Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,291 results · page 133 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-33867 | In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. | CRITICAL 9.1EPSS 0.15% | 27 March 2026 |
| CVE-2026-28369 | This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. | CRITICAL 9.1EPSS 0.68% | 27 March 2026 |
| CVE-2026-28368 | This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. | CRITICAL 9.1EPSS 0.70% | 27 March 2026 |
| CVE-2026-28367 | A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. | CRITICAL 9.1EPSS 0.71% | 27 March 2026 |
| CVE-2026-30533 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | CRITICAL 9.8EPSS 0.39% | 27 March 2026 |
| CVE-2026-30532 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | CRITICAL 9.8EPSS 0.33% | 27 March 2026 |
| CVE-2026-30530 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). | CRITICAL 9.8EPSS 0.48% | 27 March 2026 |
| CVE-2026-30302 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. | CRITICAL 10.0EPSS 1.99% | 27 March 2026 |
| CVE-2026-33758 | Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a failed authentication. | CRITICAL 9.4EPSS 0.29% | 27 March 2026 |
| CVE-2026-30304 | In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. | CRITICAL 9.6EPSS 0.43% | 27 March 2026 |
| CVE-2026-30303 | The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. | CRITICAL 9.8EPSS 1.38% | 27 March 2026 |
| CVE-2026-27876 | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). | CRITICAL 9.1EPSS 1.93% | 27 March 2026 |
| CVE-2026-1496 | Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. | CRITICAL 9.3EPSS 0.48% | 27 March 2026 |
| CVE-2026-22738 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. | CRITICAL 9.8EPSS 1.09% | 27 March 2026 |
| CVE-2026-33747 | Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. | CRITICAL 9.8EPSS 0.50% | 27 March 2026 |
| CVE-2026-33728 | In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. | CRITICAL 9.3EPSS 0.70% | 27 March 2026 |
| CVE-2026-33718 | Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method at `openhands/runtime/utils/git_handler.py:134`. | CRITICAL 9.9EPSS 1.93% | 27 March 2026 |
| CVE-2026-33701 | In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. | CRITICAL 9.3EPSS 0.92% | 27 March 2026 |
| CVE-2026-33945 | Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. | CRITICAL 9.6EPSS 0.45% | 27 March 2026 |
| CVE-2026-34352 | In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions. | CRITICAL 9.8EPSS 0.25% | 26 March 2026 |
| CVE-2026-33897 | Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. | CRITICAL 9.9EPSS 0.48% | 26 March 2026 |
| CVE-2026-33640 | Outline is a service that allows for collaborative documentation. | CRITICAL 9.1EPSS 0.47% | 26 March 2026 |
| CVE-2026-30458 | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. | CRITICAL 9.1EPSS 0.36% | 26 March 2026 |
| CVE-2026-30457 | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | CRITICAL 9.8EPSS 0.63% | 26 March 2026 |
| CVE-2026-33494 | Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. | CRITICAL 10.0EPSS 0.52% | 26 March 2026 |
| CVE-2026-33396 | Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. | CRITICAL 9.9EPSS 0.83% | 26 March 2026 |
| CVE-2025-55261 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data. | CRITICAL 9.8EPSS 0.32% | 26 March 2026 |
| CVE-2025-55270 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc. | CRITICAL 9.8EPSS 1.00% | 26 March 2026 |
| CVE-2025-55269 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. | CRITICAL 9.8EPSS 0.24% | 26 March 2026 |
| CVE-2025-55267 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | CRITICAL 9.8EPSS 0.29% | 26 March 2026 |
| CVE-2026-4809 | plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. | CRITICAL 9.3EPSS 0.87% | 26 March 2026 |
| CVE-2014-125112 | Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. | CRITICAL 9.8EPSS 0.83% | 26 March 2026 |
| CVE-2026-33526 | Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. | CRITICAL 9.2EPSS 8.94% | 26 March 2026 |
| CVE-2026-30975 | Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that… | CRITICAL 9.8EPSS 0.47% | 25 March 2026 |
| CVE-2025-14917 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. | CRITICAL 9.8EPSS 0.36% | 25 March 2026 |
| CVE-2025-70888 | An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component | CRITICAL 9.8EPSS 0.48% | 25 March 2026 |
| CVE-2026-33696 | Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. | CRITICAL 9.4EPSS 0.79% | 25 March 2026 |
| CVE-2026-33660 | Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n host and achieve remote code execution. | CRITICAL 9.4EPSS 0.95% | 25 March 2026 |
| CVE-2026-32573 | Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.7. | CRITICAL 9.1EPSS 0.30% | 25 March 2026 |
| CVE-2026-32539 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: from n/a through <= 3.7.23. | CRITICAL 9.3EPSS 0.25% | 25 March 2026 |
| CVE-2026-32536 | Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a through <= 2.08. | CRITICAL 9.9EPSS 0.26% | 25 March 2026 |
| CVE-2026-32525 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | CRITICAL 9.9EPSS 0.29% | 25 March 2026 |
| CVE-2026-32524 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9. | CRITICAL 9.1EPSS 0.33% | 25 March 2026 |
| CVE-2026-32523 | Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2. | CRITICAL 9.9EPSS 0.32% | 25 March 2026 |
| CVE-2026-32520 | Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4. | CRITICAL 9.8EPSS 0.32% | 25 March 2026 |
| CVE-2026-32519 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2. | CRITICAL 9.0EPSS 0.34% | 25 March 2026 |
| CVE-2026-32512 | Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-32502 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-32499 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-32482 | Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24. | CRITICAL 9.9EPSS 0.32% | 25 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.