Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 24 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-82456 | Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources. | CRITICAL 10.0EPSS 1.39% | 29 August 2026 |
| CVE-2026-82454 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. | CRITICAL 9.3EPSS 0.23% | 29 August 2026 |
| CVE-2026-82452 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. | CRITICAL 9.3EPSS 0.46% | 29 August 2026 |
| CVE-2026-82448 | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. | CRITICAL 9.3EPSS 0.41% | 29 August 2026 |
| CVE-2026-14494 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. | CRITICAL 9.8EPSS 0.69% | 29 August 2026 |
| CVE-2026-80725 | In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP… | CRITICAL 9.8EPSS 0.46% | 29 August 2026 |
| CVE-2026-77012 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated… | CRITICAL 9.3EPSS 0.20% | 29 August 2026 |
| CVE-2026-16947 | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing… | CRITICAL 9.1EPSS 0.24% | 29 August 2026 |
| CVE-2026-16259 | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and… | CRITICAL 9.8EPSS 0.28% | 29 August 2026 |
| CVE-2026-10522 | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator,… | CRITICAL 9.8EPSS 0.34% | 29 August 2026 |
| CVE-2026-51663 | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.47% | 28 August 2026 |
| CVE-2026-51661 | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-3627 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. | CRITICAL 9.1EPSS 0.51% | 28 August 2026 |
| CVE-2026-19295 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. | CRITICAL 9.9EPSS 1.81% | 28 August 2026 |
| CVE-2026-19286 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint. | CRITICAL 9.8EPSS 0.62% | 28 August 2026 |
| CVE-2026-18527 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. | CRITICAL 9.9EPSS 0.29% | 28 August 2026 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 7.67% | 28 August 2026 |
| CVE-2026-82281 | Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks. | CRITICAL 9.1EPSS 0.26% | 28 August 2026 |
| CVE-2026-82277 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. | CRITICAL 9.3EPSS 0.43% | 28 August 2026 |
| CVE-2026-82266 | Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication. | CRITICAL 9.3EPSS 0.34% | 28 August 2026 |
| CVE-2026-82021 | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a… | CRITICAL 9.0EPSS 0.23% | 28 August 2026 |
| CVE-2026-55634 | Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by… | CRITICAL 9.9EPSS 0.45% | 28 August 2026 |
| CVE-2026-55565 | The pattern can originate from POST /api/archive/{instance}:executeSql, POST /api/archive/{instance}:streamSql, POST /api/archive/{instance}/tables/{table}:readRows, GET /api/archive/{instance}/events, or activity searches, including paths available… | CRITICAL 9.9EPSS 0.46% | 28 August 2026 |
| CVE-2026-55559 | The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing an attacker to inject a services entry for org.yamcs.ProcessRunner. | CRITICAL 9.8EPSS 0.55% | 28 August 2026 |
| CVE-2026-55511 | Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. | CRITICAL 9.1EPSS 0.68% | 28 August 2026 |
| CVE-2026-55378 | A remote user who opens a pull request can use shell metacharacters in a branch or fork name to execute commands in the GitHub Actions runner with the workflow's GITHUB_TOKEN, which has pull-requests write permission. | CRITICAL 9.3EPSS 0.60% | 28 August 2026 |
| CVE-2026-55248 | The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe internal network services and open ports. | CRITICAL 9.1EPSS 0.32% | 28 August 2026 |
| CVE-2026-55247 | A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. | CRITICAL 9.1EPSS 0.34% | 28 August 2026 |
| CVE-2026-55220 | Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspotimage.php passes the field __hotspots object-store column to… | CRITICAL 9.3EPSS 0.50% | 28 August 2026 |
| CVE-2026-55068 | The invalid profiles are persisted in the MongoDB NfProfile collection and returned by NFDiscover, allowing an attacker with SBI access to advertise attacker-controlled network-function endpoints and redirect control-plane signaling. | CRITICAL 9.3EPSS 0.44% | 28 August 2026 |
| CVE-2026-54755 | Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or… | CRITICAL 9.6EPSS 0.39% | 28 August 2026 |
| CVE-2026-54754 | An asset owner can create a valid listing and then use AssetTrigger UpdateRoyalties to make the combined referral and royalty percentages exceed the bid. executeBuyMarket pays referral and royalty amounts unconditionally while computeMarketOwnerAmount… | CRITICAL 9.6EPSS 0.30% | 28 August 2026 |
| CVE-2026-54745 | Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. | CRITICAL 10.0EPSS 0.43% | 28 August 2026 |
| CVE-2026-51660 | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51657 | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51649 | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51646 | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51645 | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.8EPSS 0.44% | 28 August 2026 |
| CVE-2026-51643 | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51636 | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51628 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51626 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51622 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CRITICAL 9.1EPSS 0.36% | 28 August 2026 |
| CVE-2026-51611 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. | CRITICAL 9.8EPSS 0.44% | 28 August 2026 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | KEVCRITICAL 9.4EPSS 3.57% | 28 August 2026 |
| CVE-2026-37751 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. | CRITICAL 9.8EPSS 1.60% | 28 August 2026 |
| CVE-2026-37236 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. | CRITICAL 9.8EPSS 0.44% | 28 August 2026 |
| CVE-2026-82244 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. | CRITICAL 9.4EPSS 0.62% | 28 August 2026 |
| CVE-2026-82222 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. | CRITICAL 10.0EPSS 1.55% | 28 August 2026 |
| CVE-2026-42007 | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. | CRITICAL 9.1EPSS 0.29% | 28 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.