Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,298 results · page 134 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-32523 | Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2. | CRITICAL 9.9EPSS 0.32% | 25 March 2026 |
| CVE-2026-32520 | Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4. | CRITICAL 9.8EPSS 0.32% | 25 March 2026 |
| CVE-2026-32519 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2. | CRITICAL 9.0EPSS 0.34% | 25 March 2026 |
| CVE-2026-32512 | Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-32502 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-32499 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-32482 | Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24. | CRITICAL 9.9EPSS 0.32% | 25 March 2026 |
| CVE-2026-31920 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange… | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-27095 | Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <=… | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-27084 | Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11. | CRITICAL 9.8EPSS 0.48% | 25 March 2026 |
| CVE-2026-27083 | Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-27082 | Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-27071 | Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7. | CRITICAL 9.1EPSS 0.30% | 25 March 2026 |
| CVE-2026-27051 | Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. | CRITICAL 9.8EPSS 0.32% | 25 March 2026 |
| CVE-2026-27049 | Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2. | CRITICAL 9.8EPSS 0.53% | 25 March 2026 |
| CVE-2026-27044 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | CRITICAL 9.9EPSS 0.30% | 25 March 2026 |
| CVE-2026-25447 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9. | CRITICAL 9.1EPSS 0.31% | 25 March 2026 |
| CVE-2026-25429 | Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-25413 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | CRITICAL 9.9EPSS 0.33% | 25 March 2026 |
| CVE-2026-25377 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-25371 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-25366 | Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1. | CRITICAL 9.9EPSS 0.31% | 25 March 2026 |
| CVE-2026-25345 | Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2. | CRITICAL 9.9EPSS 0.45% | 25 March 2026 |
| CVE-2026-25340 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-25035 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2. | CRITICAL 9.8EPSS 0.42% | 25 March 2026 |
| CVE-2026-25032 | Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-25031 | Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-25030 | Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-25029 | Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-24993 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects… | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-24989 | Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0. | CRITICAL 9.8EPSS 0.38% | 25 March 2026 |
| CVE-2026-24971 | Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8. | CRITICAL 9.8EPSS 0.32% | 25 March 2026 |
| CVE-2026-24968 | Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30. | CRITICAL 9.8EPSS 0.41% | 25 March 2026 |
| CVE-2026-24378 | Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0. | CRITICAL 9.8EPSS 0.51% | 25 March 2026 |
| CVE-2026-22507 | Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6. | CRITICAL 9.8EPSS 0.51% | 25 March 2026 |
| CVE-2026-22500 | Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2. | CRITICAL 9.8EPSS 0.51% | 25 March 2026 |
| CVE-2026-22484 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0. | CRITICAL 9.3EPSS 0.38% | 25 March 2026 |
| CVE-2026-26833 | thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or… | CRITICAL 9.8EPSS 2.31% | 25 March 2026 |
| CVE-2026-26832 | In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. | CRITICAL 9.8EPSS 1.71% | 25 March 2026 |
| CVE-2026-26831 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. | CRITICAL 9.8EPSS 2.42% | 25 March 2026 |
| CVE-2026-26830 | pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. | CRITICAL 9.8EPSS 2.49% | 25 March 2026 |
| CVE-2025-59707 | In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability. | CRITICAL 9.8EPSS 0.53% | 25 March 2026 |
| CVE-2025-59706 | In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution. | CRITICAL 9.8EPSS 0.53% | 25 March 2026 |
| CVE-2025-32991 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. | CRITICAL 9.0EPSS 0.34% | 25 March 2026 |
| CVE-2026-28858 | A buffer overflow was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.53% | 25 March 2026 |
| CVE-2026-28827 | A parsing issue in the handling of directory paths was addressed with improved path validation. | CRITICAL 9.3EPSS 0.28% | 25 March 2026 |
| CVE-2026-20688 | A path handling issue was addressed with improved validation. | CRITICAL 9.3EPSS 0.27% | 25 March 2026 |
| CVE-2026-24159 | NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. | CRITICAL 9.8EPSS 0.64% | 24 March 2026 |
| CVE-2026-24157 | NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. | CRITICAL 9.8EPSS 0.65% | 24 March 2026 |
| CVE-2025-33244 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. | CRITICAL 9.0EPSS 0.58% | 24 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.