Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 20 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-84834 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | CRITICAL 9.8EPSS 0.32% | 3 September 2026 |
| CVE-2026-84814 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | CRITICAL 9.8EPSS 0.36% | 3 September 2026 |
| CVE-2026-84813 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | CRITICAL 9.3EPSS 0.24% | 3 September 2026 |
| CVE-2026-84768 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | CRITICAL 9.3EPSS 0.24% | 3 September 2026 |
| CVE-2026-84753 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | CRITICAL 9.8EPSS 0.31% | 3 September 2026 |
| CVE-2026-84238 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | CRITICAL 9.8EPSS 0.27% | 3 September 2026 |
| CVE-2026-85216 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. | CRITICAL 9.5EPSS 0.50% | 3 September 2026 |
| CVE-2026-85183 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. | CRITICAL 9.3EPSS 0.15% | 3 September 2026 |
| CVE-2026-85181 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. | CRITICAL 9.3EPSS 0.38% | 3 September 2026 |
| CVE-2026-82180 | Authorisation is reduced to two string comparisons on attacker-supplied data: the DN-qualifier must equal "sy" or "op", and the cloud-name part of the CN must match the server's. | CRITICAL 9.5EPSS 0.22% | 3 September 2026 |
| CVE-2026-85154 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. | CRITICAL 9.3EPSS 0.34% | 3 September 2026 |
| CVE-2026-80726 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs… | CRITICAL 9.3EPSS 0.18% | 3 September 2026 |
| CVE-2026-78080 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | CRITICAL 9.3EPSS 0.28% | 3 September 2026 |
| CVE-2026-78069 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check… | CRITICAL 9.5EPSS 0.24% | 3 September 2026 |
| CVE-2026-76178 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. | CRITICAL 9.2EPSS 0.27% | 3 September 2026 |
| CVE-2026-76174 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. | CRITICAL 9.4EPSS 0.49% | 3 September 2026 |
| CVE-2026-19117 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. | CRITICAL 9.8EPSS 0.28% | 2 September 2026 |
| CVE-2026-66786 | A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. | CRITICAL 9.1EPSS 0.74% | 2 September 2026 |
| CVE-2026-53671 | An attacker can craft an eBPF program that overwrites a context field (e.g., ctx->data), reload that field typed as T_PACKET, and dereference an attacker-controlled address — and prevail will report the program as safe. | CRITICAL 9.3EPSS 0.29% | 2 September 2026 |
| CVE-2026-53670 | Subsequent bounds checks use the stale offset and accept out-of-bounds memory accesses, so a crafted BPF program passes verification even though it would corrupt memory at runtime. | CRITICAL 9.3EPSS 0.29% | 2 September 2026 |
| CVE-2026-53649 | Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. | CRITICAL 9.6EPSS 0.21% | 2 September 2026 |
| CVE-2026-20279 | This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.30% | 2 September 2026 |
| CVE-2026-20274 | This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.73% | 2 September 2026 |
| CVE-2026-20212 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. | CRITICAL 9.8EPSS 0.53% | 2 September 2026 |
| CVE-2026-78689 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. | CRITICAL 9.2EPSS 0.45% | 2 September 2026 |
| CVE-2026-53611 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a… | CRITICAL 9.8EPSS 1.05% | 2 September 2026 |
| CVE-2026-82955 | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through… | CRITICAL 9.0EPSS 0.14% | 2 September 2026 |
| CVE-2026-77009 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server. | CRITICAL 9.9EPSS 0.29% | 2 September 2026 |
| CVE-2026-4357 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. | CRITICAL 10.0EPSS 0.30% | 2 September 2026 |
| CVE-2025-9314 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | CRITICAL 9.8EPSS 0.30% | 2 September 2026 |
| CVE-2026-73475 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. | CRITICAL 9.1EPSS 0.23% | 2 September 2026 |
| CVE-2026-84795 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. | CRITICAL 9.2EPSS 0.28% | 2 September 2026 |
| CVE-2026-81294 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | CRITICAL 9.8EPSS 0.33% | 2 September 2026 |
| CVE-2026-81286 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | CRITICAL 9.3EPSS 0.29% | 2 September 2026 |
| CVE-2026-78657 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. | CRITICAL 9.8EPSS 0.72% | 2 September 2026 |
| CVE-2026-9055 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. | CRITICAL 9.8EPSS 0.29% | 2 September 2026 |
| CVE-2026-84699 | Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | CRITICAL 9.3EPSS 0.37% | 2 September 2026 |
| CVE-2026-84696 | Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. | CRITICAL 9.3EPSS 0.15% | 2 September 2026 |
| CVE-2026-84695 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. | CRITICAL 9.3EPSS 0.26% | 2 September 2026 |
| CVE-2026-84354 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.27% | 2 September 2026 |
| CVE-2026-84353 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 2 September 2026 |
| CVE-2026-84352 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 2 September 2026 |
| CVE-2026-84333 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.28% | 2 September 2026 |
| CVE-2026-84325 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. | CRITICAL 9.8EPSS 0.25% | 2 September 2026 |
| CVE-2026-84324 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. | CRITICAL 9.0EPSS 0.29% | 2 September 2026 |
| CVE-2026-84480 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. | CRITICAL 9.3EPSS 0.29% | 1 September 2026 |
| CVE-2026-84479 | The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. | CRITICAL 9.3EPSS 0.32% | 1 September 2026 |
| CVE-2026-84639 | This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | CRITICAL 9.1EPSS 0.32% | 1 September 2026 |
| CVE-2026-84637 | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. | CRITICAL 9.8EPSS 0.34% | 1 September 2026 |
| CVE-2026-84372 | Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additional commands. | CRITICAL 9.8EPSS 0.41% | 1 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.