Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,163 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,321 results · page 144 of 787
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-55026 | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request. | CRITICAL 9.8EPSS 0.34% | 3 March 2026 |
| CVE-2024-55024 | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts. | CRITICAL 9.8EPSS 0.36% | 3 March 2026 |
| CVE-2024-55020 | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges. | CRITICAL 9.8EPSS 1.67% | 3 March 2026 |
| CVE-2026-3437 | An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering… | CRITICAL 9.3EPSS 0.16% | 3 March 2026 |
| CVE-2026-24103 | A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi. | CRITICAL 9.8EPSS 0.43% | 3 March 2026 |
| CVE-2026-22891 | A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). | CRITICAL 9.8EPSS 0.59% | 3 March 2026 |
| CVE-2025-70821 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component | CRITICAL 9.8EPSS 0.40% | 3 March 2026 |
| CVE-2025-57622 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component | CRITICAL 9.8EPSS 0.50% | 3 March 2026 |
| CVE-2025-59059 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. | CRITICAL 9.8EPSS 1.24% | 3 March 2026 |
| CVE-2026-22886 | OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. | CRITICAL 9.8EPSS 0.40% | 3 March 2026 |
| CVE-2026-1492 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including,… | CRITICAL 9.8EPSS 28.0% | 3 March 2026 |
| CVE-2026-2628 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. | CRITICAL 9.8EPSS 0.86% | 3 March 2026 |
| CVE-2026-26713 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | CRITICAL 9.8EPSS 0.33% | 2 March 2026 |
| CVE-2026-26712 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | CRITICAL 9.8EPSS 0.32% | 2 March 2026 |
| CVE-2026-26711 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | CRITICAL 9.8EPSS 0.33% | 2 March 2026 |
| CVE-2026-26710 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | CRITICAL 9.8EPSS 0.34% | 2 March 2026 |
| CVE-2026-26709 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | CRITICAL 9.8EPSS 0.33% | 2 March 2026 |
| CVE-2026-0006 | In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. | CRITICAL 9.8EPSS 0.66% | 2 March 2026 |
| CVE-2025-48609 | In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. | CRITICAL 9.1EPSS 0.26% | 2 March 2026 |
| CVE-2026-26707 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | CRITICAL 9.8EPSS 0.47% | 2 March 2026 |
| CVE-2026-26706 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | CRITICAL 9.8EPSS 0.47% | 2 March 2026 |
| CVE-2026-26705 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | CRITICAL 9.8EPSS 0.39% | 2 March 2026 |
| CVE-2026-26704 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | CRITICAL 9.8EPSS 0.39% | 2 March 2026 |
| CVE-2026-28286 | However, when interacting directly with the API, the restrictions are bypass-able. | CRITICAL 9.9EPSS 0.41% | 2 March 2026 |
| CVE-2026-26708 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | CRITICAL 9.8EPSS 0.32% | 2 March 2026 |
| CVE-2026-26700 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php. | CRITICAL 9.8EPSS 0.39% | 2 March 2026 |
| CVE-2026-24105 | The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd. | CRITICAL 9.8EPSS 1.70% | 2 March 2026 |
| CVE-2026-26720 | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. | CRITICAL 9.8EPSS 0.82% | 2 March 2026 |
| CVE-2026-26701 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php. | CRITICAL 9.8EPSS 0.47% | 2 March 2026 |
| CVE-2026-24112 | Attackers may exploit the vulnerability by specifying the value of `userInfo`. | CRITICAL 9.8EPSS 0.53% | 2 March 2026 |
| CVE-2026-24110 | Attackers may send overly long `addDhcpRules` data. | CRITICAL 9.8EPSS 0.43% | 2 March 2026 |
| CVE-2026-24101 | The value of s1_1 is not validated, potentially leading to a command injection vulnerability. | CRITICAL 9.8EPSS 1.67% | 2 March 2026 |
| CVE-2026-26703 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php. | CRITICAL 9.8EPSS 0.55% | 2 March 2026 |
| CVE-2026-26702 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. | CRITICAL 9.8EPSS 0.55% | 2 March 2026 |
| CVE-2026-26696 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. | CRITICAL 9.8EPSS 0.49% | 2 March 2026 |
| CVE-2026-26695 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. | CRITICAL 9.8EPSS 0.49% | 2 March 2026 |
| CVE-2026-26694 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. | CRITICAL 9.8EPSS 0.50% | 2 March 2026 |
| CVE-2026-24115 | Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow. | CRITICAL 9.8EPSS 0.69% | 2 March 2026 |
| CVE-2026-24114 | Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`. | CRITICAL 9.8EPSS 0.62% | 2 March 2026 |
| CVE-2026-24113 | Attackers may exploit the vulnerability by controlling the value of `nptr`. | CRITICAL 9.8EPSS 0.65% | 2 March 2026 |
| CVE-2026-24111 | Attackers may exploit the vulnerability by specifying the value of `userInfo`. | CRITICAL 9.8EPSS 0.65% | 2 March 2026 |
| CVE-2026-24109 | Attackers may exploit the vulnerability by controlling the value of `picName`. | CRITICAL 9.8EPSS 0.65% | 2 March 2026 |
| CVE-2026-24108 | Attackers may exploit the vulnerability by controlling the value of `nptr`. | CRITICAL 9.8EPSS 0.65% | 2 March 2026 |
| CVE-2026-24107 | Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities. | CRITICAL 9.8EPSS 2.16% | 2 March 2026 |
| CVE-2026-23600 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | CRITICAL 10.0EPSS 0.96% | 2 March 2026 |
| CVE-2025-50187 | Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. | CRITICAL 9.8EPSS 0.88% | 2 March 2026 |
| CVE-2026-3432 | On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. | CRITICAL 9.3EPSS 0.30% | 2 March 2026 |
| CVE-2026-3431 | On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. | CRITICAL 9.8EPSS 0.35% | 2 March 2026 |
| CVE-2025-14532 | DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. | CRITICAL 9.3EPSS 0.54% | 2 March 2026 |
| CVE-2025-12462 | A Blind SQL injection vulnerability has been identified in DobryCMS. | CRITICAL 9.3EPSS 0.45% | 2 March 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.