Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,291 results · page 135 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-4724 | This vulnerability was fixed in Firefox 149 and Thunderbird 149. | CRITICAL 9.1EPSS 0.32% | 24 March 2026 |
| CVE-2026-4723 | Use-after-free in the JavaScript Engine component. | CRITICAL 9.8EPSS 0.39% | 24 March 2026 |
| CVE-2026-4721 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.42% | 24 March 2026 |
| CVE-2026-4720 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.42% | 24 March 2026 |
| CVE-2026-4717 | Privilege escalation in the Netmonitor component. | CRITICAL 9.8EPSS 0.42% | 24 March 2026 |
| CVE-2026-4716 | This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.1EPSS 0.41% | 24 March 2026 |
| CVE-2026-4715 | This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.1EPSS 0.43% | 24 March 2026 |
| CVE-2026-4711 | Use-after-free in the Widget: Cocoa component. | CRITICAL 9.8EPSS 0.40% | 24 March 2026 |
| CVE-2026-4710 | This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.8EPSS 0.41% | 24 March 2026 |
| CVE-2026-4705 | This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.8EPSS 0.42% | 24 March 2026 |
| CVE-2026-4702 | This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.8EPSS 0.47% | 24 March 2026 |
| CVE-2026-4701 | Use-after-free in the JavaScript Engine component. | CRITICAL 9.8EPSS 0.46% | 24 March 2026 |
| CVE-2026-4700 | Mitigation bypass in the Networking: HTTP component. | CRITICAL 9.8EPSS 0.46% | 24 March 2026 |
| CVE-2026-4698 | This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 9.8EPSS 0.76% | 24 March 2026 |
| CVE-2026-4696 | Use-after-free in the Layout: Text and Fonts component. | CRITICAL 9.8EPSS 0.48% | 24 March 2026 |
| CVE-2026-4692 | This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | CRITICAL 10.0EPSS 0.49% | 24 March 2026 |
| CVE-2026-4691 | Use-after-free in the CSS Parsing and Computation component. | CRITICAL 9.8EPSS 0.48% | 24 March 2026 |
| CVE-2026-4689 | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | CRITICAL 10.0EPSS 0.66% | 24 March 2026 |
| CVE-2026-4688 | Sandbox escape due to use-after-free in the Disability Access APIs component. | CRITICAL 10.0EPSS 0.53% | 24 March 2026 |
| CVE-2026-33475 | An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0. | CRITICAL 9.1EPSS 2.96% | 24 March 2026 |
| CVE-2026-33309 | Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. | CRITICAL 9.9EPSS 11.1% | 24 March 2026 |
| CVE-2019-25646 | Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. | CRITICAL 9.3EPSS 0.91% | 24 March 2026 |
| CVE-2019-25628 | Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. | CRITICAL 9.3EPSS 0.80% | 24 March 2026 |
| CVE-2026-4755 | CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | CRITICAL 9.8EPSS 0.28% | 24 March 2026 |
| CVE-2026-4753 | Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72. | CRITICAL 9.1EPSS 0.42% | 24 March 2026 |
| CVE-2026-4750 | Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0. | CRITICAL 9.1EPSS 0.40% | 24 March 2026 |
| CVE-2026-33854 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. | CRITICAL 9.8EPSS 0.24% | 24 March 2026 |
| CVE-2026-4746 | Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). | CRITICAL 10.0EPSS 0.28% | 24 March 2026 |
| CVE-2026-4745 | Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). | CRITICAL 10.0EPSS 0.29% | 24 March 2026 |
| CVE-2026-4283 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. | CRITICAL 9.1EPSS 0.43% | 24 March 2026 |
| CVE-2026-4744 | Out-of-bounds Read vulnerability in rizonesoft Notepad3 (scintilla/oniguruma/src modules). | CRITICAL 9.3EPSS 0.13% | 24 March 2026 |
| CVE-2026-4739 | Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1. | CRITICAL 9.4EPSS 0.28% | 24 March 2026 |
| CVE-2026-4738 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). | CRITICAL 9.4EPSS 0.28% | 24 March 2026 |
| CVE-2026-4734 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). | CRITICAL 9.4EPSS 0.28% | 24 March 2026 |
| CVE-2026-4001 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within… | CRITICAL 9.8EPSS 0.71% | 24 March 2026 |
| CVE-2026-33286 | Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. | CRITICAL 9.1EPSS 0.63% | 24 March 2026 |
| CVE-2026-33211 | Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. | CRITICAL 9.6EPSS 0.57% | 24 March 2026 |
| CVE-2026-4681 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. | CRITICAL 9.3EPSS 0.76% | 23 March 2026 |
| CVE-2026-33634 | Aquasecurity Trivy Embedded Malicious Code Vulnerability | KEVCRITICAL 9.4EPSS 59.2% | 23 March 2026 |
| CVE-2025-60949 | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. | CRITICAL 9.3EPSS 0.40% | 23 March 2026 |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability | KEVCRITICAL 9.3EPSS 87.2% | 23 March 2026 |
| CVE-2026-30849 | Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. | CRITICAL 9.3EPSS 1.46% | 23 March 2026 |
| CVE-2026-2298 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. | CRITICAL 9.4EPSS 0.41% | 23 March 2026 |
| CVE-2026-33716 | An attacker can redirect token verification to a server they control that always returns `{"error": false}`, completely bypassing authentication. | CRITICAL 9.4EPSS 0.44% | 23 March 2026 |
| CVE-2026-0898 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. | CRITICAL 9.0EPSS 0.32% | 23 March 2026 |
| CVE-2026-4404 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | CRITICAL 9.4EPSS 0.49% | 23 March 2026 |
| CVE-2026-33478 | In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. | CRITICAL 10.0EPSS 13.3% | 23 March 2026 |
| CVE-2026-33352 | Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. | CRITICAL 9.8EPSS 0.43% | 23 March 2026 |
| CVE-2026-33351 | Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. | CRITICAL 9.1EPSS 0.43% | 23 March 2026 |
| CVE-2025-41008 | SQL injection vulnerability in Sinturno. | CRITICAL 9.3EPSS 0.25% | 23 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.