Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,321 results · page 143 of 787
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-3381 | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. | CRITICAL 9.8EPSS 0.55% | 5 March 2026 |
| CVE-2026-3257 | UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. | CRITICAL 9.8EPSS 0.41% | 5 March 2026 |
| CVE-2025-40931 | Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. | CRITICAL 9.1EPSS 0.58% | 5 March 2026 |
| CVE-2025-40926 | Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. | CRITICAL 9.8EPSS 0.43% | 5 March 2026 |
| CVE-2026-2835 | An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. | CRITICAL 9.3EPSS 0.79% | 5 March 2026 |
| CVE-2026-2833 | An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. | CRITICAL 9.3EPSS 0.67% | 5 March 2026 |
| CVE-2026-29045 | Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. | CRITICAL 9.8EPSS 0.50% | 4 March 2026 |
| CVE-2026-29000 | pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. | CRITICAL 9.3EPSS 5.86% | 4 March 2026 |
| CVE-2025-70222 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode. | CRITICAL 9.8EPSS 0.48% | 4 March 2026 |
| CVE-2025-70225 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component | CRITICAL 9.8EPSS 0.48% | 4 March 2026 |
| CVE-2025-70221 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin. | CRITICAL 9.8EPSS 0.48% | 4 March 2026 |
| CVE-2025-46108 | D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. | CRITICAL 9.8EPSS 0.60% | 4 March 2026 |
| CVE-2026-3545 | Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.38% | 4 March 2026 |
| CVE-2025-70219 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. | CRITICAL 9.8EPSS 3.26% | 4 March 2026 |
| CVE-2025-70226 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard. | CRITICAL 9.8EPSS 0.48% | 4 March 2026 |
| CVE-2025-70223 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork. | CRITICAL 9.8EPSS 0.51% | 4 March 2026 |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 10.0EPSS 33.4% | 4 March 2026 |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 10.0EPSS 75.8% | 4 March 2026 |
| CVE-2025-70220 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4. | CRITICAL 9.8EPSS 0.60% | 4 March 2026 |
| CVE-2025-70218 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component. | CRITICAL 9.8EPSS 0.63% | 4 March 2026 |
| CVE-2026-28783 | In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with access to the System Messages utility. | CRITICAL 9.4EPSS 0.46% | 4 March 2026 |
| CVE-2026-28697 | Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). | CRITICAL 9.4EPSS 1.07% | 4 March 2026 |
| CVE-2025-69969 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the… | CRITICAL 9.6EPSS 0.46% | 4 March 2026 |
| CVE-2025-66944 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint | CRITICAL 9.8EPSS 0.77% | 4 March 2026 |
| CVE-2025-66678 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request. | CRITICAL 9.8EPSS 0.64% | 4 March 2026 |
| CVE-2026-26478 | A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account. | CRITICAL 9.8EPSS 2.00% | 4 March 2026 |
| CVE-2026-27446 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. | CRITICAL 9.3EPSS 10.0% | 4 March 2026 |
| CVE-2026-27442 | The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access files on the gateway. | CRITICAL 9.3EPSS 0.42% | 4 March 2026 |
| CVE-2026-27441 | SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution. | CRITICAL 9.5EPSS 0.31% | 4 March 2026 |
| CVE-2026-29120 | The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. | CRITICAL 9.2EPSS 0.14% | 4 March 2026 |
| CVE-2026-28777 | A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell. | CRITICAL 9.2EPSS 0.49% | 4 March 2026 |
| CVE-2026-28775 | An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. | CRITICAL 10.0EPSS 1.20% | 4 March 2026 |
| CVE-2026-28774 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. | CRITICAL 9.3EPSS 2.43% | 4 March 2026 |
| CVE-2026-28773 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. | CRITICAL 9.3EPSS 2.09% | 4 March 2026 |
| CVE-2026-27971 | Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single… | CRITICAL 9.2EPSS 5.42% | 3 March 2026 |
| CVE-2026-26279 | This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. | CRITICAL 9.1EPSS 0.80% | 3 March 2026 |
| CVE-2026-3224 | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT). | CRITICAL 9.8EPSS 0.51% | 3 March 2026 |
| CVE-2026-3204 | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL. | CRITICAL 9.8EPSS 0.53% | 3 March 2026 |
| CVE-2026-3130 | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one… | CRITICAL 9.8EPSS 0.45% | 3 March 2026 |
| CVE-2026-27012 | In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. | CRITICAL 9.8EPSS 0.54% | 3 March 2026 |
| CVE-2026-2590 | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially… | CRITICAL 9.8EPSS 0.42% | 3 March 2026 |
| CVE-2026-24898 | Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to complete third-party service compromise, PHI exfiltration,… | CRITICAL 9.8EPSS 0.56% | 3 March 2026 |
| CVE-2025-70240 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51. | CRITICAL 9.8EPSS 0.72% | 3 March 2026 |
| CVE-2025-70239 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55. | CRITICAL 9.8EPSS 0.61% | 3 March 2026 |
| CVE-2025-70234 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS. | CRITICAL 9.8EPSS 0.70% | 3 March 2026 |
| CVE-2025-70241 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5. | CRITICAL 9.8EPSS 0.59% | 3 March 2026 |
| CVE-2025-70237 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr. | CRITICAL 9.8EPSS 0.71% | 3 March 2026 |
| CVE-2025-70236 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter. | CRITICAL 9.8EPSS 0.59% | 3 March 2026 |
| CVE-2025-66945 | A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. | CRITICAL 9.1EPSS 0.53% | 3 March 2026 |
| CVE-2025-14923 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. | CRITICAL 9.8EPSS 0.17% | 3 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.