Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,321 results · page 142 of 787
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-27944 | Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. | CRITICAL 9.8EPSS 22.2% | 5 March 2026 |
| CVE-2026-25921 | Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. | CRITICAL 9.3EPSS 0.33% | 5 March 2026 |
| CVE-2026-24457 | An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. | CRITICAL 9.8EPSS 0.62% | 5 March 2026 |
| CVE-2025-70233 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard. | CRITICAL 9.8EPSS 0.63% | 5 March 2026 |
| CVE-2025-70232 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter. | CRITICAL 9.8EPSS 0.63% | 5 March 2026 |
| CVE-2025-70231 | D-Link DIR-513 version 1.10 contains a critical-level vulnerability. | CRITICAL 9.8EPSS 0.66% | 5 March 2026 |
| CVE-2025-70230 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS. | CRITICAL 9.8EPSS 0.78% | 5 March 2026 |
| CVE-2025-70229 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule. | CRITICAL 9.8EPSS 0.63% | 5 March 2026 |
| CVE-2025-13476 | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy… | CRITICAL 9.8EPSS 0.34% | 5 March 2026 |
| CVE-2026-30797 | Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. | CRITICAL 9.3EPSS 0.46% | 5 March 2026 |
| CVE-2026-30793 | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. | CRITICAL 9.3EPSS 0.31% | 5 March 2026 |
| CVE-2026-2599 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. | CRITICAL 9.8EPSS 0.52% | 5 March 2026 |
| CVE-2026-21628 | A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. | CRITICAL 10.0EPSS 0.47% | 5 March 2026 |
| CVE-2026-2743 | Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. | CRITICAL 10.0EPSS 0.84% | 5 March 2026 |
| CVE-2026-25702 | A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from… | CRITICAL 9.8EPSS 0.20% | 5 March 2026 |
| CVE-2026-1678 | With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when CONFIG_DNS_RESOLVER is enabled. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-2418 | The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email | CRITICAL 9.1EPSS 0.32% | 5 March 2026 |
| CVE-2026-29053 | From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. | EXPLOITCRITICAL 9.8EPSS 3.58% | 5 March 2026 |
| CVE-2026-28115 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP… | CRITICAL 9.3EPSS 0.24% | 5 March 2026 |
| CVE-2026-28114 | Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6. | CRITICAL 9.1EPSS 0.28% | 5 March 2026 |
| CVE-2026-28105 | Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-28074 | Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-28043 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Clinic & Medical WordPress Theme healer allows PHP Local File Inclusion.This issue affects Healer -… | CRITICAL 9.8EPSS 0.40% | 5 March 2026 |
| CVE-2026-27984 | Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Options: from n/a through <= 4.1.3. | CRITICAL 9.0EPSS 0.27% | 5 March 2026 |
| CVE-2026-27983 | Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4. | CRITICAL 9.8EPSS 0.32% | 5 March 2026 |
| CVE-2026-27439 | Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-27438 | Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-27437 | Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-27417 | Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1. | CRITICAL 9.8EPSS 0.38% | 5 March 2026 |
| CVE-2026-27389 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a… | CRITICAL 9.8EPSS 0.42% | 5 March 2026 |
| CVE-2026-27384 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1. | CRITICAL 9.0EPSS 0.30% | 5 March 2026 |
| CVE-2026-24960 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2. | CRITICAL 9.9EPSS 0.33% | 5 March 2026 |
| CVE-2026-23802 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2. | CRITICAL 9.1EPSS 0.46% | 5 March 2026 |
| CVE-2026-23767 | ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands… | CRITICAL 9.8EPSS 0.45% | 5 March 2026 |
| CVE-2026-22501 | Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22497 | Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22475 | Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4. | CRITICAL 9.8EPSS 0.39% | 5 March 2026 |
| CVE-2026-22474 | Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5. | CRITICAL 9.8EPSS 0.39% | 5 March 2026 |
| CVE-2026-22454 | Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22453 | Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22451 | Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through <= 1.4.7. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22417 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-22390 | Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1. | CRITICAL 9.9EPSS 0.47% | 5 March 2026 |
| CVE-2025-69338 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind SQL Injection.This issue affects Riode Core: from n/a through <= 1.6.26. | CRITICAL 9.3EPSS 0.38% | 5 March 2026 |
| CVE-2025-68555 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1. | CRITICAL 9.9EPSS 0.43% | 5 March 2026 |
| CVE-2025-68554 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1. | CRITICAL 9.9EPSS 0.43% | 5 March 2026 |
| CVE-2025-68553 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1. | CRITICAL 9.9EPSS 0.45% | 5 March 2026 |
| CVE-2025-54001 | Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5. | CRITICAL 9.8EPSS 0.51% | 5 March 2026 |
| CVE-2026-29127 | The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged… | CRITICAL 9.2EPSS 0.17% | 5 March 2026 |
| CVE-2024-57854 | Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. | CRITICAL 9.1EPSS 0.41% | 5 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.