Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,321 results · page 140 of 787
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-30903 | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access. | CRITICAL 9.8EPSS 0.33% | 11 March 2026 |
| CVE-2026-3826 | IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server. | CRITICAL 9.3EPSS 0.52% | 11 March 2026 |
| CVE-2026-27842 | Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration. | CRITICAL 9.3EPSS 0.56% | 11 March 2026 |
| CVE-2026-2631 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. | CRITICAL 9.8EPSS 0.58% | 11 March 2026 |
| CVE-2026-24448 | Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access. | CRITICAL 9.3EPSS 0.39% | 11 March 2026 |
| CVE-2023-27573 | netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). | CRITICAL 9.8EPSS 0.49% | 11 March 2026 |
| CVE-2026-29515 | MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. | CRITICAL 9.3EPSS 0.48% | 11 March 2026 |
| CVE-2026-23813 | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. | CRITICAL 9.8EPSS 0.74% | 11 March 2026 |
| CVE-2026-28806 | Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API. | CRITICAL 9.4EPSS 0.41% | 10 March 2026 |
| CVE-2026-30966 | An attacker can create, read, update, or delete records in any internal relationship table. | CRITICAL 10.0EPSS 0.38% | 10 March 2026 |
| CVE-2026-30965 | Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter. | CRITICAL 9.9EPSS 1.33% | 10 March 2026 |
| CVE-2026-0124 | There is a possible out of bounds write due to a missing bounds check. | CRITICAL 10.0EPSS 0.14% | 10 March 2026 |
| CVE-2026-0120 | This could lead to remote code execution with no additional execution privileges needed. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-0116 | In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-0114 | This could lead to remote code execution with no additional execution privileges needed. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-0113 | This could lead to remote escalation of privilege with no additional execution privileges needed. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-0111 | This could lead to remote escalation of privilege with no additional execution privileges needed. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-0110 | In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. | CRITICAL 9.8EPSS 0.31% | 10 March 2026 |
| CVE-2026-29793 | From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove). | CRITICAL 9.3EPSS 0.46% | 10 March 2026 |
| CVE-2026-29792 | From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a forged profile in the query string. | CRITICAL 9.3EPSS 0.52% | 10 March 2026 |
| CVE-2026-28292 | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code… | CRITICAL 9.8EPSS 1.30% | 10 March 2026 |
| CVE-2026-3843 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. | CRITICAL 9.3EPSS 0.76% | 10 March 2026 |
| CVE-2026-30960 | The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Function Interface). | CRITICAL 9.4EPSS 0.21% | 10 March 2026 |
| CVE-2026-30957 | Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. | CRITICAL 9.9EPSS 1.15% | 10 March 2026 |
| CVE-2026-30956 | Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid header. | CRITICAL 9.9EPSS 0.49% | 10 March 2026 |
| CVE-2026-26105 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | CRITICAL 9.3EPSS 1.16% | 10 March 2026 |
| CVE-2026-23240 | In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. | CRITICAL 9.8EPSS 0.49% | 10 March 2026 |
| CVE-2025-69615 | Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. | CRITICAL 9.1EPSS 0.45% | 10 March 2026 |
| CVE-2025-69614 | Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. | CRITICAL 9.4EPSS 0.39% | 10 March 2026 |
| CVE-2025-56422 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. | CRITICAL 9.8EPSS 0.85% | 10 March 2026 |
| CVE-2025-41709 | An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. | CRITICAL 9.8EPSS 2.15% | 10 March 2026 |
| CVE-2025-40943 | This could allow an attacker to inject code through social engineering an authorized user, who has the function right "Read diagnostics", to import a specially crafted trace file. | CRITICAL 9.4EPSS 0.46% | 10 March 2026 |
| CVE-2026-30921 | Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. | CRITICAL 9.9EPSS 0.45% | 10 March 2026 |
| CVE-2026-30887 | Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. | CRITICAL 9.9EPSS 0.39% | 10 March 2026 |
| CVE-2026-30869 | Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. | CRITICAL 9.8EPSS 1.03% | 10 March 2026 |
| CVE-2026-30862 | Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). | CRITICAL 9.0EPSS 0.31% | 10 March 2026 |
| CVE-2026-27685 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system. | CRITICAL 9.1EPSS 0.55% | 10 March 2026 |
| CVE-2026-0953 | The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. | CRITICAL 9.8EPSS 0.66% | 10 March 2026 |
| CVE-2025-11158 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE. | CRITICAL 9.1EPSS 0.38% | 10 March 2026 |
| CVE-2026-28431 | All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access due to insufficient permission checks and proper input validation. | CRITICAL 9.2EPSS 0.25% | 10 March 2026 |
| CVE-2026-31816 | In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. | CRITICAL 9.1EPSS 15.3% | 9 March 2026 |
| CVE-2026-25960 | The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client. | CRITICAL 9.8EPSS 0.54% | 9 March 2026 |
| CVE-2026-25737 | In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. | CRITICAL 9.0EPSS 0.26% | 9 March 2026 |
| CVE-2025-70039 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. | CRITICAL 9.8EPSS 0.38% | 9 March 2026 |
| CVE-2025-70046 | An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master. | CRITICAL 9.8EPSS 0.36% | 9 March 2026 |
| CVE-2025-70042 | An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. | CRITICAL 9.8EPSS 0.33% | 9 March 2026 |
| CVE-2026-24713 | Improper Input Validation vulnerability in Apache IoTDB. | CRITICAL 9.8EPSS 0.66% | 9 March 2026 |
| CVE-2026-24015 | A vulnerability in Apache IoTDB. | CRITICAL 9.8EPSS 0.58% | 9 March 2026 |
| CVE-2025-41765 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. | CRITICAL 9.1EPSS 0.27% | 9 March 2026 |
| CVE-2025-41764 | Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates. | CRITICAL 9.1EPSS 0.41% | 9 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.