Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,298 results · page 136 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-33716 | An attacker can redirect token verification to a server they control that always returns `{"error": false}`, completely bypassing authentication. | CRITICAL 9.4EPSS 0.44% | 23 March 2026 |
| CVE-2026-0898 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. | CRITICAL 9.0EPSS 0.32% | 23 March 2026 |
| CVE-2026-4404 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | CRITICAL 9.4EPSS 0.49% | 23 March 2026 |
| CVE-2026-33478 | In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. | CRITICAL 10.0EPSS 13.3% | 23 March 2026 |
| CVE-2026-33352 | Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. | CRITICAL 9.8EPSS 0.43% | 23 March 2026 |
| CVE-2026-33351 | Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. | CRITICAL 9.1EPSS 0.43% | 23 March 2026 |
| CVE-2025-41008 | SQL injection vulnerability in Sinturno. | CRITICAL 9.3EPSS 0.25% | 23 March 2026 |
| CVE-2025-41007 | SQL Injection in Cuantis. | CRITICAL 9.3EPSS 0.31% | 23 March 2026 |
| CVE-2026-32968 | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. | CRITICAL 9.8EPSS 0.55% | 23 March 2026 |
| CVE-2026-3587 | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device. | CRITICAL 10.0EPSS 0.68% | 23 March 2026 |
| CVE-2026-4599 | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the… | CRITICAL 9.3EPSS 0.48% | 23 March 2026 |
| CVE-2026-4606 | GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. | CRITICAL 10.0EPSS 0.30% | 23 March 2026 |
| CVE-2019-25614 | Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. | CRITICAL 9.3EPSS 0.95% | 22 March 2026 |
| CVE-2019-25568 | Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. | CRITICAL 9.3EPSS 0.32% | 21 March 2026 |
| CVE-2026-24060 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. | CRITICAL 9.1EPSS 0.20% | 21 March 2026 |
| CVE-2026-33186 | Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. | CRITICAL 9.1EPSS 1.56% | 20 March 2026 |
| CVE-2026-29796 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. | CRITICAL 9.3EPSS 0.47% | 20 March 2026 |
| CVE-2026-25192 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. | CRITICAL 9.3EPSS 0.48% | 20 March 2026 |
| CVE-2026-21732 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. | CRITICAL 9.6EPSS 0.29% | 20 March 2026 |
| CVE-2026-3584 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. | CRITICAL 9.8EPSS 7.24% | 20 March 2026 |
| CVE-2026-32710 | An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. | CRITICAL 9.9EPSS 0.86% | 20 March 2026 |
| CVE-2026-22898 | A missing authentication for critical function vulnerability has been reported to affect QVR Pro. | CRITICAL 9.3EPSS 0.68% | 20 March 2026 |
| CVE-2026-22172 | OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. | CRITICAL 9.4EPSS 0.56% | 20 March 2026 |
| CVE-2024-44722 | SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. | CRITICAL 9.8EPSS 0.51% | 20 March 2026 |
| CVE-2026-33131 | Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. | CRITICAL 9.1EPSS 0.39% | 20 March 2026 |
| CVE-2026-33128 | In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). | CRITICAL 10.0EPSS 0.57% | 20 March 2026 |
| CVE-2026-33075 | In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. | CRITICAL 9.4EPSS 0.30% | 20 March 2026 |
| CVE-2026-33057 | Mesop is a Python-based UI framework that allows users to build web applications. | CRITICAL 9.8EPSS 5.29% | 20 March 2026 |
| CVE-2026-33054 | Mesop is a Python-based UI framework that allows users to build web applications. | CRITICAL 9.8EPSS 0.71% | 20 March 2026 |
| CVE-2026-33024 | Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php. | CRITICAL 9.3EPSS 0.44% | 20 March 2026 |
| CVE-2026-33017 | Langflow Code Injection Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 96.2% | 20 March 2026 |
| CVE-2026-4038 | The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. | CRITICAL 9.8EPSS 0.30% | 20 March 2026 |
| CVE-2026-32891 | Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. | CRITICAL 9.0EPSS 0.16% | 20 March 2026 |
| CVE-2026-32890 | In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the configured guild to execute arbitrary JavaScript in the Anchorr admin's browser. | CRITICAL 9.6EPSS 0.43% | 20 March 2026 |
| CVE-2026-21992 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). | CRITICAL 9.8EPSS 1.01% | 20 March 2026 |
| CVE-2026-32817 | The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW authorization check (getFolderForDownload / getFileForDownload) before calling delete(), and they never validate a CSRF token. | CRITICAL 9.1EPSS 0.32% | 20 March 2026 |
| CVE-2026-32767 | Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. | CRITICAL 9.8EPSS 0.54% | 20 March 2026 |
| CVE-2026-33289 | Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. | CRITICAL 9.8EPSS 0.66% | 20 March 2026 |
| CVE-2026-32985 | Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing… | CRITICAL 9.3EPSS 1.48% | 20 March 2026 |
| CVE-2026-32760 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. | CRITICAL 10.0EPSS 0.67% | 20 March 2026 |
| CVE-2026-22732 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. | CRITICAL 9.1EPSS 0.48% | 19 March 2026 |
| CVE-2026-32754 | Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. | CRITICAL 9.3EPSS 0.53% | 19 March 2026 |
| CVE-2026-32194 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.18% | 19 March 2026 |
| CVE-2026-32038 | OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. | CRITICAL 9.3EPSS 0.27% | 19 March 2026 |
| CVE-2026-30872 | In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on… | CRITICAL 9.5EPSS 2.22% | 19 March 2026 |
| CVE-2026-30871 | In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. | CRITICAL 9.5EPSS 1.21% | 19 March 2026 |
| CVE-2026-4428 | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. | CRITICAL 9.1EPSS 0.25% | 19 March 2026 |
| CVE-2026-32749 | In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the… | CRITICAL 9.1EPSS 0.43% | 19 March 2026 |
| CVE-2026-32191 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.79% | 19 March 2026 |
| CVE-2026-32169 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.55% | 19 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.