Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,598 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,238 results · page 2 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-93019 | Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit. | CRITICAL 9.1EPSS 0.61% | 18 September 2026 |
| CVE-2023-5778 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. | CRITICAL 9.2EPSS 0.29% | 18 September 2026 |
| CVE-2026-28198 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. | CRITICAL 9.4EPSS 0.20% | 18 September 2026 |
| CVE-2026-28197 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. | CRITICAL 9.4EPSS 0.37% | 18 September 2026 |
| CVE-2026-13684 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct… | CRITICAL 9.8EPSS 0.46% | 18 September 2026 |
| CVE-2026-13639 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | CRITICAL 9.8EPSS 0.51% | 18 September 2026 |
| CVE-2026-67101 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from… | CRITICAL 9.3EPSS 0.27% | 18 September 2026 |
| CVE-2026-67100 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate… | CRITICAL 9.8EPSS 0.35% | 18 September 2026 |
| CVE-2026-84738 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote… | CRITICAL 9.1EPSS 0.56% | 18 September 2026 |
| CVE-2026-93467 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. | CRITICAL 9.3EPSS 0.52% | 18 September 2026 |
| CVE-2026-85878 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.55% | 18 September 2026 |
| CVE-2026-69843 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.62% | 18 September 2026 |
| CVE-2026-62874 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.32% | 18 September 2026 |
| CVE-2026-87701 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.44% | 17 September 2026 |
| CVE-2026-85889 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.49% | 17 September 2026 |
| CVE-2026-85885 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.53% | 17 September 2026 |
| CVE-2026-83944 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.45% | 17 September 2026 |
| CVE-2026-77903 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.0EPSS 0.38% | 17 September 2026 |
| CVE-2026-70200 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.58% | 17 September 2026 |
| CVE-2026-70009 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.3EPSS 0.47% | 17 September 2026 |
| CVE-2026-69865 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.45% | 17 September 2026 |
| CVE-2026-69399 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL 10.0EPSS 0.49% | 17 September 2026 |
| CVE-2026-76949 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. | CRITICAL 9.1EPSS 0.49% | 17 September 2026 |
| CVE-2026-54767 | Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. | CRITICAL 9.1EPSS 0.43% | 17 September 2026 |
| CVE-2026-54734 | A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server's… | CRITICAL 10.0EPSS 0.36% | 17 September 2026 |
| CVE-2026-54670 | Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController… | CRITICAL 9.1EPSS 0.55% | 17 September 2026 |
| CVE-2026-93393 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. | CRITICAL 9.2EPSS 0.28% | 17 September 2026 |
| CVE-2026-93374 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.35% | 17 September 2026 |
| CVE-2026-93373 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. | CRITICAL 9.6EPSS 0.30% | 17 September 2026 |
| CVE-2026-93372 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 17 September 2026 |
| CVE-2026-54501 | From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. | CRITICAL 9.4EPSS 1.22% | 17 September 2026 |
| CVE-2026-54460 | Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind enrollment to locals.user.id. | CRITICAL 9.8EPSS 0.60% | 17 September 2026 |
| CVE-2026-54237 | From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. | CRITICAL 9.3EPSS 0.56% | 17 September 2026 |
| CVE-2026-45143 | The content executes in the recipient's browser when the recipient opens the routine inbox or message view, without requiring a link click, and can expose session credentials or permit actions as the administrator. | CRITICAL 9.0EPSS 0.33% | 17 September 2026 |
| CVE-2026-45140 | Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. | CRITICAL 9.8EPSS 0.98% | 17 September 2026 |
| CVE-2025-55787 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | CRITICAL 9.8EPSS 0.32% | 17 September 2026 |
| CVE-2026-92943 | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core… | CRITICAL 9.2EPSS 0.27% | 17 September 2026 |
| CVE-2026-54752 | The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. | CRITICAL 9.6EPSS 0.35% | 17 September 2026 |
| CVE-2026-54627 | In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows… | CRITICAL 9.8EPSS 0.44% | 17 September 2026 |
| CVE-2026-54626 | In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel SAIL_PIXEL_FORMAT_BPP8_INDEXED format returned by tga_private_sail_pixel_format() in src/sail-codecs/tga/helpers.c, while… | CRITICAL 9.8EPSS 0.53% | 17 September 2026 |
| CVE-2026-54618 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. | CRITICAL 9.4EPSS 0.40% | 17 September 2026 |
| CVE-2026-54617 | Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. | CRITICAL 9.8EPSS 0.68% | 17 September 2026 |
| CVE-2026-47252 | Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into… | CRITICAL 9.0EPSS 0.45% | 17 September 2026 |
| CVE-2026-54053 | Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. | CRITICAL 9.6EPSS 0.70% | 17 September 2026 |
| CVE-2026-92489 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred.… | CRITICAL 9.8EPSS 0.46% | 17 September 2026 |
| CVE-2026-90414 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was received isert_recv_done() hands each received PDU to the opcode handlers without ever looking at wc->byte_len, the number of bytes… | CRITICAL 9.1EPSS 0.52% | 17 September 2026 |
| CVE-2026-90413 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data than was received isert_login_recv_done() records how many bytes the HCA actually placed in the login buffer, but nothing compares that… | CRITICAL 9.1EPSS 0.83% | 17 September 2026 |
| CVE-2026-90235 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE xprtsock replaces and restores sk->sk_data_ready and sk->sk_write_space on live sockets with plain stores,… | CRITICAL 9.8EPSS 0.63% | 17 September 2026 |
| CVE-2026-90230 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it… | CRITICAL 9.1EPSS 0.46% | 17 September 2026 |
| CVE-2026-90173 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free_cq() smbdirect_connection_destroy_qp() creates the send and receive completion queues with ib_alloc_cq_any(), which for… | CRITICAL 9.8EPSS 0.52% | 17 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.