Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,321 results · page 141 of 787
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-3823 | EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | CRITICAL 9.3EPSS 0.73% | 9 March 2026 |
| CVE-2026-3630 | Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability. | CRITICAL 9.8EPSS 0.96% | 9 March 2026 |
| CVE-2026-30909 | Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing… | CRITICAL 9.8EPSS 0.53% | 8 March 2026 |
| CVE-2026-30863 | This allows an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server. | CRITICAL 9.3EPSS 0.53% | 7 March 2026 |
| CVE-2026-30860 | Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. | CRITICAL 9.8EPSS 0.54% | 7 March 2026 |
| CVE-2026-30832 | The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at… | CRITICAL 9.1EPSS 0.33% | 7 March 2026 |
| CVE-2026-29191 | From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. | CRITICAL 9.3EPSS 0.40% | 7 March 2026 |
| CVE-2026-29186 | Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. | CRITICAL 9.8EPSS 0.78% | 7 March 2026 |
| CVE-2026-29067 | From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. | CRITICAL 9.3EPSS 0.32% | 7 March 2026 |
| CVE-2026-25070 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. | CRITICAL 9.3EPSS 3.00% | 7 March 2026 |
| CVE-2026-30847 | Wekan is an open source kanban tool built with Meteor. | CRITICAL 9.3EPSS 0.24% | 6 March 2026 |
| CVE-2026-30844 | Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. | CRITICAL 9.3EPSS 0.24% | 6 March 2026 |
| CVE-2026-30843 | Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update endpoints, potentially leading to unauthorized data… | CRITICAL 9.3EPSS 0.22% | 6 March 2026 |
| CVE-2026-28514 | Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that allows an attacker to log in to the service as… | CRITICAL 9.3EPSS 0.50% | 6 March 2026 |
| CVE-2026-29075 | In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. | CRITICAL 9.8EPSS 0.37% | 6 March 2026 |
| CVE-2026-26288 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. | CRITICAL 9.3EPSS 0.64% | 6 March 2026 |
| CVE-2026-26051 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. | CRITICAL 9.3EPSS 0.87% | 6 March 2026 |
| CVE-2026-2331 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. | CRITICAL 9.8EPSS 0.89% | 6 March 2026 |
| CVE-2026-2330 | An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. | CRITICAL 9.4EPSS 0.66% | 6 March 2026 |
| CVE-2026-29058 | Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. | CRITICAL 9.8EPSS 2.13% | 6 March 2026 |
| CVE-2026-2446 | The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users | CRITICAL 9.8EPSS 0.40% | 6 March 2026 |
| CVE-2026-28794 | Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package. | CRITICAL 9.3EPSS 0.91% | 6 March 2026 |
| CVE-2026-28787 | This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.3) and allows an attacker who has obtained a valid WebAuthn assertion (e.g., via XSS, MitM, or log exposure) to replay it indefinitely, completely bypassing the… | CRITICAL 9.0EPSS 0.28% | 6 March 2026 |
| CVE-2026-28785 | Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. | CRITICAL 9.3EPSS 0.37% | 6 March 2026 |
| CVE-2026-28680 | Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. | CRITICAL 9.3EPSS 0.23% | 6 March 2026 |
| CVE-2026-28508 | Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. | CRITICAL 9.2EPSS 0.63% | 6 March 2026 |
| CVE-2026-29093 | An attacker who can reach port 11211 can read, modify, or flush session data — enabling session hijacking, admin impersonation, and mass session destruction without any application-level authentication. | CRITICAL 9.8EPSS 0.49% | 6 March 2026 |
| CVE-2026-29046 | This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. | CRITICAL 9.2EPSS 0.39% | 6 March 2026 |
| CVE-2026-28502 | Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. | CRITICAL 9.3EPSS 0.67% | 6 March 2026 |
| CVE-2026-28501 | Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. | CRITICAL 9.8EPSS 1.51% | 6 March 2026 |
| CVE-2026-28497 | Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. | CRITICAL 9.3EPSS 0.47% | 6 March 2026 |
| CVE-2025-59543 | Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. | CRITICAL 9.0EPSS 0.25% | 6 March 2026 |
| CVE-2025-59542 | Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. | CRITICAL 9.0EPSS 0.30% | 6 March 2026 |
| CVE-2025-55289 | Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging features. | CRITICAL 9.0EPSS 0.30% | 6 March 2026 |
| CVE-2026-28710 | Sensitive information disclosure and manipulation due to improper authentication. | CRITICAL 9.8EPSS 0.41% | 6 March 2026 |
| CVE-2026-22552 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. | CRITICAL 9.3EPSS 0.89% | 6 March 2026 |
| CVE-2026-26125 | Payment Orchestrator Service Elevation of Privilege Vulnerability | CRITICAL 9.8EPSS 1.17% | 5 March 2026 |
| CVE-2026-21536 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | CRITICAL 9.8EPSS 1.60% | 5 March 2026 |
| CVE-2026-28474 | OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. | CRITICAL 9.3EPSS 0.48% | 5 March 2026 |
| CVE-2026-28472 | OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. | CRITICAL 9.2EPSS 0.35% | 5 March 2026 |
| CVE-2026-28470 | OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. | CRITICAL 9.2EPSS 0.47% | 5 March 2026 |
| CVE-2026-28466 | OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. | CRITICAL 9.4EPSS 0.42% | 5 March 2026 |
| CVE-2026-28446 | OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict… | CRITICAL 9.2EPSS 0.65% | 5 March 2026 |
| CVE-2026-28391 | OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. | CRITICAL 9.2EPSS 0.50% | 5 March 2026 |
| CVE-2026-21622 | Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. | CRITICAL 9.5EPSS 0.39% | 5 March 2026 |
| CVE-2026-0848 | NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. | CRITICAL 10.0EPSS 0.81% | 5 March 2026 |
| CVE-2025-70948 | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header. | CRITICAL 9.3EPSS 0.35% | 5 March 2026 |
| CVE-2025-55208 | Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. | CRITICAL 9.0EPSS 0.31% | 5 March 2026 |
| CVE-2026-28353 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. | CRITICAL 10.0EPSS 0.45% | 5 March 2026 |
| CVE-2025-29165 | An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component | CRITICAL 9.8EPSS 0.63% | 5 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.