Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 16 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-78445 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.89% | 8 September 2026 |
| CVE-2026-77493 | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.95% | 8 September 2026 |
| CVE-2026-73025 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. | CRITICAL 9.8EPSS 0.90% | 8 September 2026 |
| CVE-2026-73010 | Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.89% | 8 September 2026 |
| CVE-2026-73009 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.89% | 8 September 2026 |
| CVE-2026-72983 | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.91% | 8 September 2026 |
| CVE-2026-72982 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.91% | 8 September 2026 |
| CVE-2026-72979 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 8 September 2026 |
| CVE-2026-70296 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.95% | 8 September 2026 |
| CVE-2026-69910 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 8 September 2026 |
| CVE-2026-69854 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.0EPSS 0.64% | 8 September 2026 |
| CVE-2026-69845 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.93% | 8 September 2026 |
| CVE-2026-69829 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.03% | 8 September 2026 |
| CVE-2026-69824 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.00% | 8 September 2026 |
| CVE-2026-69819 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.93% | 8 September 2026 |
| CVE-2026-69769 | Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.91% | 8 September 2026 |
| CVE-2026-69768 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.93% | 8 September 2026 |
| CVE-2026-69730 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.05% | 8 September 2026 |
| CVE-2026-69715 | Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.00% | 8 September 2026 |
| CVE-2026-69641 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.1EPSS 0.85% | 8 September 2026 |
| CVE-2026-69595 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.06% | 8 September 2026 |
| CVE-2026-69590 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | CRITICAL 9.8EPSS 0.98% | 8 September 2026 |
| CVE-2026-69586 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.00% | 8 September 2026 |
| CVE-2026-69579 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 8 September 2026 |
| CVE-2026-69525 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.04% | 8 September 2026 |
| CVE-2026-69496 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 8 September 2026 |
| CVE-2026-69493 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.00% | 8 September 2026 |
| CVE-2026-69491 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.87% | 8 September 2026 |
| CVE-2026-69463 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.91% | 8 September 2026 |
| CVE-2026-69431 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.93% | 8 September 2026 |
| CVE-2026-69408 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 1.00% | 8 September 2026 |
| CVE-2026-69356 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | CRITICAL 9.3EPSS 0.70% | 8 September 2026 |
| CVE-2026-69276 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.93% | 8 September 2026 |
| CVE-2026-68839 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.78% | 8 September 2026 |
| CVE-2026-67643 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.89% | 8 September 2026 |
| CVE-2026-67636 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.0EPSS 0.51% | 8 September 2026 |
| CVE-2026-67631 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.67% | 8 September 2026 |
| CVE-2026-67378 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. | CRITICAL 9.0EPSS 0.51% | 8 September 2026 |
| CVE-2026-65669 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.74% | 8 September 2026 |
| CVE-2026-82533 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP… | CRITICAL 9.4EPSS 0.62% | 8 September 2026 |
| CVE-2026-82067 | Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. | CRITICAL 9.2EPSS 0.28% | 8 September 2026 |
| CVE-2026-79570 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. | CRITICAL 9.8EPSS 0.32% | 8 September 2026 |
| CVE-2026-79569 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. | CRITICAL 9.8EPSS 0.39% | 8 September 2026 |
| CVE-2026-78997 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. | CRITICAL 9.3EPSS 0.28% | 8 September 2026 |
| CVE-2026-75156 | Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read… | CRITICAL 9.1EPSS 0.27% | 8 September 2026 |
| CVE-2026-26084 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via… | CRITICAL 9.9EPSS 0.24% | 8 September 2026 |
| CVE-2026-86840 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. | CRITICAL 9.1EPSS 0.24% | 8 September 2026 |
| CVE-2026-86738 | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. | CRITICAL 9.3EPSS 0.27% | 8 September 2026 |
| CVE-2026-86729 | WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. | CRITICAL 9.1EPSS 0.22% | 8 September 2026 |
| CVE-2026-79574 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | CRITICAL 9.8EPSS 0.48% | 8 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.