Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,291 results · page 130 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-28798 | Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal localhost services. | CRITICAL 10.0EPSS 0.39% | 3 April 2026 |
| CVE-2026-25726 | Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. | CRITICAL 9.8EPSS 0.38% | 3 April 2026 |
| CVE-2026-32186 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.70% | 3 April 2026 |
| CVE-2026-0545 | This vulnerability affects the latest version of the repository. | CRITICAL 9.8EPSS 4.39% | 3 April 2026 |
| CVE-2026-28373 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. | CRITICAL 9.6EPSS 0.42% | 3 April 2026 |
| CVE-2026-35216 | Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. | CRITICAL 9.0EPSS 10.7% | 3 April 2026 |
| CVE-2026-31818 | Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. | CRITICAL 9.9EPSS 0.38% | 3 April 2026 |
| CVE-2026-31402 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. | CRITICAL 9.8EPSS 0.95% | 3 April 2026 |
| CVE-2026-23455 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the… | CRITICAL 9.1EPSS 1.34% | 3 April 2026 |
| CVE-2026-23450 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path… | CRITICAL 9.8EPSS 0.56% | 3 April 2026 |
| CVE-2026-5463 | Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. | CRITICAL 9.3EPSS 2.11% | 3 April 2026 |
| CVE-2026-33107 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.70% | 3 April 2026 |
| CVE-2026-33105 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.72% | 3 April 2026 |
| CVE-2026-32213 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.91% | 3 April 2026 |
| CVE-2025-15620 | HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a… | CRITICAL 9.2EPSS 0.51% | 2 April 2026 |
| CVE-2026-35053 | Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. | CRITICAL 9.2EPSS 0.55% | 2 April 2026 |
| CVE-2026-34838 | Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. | CRITICAL 9.9EPSS 1.03% | 2 April 2026 |
| CVE-2024-14034 | Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. | CRITICAL 9.3EPSS 0.46% | 2 April 2026 |
| CVE-2026-34759 | Combined with a projectId leak from the public Status Page API, an unauthenticated attacker can purchase phone numbers on the victim's Twilio account and delete all existing alerting numbers. | CRITICAL 9.2EPSS 0.60% | 2 April 2026 |
| CVE-2026-34758 | Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. | CRITICAL 9.1EPSS 0.35% | 2 April 2026 |
| CVE-2026-34745 | An unauthenticated attacker can exploit the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. | CRITICAL 9.1EPSS 0.62% | 2 April 2026 |
| CVE-2026-34877 | Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. | CRITICAL 9.8EPSS 0.43% | 2 April 2026 |
| CVE-2026-33950 | Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. | CRITICAL 9.4EPSS 0.42% | 2 April 2026 |
| CVE-2026-25212 | Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system. | CRITICAL 9.9EPSS 0.29% | 2 April 2026 |
| CVE-2026-33746 | This means an attacker could forge or tamper with JWT token payloads — such as modifying the user_uuid claim — and the token would be accepted as valid, as long as the time-based claims were satisfied. | CRITICAL 9.8EPSS 0.30% | 2 April 2026 |
| CVE-2026-35002 | Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). | CRITICAL 9.3EPSS 0.84% | 2 April 2026 |
| CVE-2026-32871 | Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. | CRITICAL 10.0EPSS 0.91% | 2 April 2026 |
| CVE-2026-2699 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. | CRITICAL 9.8EPSS 59.5% | 2 April 2026 |
| CVE-2026-33615 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. | CRITICAL 9.1EPSS 0.41% | 2 April 2026 |
| CVE-2026-34571 | Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. | CRITICAL 9.0EPSS 0.39% | 1 April 2026 |
| CVE-2026-34569 | An attacker can inject a malicious JavaScript payload into the category title field, which is then stored server-side. | CRITICAL 9.0EPSS 0.32% | 1 April 2026 |
| CVE-2026-34568 | An attacker can inject a malicious JavaScript payload into blog post content, which is then stored server-side. | CRITICAL 9.0EPSS 0.32% | 1 April 2026 |
| CVE-2026-34567 | An attacker can inject a malicious JavaScript payload into the Categories content, which is then stored server-side. | CRITICAL 9.0EPSS 0.27% | 1 April 2026 |
| CVE-2026-34566 | Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side. | CRITICAL 9.0EPSS 0.27% | 1 April 2026 |
| CVE-2026-34565 | These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). | CRITICAL 9.0EPSS 0.27% | 1 April 2026 |
| CVE-2026-34564 | This stored payload is later rendered unsafely within administrative interfaces and public-facing navigation menus, leading to stored DOM-based cross-site scripting (XSS). | CRITICAL 9.0EPSS 0.31% | 1 April 2026 |
| CVE-2026-34563 | An attacker can inject a malicious JavaScript payload into the backup filename via the uploaded xss.sql, which uses SQL functionality to insert the XSS payload server-side. | CRITICAL 9.0EPSS 0.27% | 1 April 2026 |
| CVE-2026-34562 | Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. | CRITICAL 9.0EPSS 0.27% | 1 April 2026 |
| CVE-2026-34560 | Prior to version 0.31.0.0, the application renders user-controlled input unsafely within the logs interface. | CRITICAL 9.0EPSS 0.38% | 1 April 2026 |
| CVE-2026-34559 | An attacker can inject a malicious JavaScript payload into the tag name field, which is then stored server-side. | CRITICAL 9.0EPSS 0.32% | 1 April 2026 |
| CVE-2026-4101 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 under certain load conditions… | CRITICAL 9.8EPSS 0.36% | 1 April 2026 |
| CVE-2026-34873 | An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. | CRITICAL 9.1EPSS 0.24% | 1 April 2026 |
| CVE-2026-34529 | Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). | CRITICAL 9.0EPSS 0.32% | 1 April 2026 |
| CVE-2026-34528 | The Execute permission and Commands list from the default user template are not stripped. | CRITICAL 9.8EPSS 0.65% | 1 April 2026 |
| CVE-2026-34872 | There is a lack of contributory behavior in FFDH due to improper input validation. | CRITICAL 9.1EPSS 0.20% | 1 April 2026 |
| CVE-2026-34456 | From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. | CRITICAL 9.8EPSS 0.46% | 1 April 2026 |
| CVE-2026-34875 | A buffer overflow can occur in public key export for FFDH keys. | CRITICAL 9.8EPSS 0.37% | 1 April 2026 |
| CVE-2026-34751 | Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. | CRITICAL 9.1EPSS 0.31% | 1 April 2026 |
| CVE-2026-34236 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. | CRITICAL 9.8EPSS 0.22% | 1 April 2026 |
| CVE-2026-34159 | Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. | CRITICAL 9.8EPSS 1.13% | 1 April 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.