Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 14 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-8323 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. | CRITICAL 9.3EPSS 0.25% | 10 September 2026 |
| CVE-2026-88278 | GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations. | CRITICAL 9.8EPSS 0.27% | 10 September 2026 |
| CVE-2026-59679 | A malicious or compromised font server can send a small num_extents (e.g. | CRITICAL 9.2EPSS 0.41% | 10 September 2026 |
| CVE-2026-44950 | A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. | CRITICAL 9.5EPSS 0.44% | 10 September 2026 |
| CVE-2026-13745 | A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME. | CRITICAL 9.2EPSS 0.30% | 10 September 2026 |
| CVE-2026-80352 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. | CRITICAL 9.8EPSS 0.45% | 10 September 2026 |
| CVE-2026-80351 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. | CRITICAL 9.8EPSS 0.54% | 10 September 2026 |
| CVE-2026-7188 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. | CRITICAL 9.8EPSS 0.32% | 10 September 2026 |
| CVE-2026-78361 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated… | CRITICAL 9.1EPSS 0.25% | 10 September 2026 |
| CVE-2026-77770 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete… | CRITICAL 10.0EPSS 0.24% | 10 September 2026 |
| CVE-2026-84939 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). | CRITICAL 9.1EPSS 0.83% | 10 September 2026 |
| CVE-2026-67593 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. | CRITICAL 9.1EPSS 0.56% | 10 September 2026 |
| CVE-2026-57967 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. | CRITICAL 9.8EPSS 0.69% | 10 September 2026 |
| CVE-2026-49364 | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. | CRITICAL 9.1EPSS 0.38% | 10 September 2026 |
| CVE-2026-19583 | Velociraptor allows some sensitive artifacts to be gated by additional permissions. | CRITICAL 9.9EPSS 0.60% | 10 September 2026 |
| CVE-2026-18351 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. | CRITICAL 9.8EPSS 0.77% | 10 September 2026 |
| CVE-2026-88069 | Pandora contains a path traversal vulnerability in its archive extraction worker. | CRITICAL 9.3EPSS 0.33% | 9 September 2026 |
| CVE-2026-71805 | An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. | CRITICAL 9.8EPSS 0.36% | 9 September 2026 |
| CVE-2026-71801 | The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. | CRITICAL 9.8EPSS 0.53% | 9 September 2026 |
| CVE-2026-36433 | Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | CRITICAL 9.8EPSS 0.48% | 9 September 2026 |
| CVE-2026-87911 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed… | CRITICAL 9.0EPSS 0.99% | 9 September 2026 |
| CVE-2026-54694 | Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly… | CRITICAL 9.6EPSS 0.28% | 9 September 2026 |
| CVE-2026-87930 | MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. | CRITICAL 9.2EPSS 0.34% | 9 September 2026 |
| CVE-2026-87929 | MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. | CRITICAL 9.3EPSS 0.29% | 9 September 2026 |
| CVE-2026-47156 | Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. | CRITICAL 9.3EPSS 0.50% | 9 September 2026 |
| CVE-2026-79689 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. | CRITICAL 9.8EPSS 1.91% | 9 September 2026 |
| CVE-2026-68484 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. | CRITICAL 9.0EPSS 0.17% | 9 September 2026 |
| CVE-2026-67403 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. | CRITICAL 9.0EPSS 0.17% | 9 September 2026 |
| CVE-2026-67401 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | CRITICAL 9.9EPSS 1.04% | 9 September 2026 |
| CVE-2026-22590 | Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. | CRITICAL 9.1EPSS 0.38% | 9 September 2026 |
| CVE-2026-79941 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. | CRITICAL 9.8EPSS 1.91% | 9 September 2026 |
| CVE-2026-85103 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | CRITICAL 9.8EPSS 0.36% | 9 September 2026 |
| CVE-2026-85102 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | CRITICAL 9.8EPSS 0.33% | 9 September 2026 |
| CVE-2026-87806 | Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. | CRITICAL 9.1EPSS 0.29% | 9 September 2026 |
| CVE-2026-80172 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. | CRITICAL 9.8EPSS 0.27% | 9 September 2026 |
| CVE-2026-87827 | Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. | CRITICAL 10.0EPSS 1.07% | 9 September 2026 |
| CVE-2026-85978 | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. | CRITICAL 10.0EPSS 0.88% | 9 September 2026 |
| CVE-2026-56207 | Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. | CRITICAL 9.8EPSS 0.47% | 9 September 2026 |
| CVE-2026-41871 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). | CRITICAL 9.8EPSS 0.78% | 9 September 2026 |
| CVE-2026-41869 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). | CRITICAL 9.1EPSS 0.77% | 9 September 2026 |
| CVE-2026-79696 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute… | CRITICAL 10.0EPSS 0.44% | 9 September 2026 |
| CVE-2026-16272 | Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. | CRITICAL 9.1EPSS 0.14% | 9 September 2026 |
| CVE-2026-21102 | Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege. | CRITICAL 9.3EPSS 0.12% | 9 September 2026 |
| CVE-2026-21096 | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. | CRITICAL 9.2EPSS 0.46% | 9 September 2026 |
| CVE-2026-21095 | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code. | CRITICAL 9.2EPSS 0.46% | 9 September 2026 |
| CVE-2026-87654 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.36% | 9 September 2026 |
| CVE-2026-87650 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 9 September 2026 |
| CVE-2026-87646 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.36% | 9 September 2026 |
| CVE-2026-87643 | Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 9 September 2026 |
| CVE-2026-87638 | Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 9 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.