Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 25 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-18918 | In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. | CRITICAL 9.1EPSS 0.37% | 28 August 2026 |
| CVE-2026-80714 | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. | CRITICAL 9.8EPSS 0.40% | 28 August 2026 |
| CVE-2026-80694 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq cookie), but mtk_poll_controller… | CRITICAL 9.8EPSS 0.46% | 28 August 2026 |
| CVE-2026-80693 | In the Linux kernel, the following vulnerability has been resolved: idpf: bound interrupt-vector register fill to the allocated array idpf_get_reg_intr_vecs() fills the caller-allocated reg_vals[] array from the VIRTCHNL2_OP_ALLOC_VECTORS reply in… | CRITICAL 9.3EPSS 0.13% | 28 August 2026 |
| CVE-2026-80684 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure The airq_iv_create() can return NULL on failure, but the return value was never checked. | CRITICAL 9.3EPSS 0.14% | 28 August 2026 |
| CVE-2026-80681 | In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). | CRITICAL 9.8EPSS 0.51% | 28 August 2026 |
| CVE-2026-80674 | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list() only on the non-resident path;… | CRITICAL 9.8EPSS 0.38% | 28 August 2026 |
| CVE-2026-80673 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribute lookup with a non-zero @lowest_vcn, ntfs_external_attr_find() peeks at the next… | CRITICAL 9.8EPSS 0.38% | 28 August 2026 |
| CVE-2026-80671 | In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON register_pid() has several issues when processing untrusted perf.data: 1. | CRITICAL 9.3EPSS 0.16% | 28 August 2026 |
| CVE-2026-80670 | In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() machine__resolve() accesses env->cpu[al->cpu].socket_id after checking al->cpu >= 0 and env->cpu != NULL, but without… | CRITICAL 9.1EPSS 0.47% | 28 August 2026 |
| CVE-2026-80668 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer API by GC worker approach for expectations, as it already happened in many other… | CRITICAL 9.8EPSS 0.38% | 28 August 2026 |
| CVE-2026-80634 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps inside WARN_ON_ONCE(). num_encaps is u8, so if… | CRITICAL 9.8EPSS 0.38% | 28 August 2026 |
| CVE-2026-80630 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Whenever fq_codel drops packets during peek, it calls qdisc_tree_reduce_backlog. | CRITICAL 9.8EPSS 0.52% | 28 August 2026 |
| CVE-2026-80617 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size foe_check_time is declared as u16 pointer but was allocated with only ppe_num_entries bytes instead of ppe_num_entries * sizeof(u16). | CRITICAL 9.8EPSS 0.50% | 28 August 2026 |
| CVE-2026-80612 | In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsulation skb metadata is meant for passing information between XDP and TC. | CRITICAL 9.8EPSS 0.38% | 28 August 2026 |
| CVE-2026-80609 | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access. | CRITICAL 9.8EPSS 0.51% | 28 August 2026 |
| CVE-2026-80603 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read parse_dcc() treats data_end as an inclusive end pointer, but its only caller passes data_limit = ib_ptr + datalen, which… | CRITICAL 9.1EPSS 0.43% | 28 August 2026 |
| CVE-2026-80600 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after skb realloc The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer behind the skb. | CRITICAL 9.8EPSS 0.51% | 28 August 2026 |
| CVE-2026-78032 | SOY CMS contains an issue with deserialization of untrusted data. | CRITICAL 9.3EPSS 0.42% | 28 August 2026 |
| CVE-2026-76581 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. | CRITICAL 9.8EPSS 0.34% | 28 August 2026 |
| CVE-2026-40541 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files… | CRITICAL 9.0EPSS 0.48% | 28 August 2026 |
| CVE-2026-82090 | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. | CRITICAL 9.2EPSS 0.28% | 28 August 2026 |
| CVE-2026-82082 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. | CRITICAL 9.3EPSS 1.50% | 28 August 2026 |
| CVE-2026-78174 | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. | CRITICAL 9.3EPSS 0.35% | 28 August 2026 |
| CVE-2026-61800 | In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. | CRITICAL 9.1EPSS 0.61% | 28 August 2026 |
| CVE-2026-19318 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | CRITICAL 9.3EPSS 0.47% | 28 August 2026 |
| CVE-2026-19315 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | CRITICAL 9.3EPSS 0.46% | 28 August 2026 |
| CVE-2026-19313 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | CRITICAL 9.3EPSS 0.47% | 28 August 2026 |
| CVE-2026-13086 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | CRITICAL 9.3EPSS 0.44% | 28 August 2026 |
| CVE-2026-78239 | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. | CRITICAL 9.3EPSS 0.55% | 28 August 2026 |
| CVE-2026-76943 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. | CRITICAL 9.3EPSS 0.67% | 28 August 2026 |
| CVE-2026-76179 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. | CRITICAL 9.3EPSS 0.43% | 28 August 2026 |
| CVE-2026-75337 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. | CRITICAL 9.8EPSS 0.42% | 28 August 2026 |
| CVE-2026-73125 | An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. | CRITICAL 9.3EPSS 0.53% | 28 August 2026 |
| CVE-2026-71187 | An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. | CRITICAL 9.3EPSS 0.52% | 28 August 2026 |
| CVE-2026-69658 | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. | CRITICAL 9.3EPSS 0.24% | 28 August 2026 |
| CVE-2026-68929 | As a result, an unauthenticated attacker who knows a victim team's shareId can take that team's WeChat bot offline or hijack the channel to their own bot: the logout endpoint is gated only by an existence check yet wipes the outLink's stored WeChat… | CRITICAL 9.3EPSS 0.26% | 28 August 2026 |
| CVE-2026-50152 | In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted… | CRITICAL 9.1EPSS 0.16% | 28 August 2026 |
| CVE-2026-18717 | ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications. | CRITICAL 9.1EPSS 0.22% | 28 August 2026 |
| CVE-2026-74820 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. | CRITICAL 10.0EPSS 0.25% | 27 August 2026 |
| CVE-2026-6876 | This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. | CRITICAL 10.0EPSS 0.40% | 27 August 2026 |
| CVE-2026-59313 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). | CRITICAL 9.8EPSS 0.39% | 27 August 2026 |
| CVE-2026-59283 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. | CRITICAL 9.1EPSS 0.37% | 27 August 2026 |
| CVE-2026-53579 | In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored without sanitization and later rendered as HTML, allowing an attacker-supplied… | CRITICAL 9.3EPSS 0.21% | 27 August 2026 |
| CVE-2026-53578 | In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed… | CRITICAL 9.3EPSS 0.21% | 27 August 2026 |
| CVE-2026-48996 | In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into raw HTML that is rendered as innerHTML, allowing an attacker-supplied import… | CRITICAL 9.3EPSS 0.21% | 27 August 2026 |
| CVE-2026-37072 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | CRITICAL 9.8EPSS 0.35% | 27 August 2026 |
| CVE-2026-37071 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted… | CRITICAL 9.8EPSS 0.35% | 27 August 2026 |
| CVE-2026-37065 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | CRITICAL 9.1EPSS 0.35% | 27 August 2026 |
| CVE-2026-37007 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument. | CRITICAL 9.8EPSS 0.69% | 27 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.