Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,298 results · page 138 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-69902 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters. | CRITICAL 9.8EPSS 2.06% | 16 March 2026 |
| CVE-2026-28430 | Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. | CRITICAL 9.3EPSS 0.33% | 16 March 2026 |
| CVE-2025-69809 | A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet. | CRITICAL 9.8EPSS 0.53% | 16 March 2026 |
| CVE-2025-69808 | An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet. | CRITICAL 9.1EPSS 0.35% | 16 March 2026 |
| CVE-2026-27962 | Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. | CRITICAL 9.1EPSS 0.55% | 16 March 2026 |
| CVE-2026-23489 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. | CRITICAL 9.1EPSS 0.30% | 16 March 2026 |
| CVE-2025-62319 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. | CRITICAL 9.8EPSS 0.28% | 16 March 2026 |
| CVE-2026-32626 | In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure Electron configuration. | CRITICAL 9.6EPSS 0.72% | 16 March 2026 |
| CVE-2026-32621 | Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. | CRITICAL 9.9EPSS 0.51% | 16 March 2026 |
| CVE-2025-52648 | HCL AION is affected by a vulnerability where offering images are not digitally signed. | CRITICAL 9.8EPSS 0.12% | 16 March 2026 |
| CVE-2025-15060 | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 1.63% | 16 March 2026 |
| CVE-2017-20224 | Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. | CRITICAL 9.3EPSS 1.04% | 16 March 2026 |
| CVE-2017-20223 | Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. | CRITICAL 9.3EPSS 0.52% | 16 March 2026 |
| CVE-2016-20030 | ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. | CRITICAL 9.3EPSS 0.56% | 16 March 2026 |
| CVE-2016-20026 | ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. | CRITICAL 9.3EPSS 0.78% | 16 March 2026 |
| CVE-2016-20024 | ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. | CRITICAL 9.3EPSS 0.73% | 16 March 2026 |
| CVE-2026-3891 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. | EXPLOITCRITICAL 9.8EPSS 25.1% | 13 March 2026 |
| CVE-2026-32746 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | EXPLOITCRITICAL 9.8EPSS 23.7% | 13 March 2026 |
| CVE-2026-32367 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <= 3.5.16. | CRITICAL 9.1EPSS 0.40% | 13 March 2026 |
| CVE-2026-32306 | There is no allowlist, no parameterized query binding, and no input validation. | CRITICAL 9.9EPSS 0.65% | 13 March 2026 |
| CVE-2026-32304 | Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. | CRITICAL 9.8EPSS 0.56% | 13 March 2026 |
| CVE-2026-32301 | Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). | CRITICAL 9.3EPSS 0.26% | 13 March 2026 |
| CVE-2026-31897 | FreeRDP is a free implementation of the Remote Desktop Protocol. | CRITICAL 9.1EPSS 0.29% | 13 March 2026 |
| CVE-2026-31885 | FreeRDP is a free implementation of the Remote Desktop Protocol. | CRITICAL 9.4EPSS 0.26% | 13 March 2026 |
| CVE-2026-31883 | FreeRDP is a free implementation of the Remote Desktop Protocol. | CRITICAL 9.8EPSS 0.32% | 13 March 2026 |
| CVE-2026-31806 | FreeRDP is a free implementation of the Remote Desktop Protocol. | CRITICAL 9.3EPSS 0.66% | 13 March 2026 |
| CVE-2026-26954 | Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. | CRITICAL 10.0EPSS 0.55% | 13 March 2026 |
| CVE-2026-25823 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve… | CRITICAL 9.8EPSS 0.73% | 13 March 2026 |
| CVE-2026-25818 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user… | CRITICAL 9.1EPSS 0.14% | 13 March 2026 |
| CVE-2026-22193 | wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. | CRITICAL 9.2EPSS 0.30% | 13 March 2026 |
| CVE-2026-3611 | The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. | CRITICAL 10.0EPSS 5.50% | 12 March 2026 |
| CVE-2026-32260 | From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) that bypasses the fix for CVE-2026-27190. | CRITICAL 9.8EPSS 1.48% | 12 March 2026 |
| CVE-2026-32251 | An authenticated user who can import translation files into a project can exploit this to read arbitrary files from the server and make server-side requests to internal services. | CRITICAL 9.3EPSS 0.42% | 12 March 2026 |
| CVE-2026-32248 | Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g. anonymous authentication). | CRITICAL 9.3EPSS 0.63% | 12 March 2026 |
| CVE-2026-1525 | Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). | CRITICAL 9.8EPSS 0.49% | 12 March 2026 |
| CVE-2026-32242 | Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one provider to be accepted because it… | CRITICAL 9.1EPSS 0.26% | 12 March 2026 |
| CVE-2026-26793 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. | CRITICAL 9.8EPSS 2.27% | 12 March 2026 |
| CVE-2025-70245 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode. | CRITICAL 9.8EPSS 0.60% | 12 March 2026 |
| CVE-2026-32140 | Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. | CRITICAL 9.3EPSS 0.69% | 12 March 2026 |
| CVE-2026-32137 | Since tableName is a user-controllable string, attackers can inject malicious SQL statements by constructing malicious table names. | CRITICAL 9.3EPSS 0.42% | 12 March 2026 |
| CVE-2026-28252 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device. | CRITICAL 9.2EPSS 0.22% | 12 March 2026 |
| CVE-2026-26795 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. | CRITICAL 9.8EPSS 2.49% | 12 March 2026 |
| CVE-2026-26792 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. | CRITICAL 9.8EPSS 2.78% | 12 March 2026 |
| CVE-2026-26791 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. | CRITICAL 9.8EPSS 2.49% | 12 March 2026 |
| CVE-2026-28792 | Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. | CRITICAL 9.6EPSS 0.53% | 12 March 2026 |
| CVE-2026-21708 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. | CRITICAL 9.9EPSS 1.09% | 12 March 2026 |
| CVE-2026-28384 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. | CRITICAL 9.4EPSS 0.65% | 12 March 2026 |
| CVE-2026-21671 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. | CRITICAL 9.1EPSS 1.33% | 12 March 2026 |
| CVE-2026-21669 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | CRITICAL 9.9EPSS 1.17% | 12 March 2026 |
| CVE-2026-3060 | SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication. | CRITICAL 9.8EPSS 1.16% | 12 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.