Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 13 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-89243 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. | CRITICAL 9.2EPSS 0.36% | 11 September 2026 |
| CVE-2026-86793 | SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution… | CRITICAL 9.8EPSS 0.43% | 11 September 2026 |
| CVE-2026-47839 | A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. | CRITICAL 9.2EPSS 0.30% | 11 September 2026 |
| CVE-2026-14563 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered… | CRITICAL 9.8EPSS 0.28% | 11 September 2026 |
| CVE-2026-14560 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and… | CRITICAL 10.0EPSS 0.44% | 11 September 2026 |
| CVE-2026-14559 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's… | CRITICAL 9.8EPSS 0.28% | 11 September 2026 |
| CVE-2026-8778 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and… | CRITICAL 9.8EPSS 0.62% | 11 September 2026 |
| CVE-2026-82107 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | CRITICAL 9.6EPSS 0.34% | 10 September 2026 |
| CVE-2026-81204 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. | CRITICAL 9.8EPSS 0.60% | 10 September 2026 |
| CVE-2026-80424 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. | CRITICAL 9.1EPSS 0.39% | 10 September 2026 |
| CVE-2026-79724 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | CRITICAL 9.8EPSS 0.47% | 10 September 2026 |
| CVE-2026-78573 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. | CRITICAL 9.8EPSS 0.39% | 10 September 2026 |
| CVE-2026-71640 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline | CRITICAL 9.1EPSS 0.45% | 10 September 2026 |
| CVE-2026-45764 | Crafted traffic may cause Suricata to crash, resulting in denial of service. | CRITICAL 9.1EPSS 0.43% | 10 September 2026 |
| CVE-2026-19646 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header. | CRITICAL 9.1EPSS 0.52% | 10 September 2026 |
| CVE-2026-89094 | Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled. | CRITICAL 9.9EPSS 0.50% | 10 September 2026 |
| CVE-2026-85025 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security… | CRITICAL 9.8EPSS 0.43% | 10 September 2026 |
| CVE-2026-75940 | A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. | CRITICAL 9.3EPSS 0.29% | 10 September 2026 |
| CVE-2026-89086 | In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key. | CRITICAL 9.1EPSS 0.20% | 10 September 2026 |
| CVE-2026-88062 | In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. | CRITICAL 9.5EPSS 0.94% | 10 September 2026 |
| CVE-2026-89043 | passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. | CRITICAL 9.1EPSS 0.28% | 10 September 2026 |
| CVE-2026-89042 | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. | CRITICAL 9.3EPSS 0.27% | 10 September 2026 |
| CVE-2026-68006 | An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file | CRITICAL 9.1EPSS 0.37% | 10 September 2026 |
| CVE-2026-88044 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. | CRITICAL 9.1EPSS 0.49% | 10 September 2026 |
| CVE-2026-68488 | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover. | CRITICAL 9.9EPSS 0.23% | 10 September 2026 |
| CVE-2026-68487 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | CRITICAL 9.9EPSS 0.41% | 10 September 2026 |
| CVE-2026-65639 | OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. | CRITICAL 9.5EPSS 1.61% | 10 September 2026 |
| CVE-2026-65638 | Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. | CRITICAL 9.2EPSS 3.20% | 10 September 2026 |
| CVE-2026-52098 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint | CRITICAL 9.8EPSS 0.78% | 10 September 2026 |
| CVE-2026-88899 | Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system. | CRITICAL 9.3EPSS 0.44% | 10 September 2026 |
| CVE-2026-88018 | Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same… | CRITICAL 9.8EPSS 0.50% | 10 September 2026 |
| CVE-2026-81467 | 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. | CRITICAL 9.8EPSS 3.28% | 10 September 2026 |
| CVE-2026-81046 | Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. | CRITICAL 9.4EPSS 0.37% | 10 September 2026 |
| CVE-2026-88007 | Traefik is an open source HTTP reverse proxy and load balancer. | CRITICAL 9.1EPSS 0.33% | 10 September 2026 |
| CVE-2026-81800 | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | CRITICAL 9.3EPSS 0.25% | 10 September 2026 |
| CVE-2026-88887 | When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the… | CRITICAL 9.2EPSS 0.30% | 10 September 2026 |
| CVE-2026-88882 | Registry credentials are attached to the request for the 'next' page, so a malicious or compromised NuGet registry can return a `Link` header pointing at an attacker-controlled server and cause Renovate to send the registry credentials to that server. | CRITICAL 9.2EPSS 0.30% | 10 September 2026 |
| CVE-2026-88881 | Because the pagination URL is not validated against the host originally contacted, a malicious or compromised GitHub server can return a `Link` header pointing to an attacker-controlled host and cause Renovate to disclose those credentials to it. | CRITICAL 9.2EPSS 0.30% | 10 September 2026 |
| CVE-2026-88880 | Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. | CRITICAL 9.2EPSS 0.36% | 10 September 2026 |
| CVE-2026-88877 | BasicAuth) but every annotation-derived middleware, including source-IP allowlisting. | CRITICAL 9.3EPSS 0.44% | 10 September 2026 |
| CVE-2026-88869 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. | CRITICAL 9.3EPSS 0.48% | 10 September 2026 |
| CVE-2026-88868 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. | CRITICAL 9.3EPSS 0.26% | 10 September 2026 |
| CVE-2026-88867 | WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName()… | CRITICAL 9.3EPSS 0.32% | 10 September 2026 |
| CVE-2026-88866 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. | CRITICAL 9.3EPSS 0.31% | 10 September 2026 |
| CVE-2026-88864 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. | CRITICAL 9.3EPSS 0.26% | 10 September 2026 |
| CVE-2026-88860 | Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions. | CRITICAL 9.3EPSS 0.16% | 10 September 2026 |
| CVE-2026-38626 | Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php. | CRITICAL 9.8EPSS 0.32% | 10 September 2026 |
| CVE-2026-9163 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. | CRITICAL 9.8EPSS 0.27% | 10 September 2026 |
| CVE-2026-78082 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting,… | CRITICAL 9.3EPSS 0.49% | 10 September 2026 |
| CVE-2026-88285 | GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands. | CRITICAL 9.4EPSS 0.27% | 10 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.