147 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | CRITICAL 9.9EPSS 10.4% | 15 April 2026 |
| CVE-2025-15610 | The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed in environments where the remoting ports are accessible. | CRITICAL 9.3EPSS 0.31% | 15 April 2026 |
| CVE-2026-5387 | The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of… | CRITICAL 9.3EPSS 0.39% | 15 April 2026 |
| CVE-2026-30625 | Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. | CRITICAL 9.8EPSS 0.97% | 15 April 2026 |
| CVE-2026-33805 | This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. | CRITICAL 9.0EPSS 0.44% | 15 April 2026 |
| CVE-2026-33808 | This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via semicolon delimiters when useSemicolonDelimiter is enabled. | CRITICAL 9.1EPSS 0.48% | 15 April 2026 |
| CVE-2026-33807 | This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined within affected child plugin scopes. | CRITICAL 9.1EPSS 0.43% | 15 April 2026 |
| CVE-2025-14813 | : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. | CRITICAL 9.3EPSS 0.32% | 15 April 2026 |
| CVE-2026-3461 | The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. | CRITICAL 9.8EPSS 0.47% | 15 April 2026 |
| CVE-2026-39842 | OpenRemote is an open-source IoT platform. | CRITICAL 9.9EPSS 0.92% | 15 April 2026 |
| CVE-2026-1555 | The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. | CRITICAL 9.8EPSS 0.98% | 15 April 2026 |
| CVE-2026-39399 | A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. | CRITICAL 9.6EPSS 0.53% | 14 April 2026 |
| CVE-2026-35589 | Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. | CRITICAL 9.3EPSS 0.16% | 14 April 2026 |
| CVE-2026-35033 | Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. | CRITICAL 9.3EPSS 0.32% | 14 April 2026 |
| CVE-2026-34457 | Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or --gcp-healthchecks is… | CRITICAL 9.1EPSS 0.47% | 14 April 2026 |
| CVE-2026-27304 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.3EPSS 3.63% | 14 April 2026 |
| CVE-2026-5752 | Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal. | CRITICAL 9.3EPSS 0.21% | 14 April 2026 |
| CVE-2026-34615 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.3EPSS 0.63% | 14 April 2026 |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | KEVCRITICAL 9.8EPSS 72.7% | 14 April 2026 |
| CVE-2026-27303 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.6EPSS 0.61% | 14 April 2026 |
| CVE-2026-27246 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. | CRITICAL 9.3EPSS 0.30% | 14 April 2026 |
| CVE-2026-27245 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | CRITICAL 9.3EPSS 0.30% | 14 April 2026 |
| CVE-2026-27243 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. | CRITICAL 9.3EPSS 0.30% | 14 April 2026 |
| CVE-2026-26149 | Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | CRITICAL 9.0EPSS 0.56% | 14 April 2026 |
| CVE-2025-70023 | An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. | CRITICAL 9.8EPSS 0.45% | 14 April 2026 |
| CVE-2026-39813 | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. | CRITICAL 9.8EPSS 22.2% | 14 April 2026 |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 92.8% | 14 April 2026 |
| CVE-2026-38526 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. | EXPLOITCRITICAL 9.9EPSS 3.82% | 14 April 2026 |
| CVE-2025-65135 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter. | CRITICAL 9.8EPSS 0.29% | 14 April 2026 |
| CVE-2025-65133 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. | CRITICAL 9.8EPSS 0.53% | 14 April 2026 |
| CVE-2025-63939 | Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter. | CRITICAL 9.8EPSS 0.27% | 14 April 2026 |
| CVE-2025-61260 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. | CRITICAL 9.8EPSS 6.58% | 14 April 2026 |
| CVE-2026-31049 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field | CRITICAL 9.8EPSS 0.66% | 14 April 2026 |
| CVE-2025-8095 | It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. | CRITICAL 9.1EPSS 0.22% | 14 April 2026 |
| CVE-2026-2449 | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege… | CRITICAL 9.0EPSS 0.33% | 14 April 2026 |
| CVE-2026-2332 | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html *… | CRITICAL 9.1EPSS 1.31% | 14 April 2026 |
| CVE-2026-31908 | Header injection vulnerability in Apache APISIX. | CRITICAL 9.1EPSS 0.52% | 14 April 2026 |
| CVE-2026-40313 | In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. | CRITICAL 9.1EPSS 0.30% | 14 April 2026 |
| CVE-2026-40289 | In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws… | CRITICAL 9.1EPSS 0.36% | 14 April 2026 |
| CVE-2026-40288 | In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. | CRITICAL 9.8EPSS 0.61% | 14 April 2026 |
| CVE-2026-6264 | A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. | CRITICAL 9.8EPSS 0.74% | 14 April 2026 |
| CVE-2026-4365 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. | CRITICAL 9.1EPSS 0.87% | 14 April 2026 |
| CVE-2026-27681 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. | CRITICAL 9.9EPSS 0.50% | 14 April 2026 |
| CVE-2026-22564 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system. | CRITICAL 9.8EPSS 0.42% | 13 April 2026 |
| CVE-2026-22563 | A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. | CRITICAL 9.8EPSS 1.05% | 13 April 2026 |
| CVE-2026-22562 | A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). | CRITICAL 9.8EPSS 0.77% | 13 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.