Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 19 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-85661 | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. | CRITICAL 9.3EPSS 0.44% | 4 September 2026 |
| CVE-2026-85660 | cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. | CRITICAL 9.2EPSS 0.47% | 4 September 2026 |
| CVE-2026-85625 | As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. | CRITICAL 9.2EPSS 0.55% | 4 September 2026 |
| CVE-2026-85620 | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. | CRITICAL 9.2EPSS 0.37% | 4 September 2026 |
| CVE-2026-85614 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. | CRITICAL 9.2EPSS 0.16% | 4 September 2026 |
| CVE-2026-85602 | On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name (g-recaptcha-response instead of token), causing validation to use the v2 branch, which never applies the score threshold or verifies the… | CRITICAL 9.3EPSS 0.26% | 4 September 2026 |
| CVE-2026-85595 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. | CRITICAL 9.3EPSS 0.45% | 4 September 2026 |
| CVE-2026-85184 | An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. | CRITICAL 9.1EPSS 0.32% | 4 September 2026 |
| CVE-2026-82923 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their… | CRITICAL 9.8EPSS 0.57% | 4 September 2026 |
| CVE-2026-85085 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. | CRITICAL 9.6EPSS 0.22% | 4 September 2026 |
| CVE-2026-80181 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). | CRITICAL 9.1EPSS 0.40% | 4 September 2026 |
| CVE-2026-70403 | XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). | CRITICAL 9.3EPSS 0.29% | 4 September 2026 |
| CVE-2026-69657 | XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). | CRITICAL 9.3EPSS 0.29% | 4 September 2026 |
| CVE-2026-62928 | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). | CRITICAL 9.3EPSS 1.22% | 4 September 2026 |
| CVE-2026-15354 | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. | CRITICAL 9.8EPSS 0.30% | 4 September 2026 |
| CVE-2026-85509 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. | CRITICAL 9.8EPSS 0.39% | 4 September 2026 |
| CVE-2026-85508 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). | CRITICAL 9.8EPSS 0.39% | 4 September 2026 |
| CVE-2026-85507 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). | CRITICAL 9.8EPSS 0.39% | 4 September 2026 |
| CVE-2026-85506 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). | CRITICAL 9.8EPSS 0.39% | 4 September 2026 |
| CVE-2026-85504 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. | CRITICAL 9.8EPSS 0.39% | 4 September 2026 |
| CVE-2026-11613 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. | CRITICAL 9.8EPSS 0.46% | 4 September 2026 |
| CVE-2026-85148 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. | CRITICAL 9.3EPSS 0.35% | 4 September 2026 |
| CVE-2026-85146 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. | CRITICAL 9.3EPSS 0.35% | 4 September 2026 |
| CVE-2026-75754 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH… | CRITICAL 10.0EPSS 0.21% | 4 September 2026 |
| CVE-2026-67402 | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. | CRITICAL 9.2EPSS 0.32% | 4 September 2026 |
| CVE-2026-85440 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. | CRITICAL 9.3EPSS 0.55% | 3 September 2026 |
| CVE-2026-85438 | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. | CRITICAL 9.3EPSS 0.49% | 3 September 2026 |
| CVE-2026-85437 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. | CRITICAL 9.3EPSS 0.68% | 3 September 2026 |
| CVE-2026-85435 | MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. | CRITICAL 9.3EPSS 0.17% | 3 September 2026 |
| CVE-2026-85434 | Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses. | CRITICAL 9.3EPSS 0.17% | 3 September 2026 |
| CVE-2026-85433 | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. | CRITICAL 9.3EPSS 0.34% | 3 September 2026 |
| CVE-2026-85428 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. | CRITICAL 9.3EPSS 0.55% | 3 September 2026 |
| CVE-2026-85427 | MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. | CRITICAL 9.2EPSS 0.42% | 3 September 2026 |
| CVE-2026-85426 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. | CRITICAL 9.3EPSS 0.61% | 3 September 2026 |
| CVE-2026-85425 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. | CRITICAL 9.3EPSS 0.96% | 3 September 2026 |
| CVE-2026-85424 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. | CRITICAL 9.3EPSS 0.55% | 3 September 2026 |
| CVE-2026-83711 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.58% | 3 September 2026 |
| CVE-2026-80098 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.33% | 3 September 2026 |
| CVE-2026-70352 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.62% | 3 September 2026 |
| CVE-2026-65818 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.34% | 3 September 2026 |
| CVE-2026-62916 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.60% | 3 September 2026 |
| CVE-2026-85061 | An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the… | CRITICAL 10.0EPSS 0.31% | 3 September 2026 |
| CVE-2026-85050 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 3 September 2026 |
| CVE-2026-85047 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 3 September 2026 |
| CVE-2026-85043 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. | CRITICAL 9.1EPSS 0.33% | 3 September 2026 |
| CVE-2026-85042 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 3 September 2026 |
| CVE-2026-85394 | Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. | CRITICAL 9.3EPSS 0.22% | 3 September 2026 |
| CVE-2026-85391 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. | CRITICAL 9.3EPSS 0.35% | 3 September 2026 |
| CVE-2026-82526 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. | CRITICAL 9.3EPSS 0.40% | 3 September 2026 |
| CVE-2026-58400 | Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). | CRITICAL 9.1EPSS 1.19% | 3 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.